The time seems to be getting closer to the ubiquitous need for an 'allow list' for outbound internet connections. OpenSnitch or equivalent (per device) + Pi-Hole / Adguard (per network). Inverse WEI. Sorry, this request fails our Web Environment Integrity validation, you will not be receiving any data from this device.
Now an IP might have hundreds of DNS records pointing to it. But fine, installing AdGuard works great.
But now we're fighting against 2 things:
Things smashed together on the same domain, so no longer separate subdomains.
And DNS of HTTPS, so we can't even get all our traffic to go over the same DNS server.