I have an ikev2 tunnel to my vpn isp (mikrotik ikev2 client) like described here with option 2: https://wiki.mikrotik.com/wiki/IKEv2_EAP_between_NordVPN_and_RouterOS.
Every thing is fine, but my dns request to this specific dns names which are stored in firewall access list, still are requestes by local dns server from isp (dns leak) and not as expected through dns over vpn.
I think, there is only a firewall rule missing, but my attempts went awry.
Do have a manually entered IP-address entered in /IP DNS? Also under PPPoE remove the ticked box for use peer DNS.
Restart PPPoE and you should have now DNS from NordVPN. If you point the /IP DNS also to the addresses seen on the IKEv2 connections then the router also use NordVPN.