To clarify, the issue isn't a lack of encryption for DNS queries. The traffic is already encrypted at the tunnel layer and it stays in Mullvad's intranet. The real issue is that Chrome *thinks* it's insecure, which triggers it to turn off a privacy feature.