Today's fun debug adventure, on one of the bgp.tools remote IX collector boxes in Iraq, all DNS packets appear to be ACL'd now. See the difference in mtr's for port 53 vs 54
Not too much of a problem, as just flipping the switch on systemd-resolved to use DNS Over TLS "fixed" the problem. I guess systemd-resolved is good for something then!