Considering that [1] claims 1.43 cycles per byte for Chacha20, and assuming requests & responses are typically 200 bytes (they will compress well with HTTP header compression), the actual encryption part of https only consumes 1.43 * 200 = 286 cycles.
The remaining 15,716 clock cycles should be plenty to read the actual responses from the cache and parse the HTTP/2 request bytes.
Obviously all of the above assumes you design your infrastructure purely for performance. Writing everything in Python and NodeJS might suddenly burn up all those 15,716 clock cycles!
With DNSoverHTTPS, the sender must be able to receive replies at their IP address, so cannot spoof who they are easily, closing off a lot of avenues for DoS attecks on your and other peoples recursive resolvers.
Spoofing the sender IP is only useful to conduct DNS reflection attacks, where a small question is sent, and a much larger response is sent back to the (possibly spoofed source IP).
If you require the question to be at least as large as the response, amplification is not a concern any more, so UDP is perfectly fine. This is what the DNSCrypt protocol is doing.
https://twitter.com/PowerDNS_Bert/status/1064290946731384832