DNS-over-HTTPS (DoH) Update – Detecting Managed Networks and User Choice
blog.mozilla.org
blog.mozilla.org
Perhaps using an inconsistent IP and being able to use any cdn/cloud IP(by including it as a subject in the cert) coupled with SNI encryption might help?
I am split about the subject myself but I prefer upstream DoH resolvers to be hard to block. If I want to intercept DoH I can always provide an internal resolver.
a) https proxy, custom CA certificate and filtered DNS anyway, or
b) no internet access.
I would rather not end up that far. Just internal resolver won't help you, when the apps (not systems, apps) are ignoring it.