After days of banging my head and contemplating the dangling threads of reality, on a whim I thought why not try
dnsleakest.com in a different browser (I always use Firefox). Lo and behold, Safari and Chromium both spit out my VPN's DNS server as the lone result. It instantly snapped in my pea brain that Firefox has a DNS-over-HTTPS option, and sure enough it was enabled by default and pointing to Cloudflare. After disabling that feature, all DNS leak test results in Firefox now show the VPN's DNS as the only result.