Earlier quoted context omitted.
Not the person you responded to, but I too run my own resolver on my router. I also have the router configured to drop [1] all outgoing packets to any DoH IPs; there are a bunch of lists for those, like https://github.com/Sekhan/TheGreatWall [1]: Specifically, to reject them, which means sending a TCP reset / ICMP unreachable response back rather than blackholing them.
Are you aware of "Adaptive DNS Resolver Discovery"[1] and do you have plans to block that too? (It's already in iOS 14 and slated for macOS 11.) 1: https://datatracker.ietf.org/doc/draft-pauly-add-resolver-di...
I don't use any Apple software or hardware, but if Firefox starts using it I'll start worrying about it.