About custom dns+vpn

Like you rightly intuited, on AOSP 10+, all DNS traffic (encrypted or not), from installed apps, unless explicitly “protected”, will flow through the active VPN tunnel.