Implementing the whole thing (modulo the anycast IP, which is the only thing I did not use) is easy. I have a docker-compose file which does the whole stack:
1. Unbound DNS which provides DNS-over-TLS service at port 853. It forward request to my local pihole's 53 port. 2. Pihole forward request to my Stubby DNS server. 3. Stubby connects to Google DNS over DNS-over-TLS. 4. A separate docker container to run certbot to update certificate used by the unbound container. 5. A separate docker container with Pomerium as reverse proxy so I can remote access PiHole UI.
Then you can configure your Android phone to use your unbound DNS server as the "private DNS" server. I've being using this setup for more than a month and works really well.
UPDATE: I posted my docker-compose.yaml file at https://github.com/yegle/your-dns. I'll update the README soon.