And since RethinkDNS' underlying tunnel implementation is in Go, I'm fully expecting wireguard-go to fit in seamlessly.
[0] https://www.xda-developers.com/google-restricted-networking-...
+1
https://play.google.com/store/apps/details?id=dev.ukanth.ufi...
Same is now available on iOS 14.4(?), via a mobileconfig plist/XML file.
Either use an existing public ad/tracker blocking DNS over (HTTPS, TLS) server, or host your own and enter the hostname there.
If you go down the hosting your own route, you can have a rather neat setup for managing and blocking things via a web browser - it is quite nice to be able to log in and control what's blocked.
Note - if you run an open resolver DNS server on the public internet, usual caveats apply about knowing what you are doing. You don't need to expose port 53 (UDP DNS) if you're using DoT or DoH, which should help.
RethinkDNS can:
1. Prevent apps from doing their own DNS. Android's DoT can't do that.
2. Block TCP/UDP connections to IPs per-app.
3. Block all connections when device is locked.
4. Block connections from any app not in the foreground.
5. Forward DNS queries to DNSCrypt v3 endpoints (supports Anonymized Relays) or Tor (via Orbot).
6. Forward all connections over Tor (via Orbot).