If you can't trust your device, you can't trust it without DoH either. As I said upthread, devices don't even need to use DNS. They can open up encrypted C&C channels, using whatever protocol they'd like, tunneled over whatever they'd like. They can bake rendezvous IP addresses in, they can cryptographically verify endpoints to break MITM proxies, they can even sneak data out in ICMP packets. DoH has literally nothing to do with it.
What's insidious about this argument is that it preys on peoples legitimate concerns about uncontrolled devices on their network. We're all concerned about that! But that doesn't mean we should use plaintext DNS, or Paul Vixie's preferred "encrypted DNS with a killswitch for network operators".