https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/
I like to combine DoH with a VPN. The VPN doesn't see my DNS queries, and Cloudflare just sees a vague IP based in some vague colocation center. There is still plaintext SNI[0] to worry about though, which is being mitigated with something called ECH[1]. `Oblivious DoH`[2] is worth reading about too.
[0] https://www.cloudflare.com/learning/ssl/what-is-sni/
Someone will inevitably pop in and remark, “I trust my ISP with my DNS queries due to regulations in my country!” Good, I’m happy for you. But some of us are stuck with Comcast.
It turns out that not many organizations who operate a resolver are willing to agree to those requirements. Isn't calling that centralization like saying the health inspector is centralizing restaurants by shutting down dirty kitchens?
Mind you, this entire arms race exists because every single bit of data is being used for data mining.