DoH is a technical win but a practical regression for anyone who actually runs their own DNS. With classic DNS, you could hand out your resolver via DHCP and transparently control local zones. With DoH, that's gone. You have to configure each client explicitly, because the traffic is wrapped in HTTPS and can't be intercepted. And the defaults don't help: instead of your ISP seeing your queries, now it's Cloudflare, G…
> you could hand out your resolver via DHCP and transparently control local zones. With DoH, that's gone. Checkout RFC9463
It's not supported by dhcpcd yet: https://github.com/NetworkConfiguration/dhcpcd/issues/341