Preface
I used such approach to get rid of ad or malicious domains by just forwarding required tld to upstream resolver using dnscrypt-server abilities on Windows.
Additionally subdomains of allowed tld's can be cut off using dnssec validation of prefixes (aka subdomains of allowed tld's) in windows dns client opts.
So.
What if rethink will handle such forwarding of good known tld's?
Like config where *.com, *.co.uk, *.net, *.co tld's are chosen and been forwarded but others dropped.
Source: r/rethinkdns · by /u/ButcherManny