I’m afraid things are definitely not as black&white as you’re trying to paint them.
Sure, if you’re using DNS filtering in attempt to block users from accessing certain sites, then you probably don’t like if the machines use an alternate DNS. On the other hand, there’s a lot of DNS hijacking going on out there - so for an ordinary user, security wise, it’s better if they’re protected against fake/phishing sites they may encounter if their network gets compromised.

The question from Pete was relevant - if the “Real Site” feature is on, you probably want to turn it off (or uninstall) because that’s most likely the one switching to our DNS servers.