I have solved this now via installation of knot-resolver on all cluster nodes. I specify a FQDN which does not exist in public DNS in the PMG transport config and add multiple A-records for this FQDN in a custom hints-file for knot-resolver. Works with DNSSEC. Maybe it would be worth implementing this in PMG?