Yes, nothing fancy. On the router, Dnsmasq and Dnscrypt-proxy with "forwarding rules" mapping domains or TLDs to desired resolvers. Any queries not matched get forwarded upstream to a server running Dnscrypt-wrapper and Dnsmasq, which logs and resolves over Tor.