Oh, yes, DNS is an internal DNS. You can't change it. I meant, it's the only way to "trickle leak" data without it going through the filtering proxy. But who knows, maybe the DNS requests are logged too, but they don't seem to be filtered.
Edit: they are filtered. Suspicious names go to 127.0.0.1