Earlier quoted context omitted.
I’m not sure why I’d ever want DoH, I block as much as I can at my firewall and have a canary domain. I want my devices to use my defined dns sever on my network, not some ad company (and all tech companies eventually become ad companies)
I want pihole to talk encrypted to the upstream dns server. I don't actually care if my devices talk encrypted to pihole. I just don't want to leak dns requests to my isp. If there's a way to do this without DoH or DoT, I'd happily learn more about it.
Nothing says clients need to confirm to the port requirements, but most companies will be lazy and assume 853 will work.