I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.
I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.
I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.