wrt systemd-resolved:
Debian has marked wontfix: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761658
Can’t state the issue any simpler than this:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761658#166
Baffling that the systemd maintainers don’t see any problem with the fallback config. Same opt-out of privacy invasion mentality coming to Debian.
AFAIK, systemd-resolved is disabled by default. Disabled on my Fedora templates but enabled in Whonix-13 on Qubes 3.2. Is it being used by anything?