Your lookups stay inside the tunnel.
A VPN that connects but leaves your DNS where it was is a leak that looks like success. Litora does not do that.
The mechanism
Every Litora gateway runs its own recursive resolver — answering from the root, not forwarding to a big public resolver — and your configuration points at it. Query logging is off.
One edge to know about
DNSSEC validation is on, so a site whose DNSSEC is broken will not resolve through Litora. That is the resolver protecting you from a forged answer, not an outage.