Speaking of DNS in wireguard VPN qubes, I always use this:
Actually nowadays I have a slightly different convoluted setup in the sys-vpn-* qubes, checking for the existence of the zzz-my-hook in /rw/config, and copying it to the correct location if it exists, combined with some qubesdb vm-config magic… but the principle is the same.
Removing 10.139.1.[1-2] also acts as a “poor man’s DNS leaks preventer” although only specific traffic is allowed in the upstream firewall qube - I mean, it’s an unneeded bonus feature.