https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
It's good to know that there is a method but it looks a bit strange imo (see this article[2]):
>> Now this seems a bit weird: DoH to a public resolver seemed intended to defeat an untrusted local resolver, but an untrusted local resolver can disable the use of DoH to the public resolver in this fashion. In fact, if you have content filtering in place on your DNS resolver, Firefox will also use that as a metric to decide whether or not to enable DoH to the default public resolver.
>> In other words: if the browser detects that one of the things that DoH would help protect against (censorship / content filtering) is in place, then it will not enable DoH. ?? Well, for you as the network provider, that's good news -- you remain in charge, as so often, it boils down to having to trust the things you have to trust -- if you (the end user) don't trust your network provider, you can't use their services to bootstrap a trusted environment.
[1] just add the line for the canary to /etc/dnsmasq.conf:
address=/use-application-dns.net/
[2] https://www.netmeister.org/blog/doh-dot-dnssec.html