If you use a public resolver that supports it (such as Cloudflare's 1.1.1.1), I think you'd probably be best served by DNS-over-HTTPS as it uses 443/TCP.
DNS-over-TLS (supported by 1.1.1.1 and 9.9.9.9) would be my next choice, but since it uses 853/TCP, you might run into issues if/when you encounter a wireless network that blocks outbound access to this port.
DNSSEC, if you ran your own validating resolver on your laptop, should work regardless of the network you are connected to (as it just uses 53/UDP), but with the caveat that DNSSEC does not provide privacy (just "response integrity", as noted by the RFC).
> ... out of the box, Windows and macOS and Fedora all just defer to the DNS servers that are assigned by DHCP ... So I'm pretty much stuck, ...
Even when using DHCP, you should still be able to manually configure the DNS servers you want to use. AFAIK, this is still possible on any OS (but I haven't used Windows for years, nor OS X for quite a while). For example, on my laptop (which also hops between wireless networks), I run my own resolver (unbound, which points to a recursive resolver on the Internet that I control) and use DNS-over-TLS (on 853/TCP).
For more information, see the DNS Privacy Project's web site (wiki) [0].
Not sure how I'll go with captive portals that rely on DNS hijacking, but worst case I just switch to using their DNS servers for a brief period.
DNS over HTTPS is being discussed to resolve that problem. The downside is it doesn't really exist yet.
DNSSEC doesn't do anything for query privacy (in other words: most of the reasons you'd use DNS-over-TLS aren't addressed by DNSSEC). DNSSEC is a bad standard whose primary impact on the Internet would be to replace the LetsEncrypt CA system with a PKI run by world governments. That sounds like something InfoWars would say, but I promise you, DNSSEC is weirder than InfoWars.
For now, the right answer is DNS over TLS.
Layering DNS over TLS (or anything else) is meaningless, it increases RTT (and thus response time) without any benefit for most users.
Using DNS over HTTPS or over TLS to hide traffic from your ISP is utterly meaningless. I don't know why people are advocating it for 'privacy' from your ISP.
For privacy, one would just use a VPN for all their traffic and using DNS over HTTPS matters much less, given that the DNS resolver is also being routed over the VPN connection (if it does at all).
The only use I see is that if you're visiting a HTTPS website, and it doesn't have HSTS (or if you're visiting a website with HSTS for the first time), it prevents phishing (for less tech-savvy since one would notice that it won't be TLS) people.
This use is further diminished if Firefox and other browsers start implementing the HSTS preloading[1] feature like Chrome, and people actually start submitting their domains for inclusion. Which I don't see happening soon, so it has some use case.
its still in draft state AFAIK
DNS-over-TLS and DNS-over-HTTPS accomplish the latter.
It certainly isn't "out of the box", but on the off chance it's useful to you -- you can change dhclient (/etc/dhcp/dhclient.conf) to specify your own DNS servers. This is what I do, pointing at a bind instance I run, and it provides plenty of warm feels. Or, heck, you could run a full resolver locally.