Here's a blog post from someone who uses nginx 'doh-to-dns' to connect their DoH clients to Pi-hole.
So, yes you can blacklist domains, as long as you can configure the DoH servers that the client uses.
So, yes you can blacklist domains, as long as you can configure the DoH servers that the client uses.
Which now involves not just getting every machine, but every application on every machine