Really easy setup but by no means foolproof ?
If you've gone to the extent of setting up OpenDNS at the router and configuring DHCP to point to it it's not that much more effort to firewall the DNS requests "from" inside to allow only requests to OpenDNS servers and block the rest. Then let them have at it mangling settings as it won't do any good. Another option is adjusting the GP on the machine to not allow those changes without admin authority. With proper settings not even proxies will get by it.