Instead of CloudFlare's 1.1.1.1 I like CloudFlare's 1.1.1.3: it filters known porn and known malware sites.
By now I expect many sites to be filtered out: too much crap out there.
Then I also run my own DNS (unbound) and after seeing a warning from one of my banks about a phishing site where one letter differed in the domain name from the real bank's site, I went ballistic: I did generate hundreds of thousands (maybe millions by now) of variations of the names of banks/brokers domains I use, with every single variation of one character and many variations of up to two characters and I nullroute those too (in addition to known porn and known malware sites).
And I nullroute every single Unicode domain name. I don't care. I don't care if you disagree with this: too many homoglyph attacks. Too risky. And the Web Just Works [TM] without accessing any Unicode domain.
I null route tens if not hundreds of TLDs.
Filtering out every single domain name using any Unicode char is a bit more involved but it's doable (I do it since years, but today you can ask LLMs if you want to do it or patch a DNS software to do it).
I know some go further and by default disallow everything and then only allow domains they want to use but I find that a bit too tricky.
Now... Should there be something I really want, say I want a shady torrent tracker to download some dubious file, I can always use a VM/container with a more lenient DNS.
I'm using such a setup since years. My unbound DNS runs on a Pi 3 that's on 24/7.
Works flawlessly.
P.S: on another subject I also blocklist entire IP blocks, including entire countries. Same thing: the Web still works totally fine.