Tor has bridges, which are specifically designed to thwart the Great Firewall - and I'm guessing your network monitoring software.
Malware can ship with an arbitrary number of DNS-over-HTTPS servers accessible anyway, no matter whether Google supports it. The cat was out of the bag as soon as you allowed encryption on your network in general.
Finally, there are system architectures that are inherently less susceptible to malware, which is what we should really be focusing on. If your document viewer doesn't need to access the Internet, why does it have access to the Internet? Why does your general-web-browsing browser have access to your intranet and worse, your network drives and USB sticks? The reason we're stuck with what we have now is that operating systems research largely died in the 90s, but we're now aware that e.g. microkernel capability systems can be implemented in ways that are both fast and secure.