Earlier quoted context omitted.
Again not the most ideal way to do things and Mozilla is doing a different approach to Chrome and Edge. and also a concern is that malware can use DoH to retrieve data without logging suspicious DNS queries on Firewall DNS logs which are monitored to highlight of new domains that have not been pre-approved. DNS should be something that is handled by the OS. I favor DoT which is secure and practical over DoH.
> malware can use DoH to retrieve data without logging suspicious DNS queries on Firewall DNS logs Malware can already query IPs of its choice to learn about other IPs it should contact. DoH doesn't let it do anything new.
In that case, DoH does let malware do something new -- block the company's existing DNS policies, quert logging, and security monitoring!