The Block Non-VPN Traffic option may be helpful.
If DNS is set to Automatic, the VPN interface will only use the DNS from WireGuard. When the Block Non-VPN Traffic option is enabled, data sent over the Ethernet interface will be blocked. In other words, the DNS for Ethernet is still in the settings, but no data will be sent.
So when the VPN is not available, do you want to block internet or use another manually set up DNS?