I use nextdns, it's excellent.
However beware that it's not a "set and forget" solution.
Example: This morning I did my occasional sweep of what I've blocked where, and to see if there's a new allowed domain in top N that should've been blocked. What I found is that ocsp.int-x3.letsencrypt.org.edgesuite.net is blocked by "kowabit.de - bl*cklist of death". I've added that to my whitelist now, I want certificate revocation to not be blocked.