If you prefer something more privacy oriented, but possibly not as fast:
https://servers.opennicproject.org/
84.200.69.80 # dns.watch
84.200.70.40 # dns.watch
37.235.1.174 # freedns.zone
37.235.1.177 # freedns.zone
213.73.91.35 # dnscache.berlin.ccc.de
194.150.168.168 # dns.as250.net; Berlin/Frankfurt
85.214.20.141 # FoeBud (digitalcourage.de)
77.109.148.136 # privacyfoundation.ch
77.109.148.137 # privacyfoundation.ch
91.239.100.100 # anycast.censurfridns.dk
89.233.43.71 # ns1.censurfridns.dk
204.152.184.76 # f.6to4-servers.net, ISC, USA
Edit: I know this won't do anything for ISPs using transparent proxies (from the article: "Some ISP's").This is just for people with shitty, but not as shitty ISPs. Such as ones that hijack NXDOMAIN: https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
Edit2: I couldn't get the test from dnsleaktest.com to work on my computer, but starting at step 3 from [0] seems to work fine (I do already use DNSCrypt with Unbound).
[0] https://www.smartydns.com/support/isp-doing-transparent-dns-...
I'm sure you have 500 kB free RAM for a proper resolver that works in the real world, and validates DNSSEC for free. I think most resolving should be done locally nowadays. Latency is mostly a last mile problem.
Currently I'm planning to do just DNS over TLS. I'd love feedback on this if people are interested. Both of these address this issue pretty well.