From a DNS privacy perspective, ODOH (Oblivious DNS over HTTPS) seems to achieve this at protocol level, with interoperability between providers. While there are tunnelled VPN (separate entry and exit), they always seem to be with the same provider. The iCloud private relay design appears to avoid this.
It would be interesting to see where SPN goes, and more on how it works, as you say.
It would be interesting to see where SPN goes, and more on how it works, as you say.