@xgranade @cthos @miss_rodent I caught my (LG) TV talking to 8.8.8.8 at one point, an address I hadn't told it about. So now all DNS leaving the network is DNATted to a Pi-hole instance I control. Not an option for most people, sadly.
DNSoHTTPS is going to be an utter bitch.