I have a pfsense box. It's quite arbitrary to block DNS request that are anywhere except to your pfsense box. eg. https://docs.netgate.com/pfsense/en/latest/dns/blocking-dns-...
Seems like blocking Firefox and Chrome from usurping your DNS choices is going to be much harder going forward. :(
I think the main reason the browsers have added support is so they can get the data they need to make encrypted SNI work. They’re going to have to get operating system APIs to be able to do this from the OS’s resolver or else it will screw all sorts of things up.
So I guess in theory you can block that port outbound to all hosts to handle TLS's use case.
HTTPS is tougher, but just block all traffic to those hostnames with a DNS blacklist.
DoH does, in fact, use 443/TCP, just like regular HTTPS traffic.