Except when the client ignores what you tell it. Per Paul Vixie:
google, this is bogus as hell. my dhcp server gives you dns servers to
use. please don't make me route and answer 8.8.8.8 just to watch youtube.
> [71] 2019-02-13 16:39:40.548137 [#68 vtnet0 4095] \
> [24.104.150.186].56915 [8.8.8.8].53 \
> dns QUERY,NOERROR,7357,rd \
> 1 lh3.googleusercontent.com,IN,A 0 0 0
> [71] 2019-02-13 16:39:40.548210 [#69 vtnet0 4095] \
> [24.104.150.186].56915 [8.8.8.8].53 \
> dns QUERY,NOERROR,49247,rd \
> 1 lh3.googleusercontent.com,IN,AAAA 0 0 0
(no, this device i've paid for, will NOT be allowed to send you any
information, other than what i personally approve, which will never
include DNS traffic. if you don't like that deal, buy it back from me
and i'll find some other video appliance that doesn't twist my arm.)
* https://news.ycombinator.com/item?id=19170671Of course with DoH you can't just do a UDP redirect. With DoT, which uses tcp/953, you can at least block access.
But with DoH, you have just lost control of your network. (Unless block 443 and force everything to go through a (Squid) proxy?)