I had the same issue but this was caused by the ISP modem/router forcing dns packets throught to there caching dns which was breaking dns-sec. Simply I stopped using there modem and wired purchased an SFP+ XGS-PON ONU with mascarade so the er707 router manual DNS entry's would not be overridden by a DNS forward built into the modem. I have 2 different ISP's and one ISP simply told me the modem/router was fixed and could not be changed. DNS forwarding means no matter what Public DNS you set to it will forward the DNS packets to what is specified to forward. Some ISP's are switching over to doing this so getting your own Fibre ONU maybe a requirement in future. OLD Routers do not use DNS-SEC so will not have the issue of broken DNS-SEC packets. This also depends if the ISP recognizes the need to fix there DNS cache to forward DNS-SEC correctly.
When DNS-Sec is broken the DNS packet can and will get dropped so your device will not resolve the domain.
mufti Gigabit XGS-PON will need an SFP+ capable switch or router as they need 10Gb capable port. then use mascarade mode to put in you PON s/n: which will be written on the underside of the HUB.
This may be resolved in future but these full fibre 10Gbit capable hubs are new. hopefully get fixed in newer releases.
We use DNS-Sec and DNScrypt to ensure data privacy for R&D security, so installing an XGS-PON SFP+ adapter was the only viable option.
anyway possible solutions..
Problem is TP-link solutions are there but are unobtainium in uk and europe
TP-Link XGB835v this a router fix but again cannot find anywhere in europe to purchase. https://www.tp-link.com/us/service-provider/gpon/xgb835v/ .
Problem is The TP-Link XGS-PON SFP+ adapters have been withheld in Europe including UK for some monopoly reason. Or go find a USA supplier willing to ship it at a non crazy price.
I was unable to purchase a "TP-link DS-PMA-Combo C+" from distributors as they require a trade account so ended up buying some third party with an equivalent spec.
https://www.tp-link.com/us/service-provider/gpon/ds-pma-combo-c+/
You will have the same issue with the TP-Link XM60A for standard fibre connections. https://www.tp-link.com/us/service-provider/gpon/xm60a/
I honestly hope TP-Link will make there xgs SFP+ and GPON SFP adapters available to the public because everyone is going to be buying other brands instead.
ps. The new Virgin Media full fibre to premesis which can offer up to 10Gbit is one of these which has an issue using there HUB5X which is the only hub they have to offer for both business and home use.
Footnote for TPlink If resellers refuse to sell your High grade options . please make it available to buy directly in the tp-link store.