Set up Pi-hole with your own recursive DNS server using DNSSEC
labs.ripe.net
labs.ripe.net
So you're not asking the ISP for abc.google.com, but because they provide the internet, the ISP will see all your requests, including the UDP request to the .com TLD, google.com's DNS, etc
The author of the article states they don't care about tracking of requests by their ISP, so they don't bother to implement in flight protection of DNS.
Agreed though, the DoH recursor should use DNSSEC in actual DNS upstream queries. IMO you want to use both.
Simply, you issue multiple DNS requests and take the fastest one. I use 9 different DNS servers over TLS. This is a bit excessive, two is enough most of the time.
I'm tempted to write my own DNS forwarder but this project is working well for me: https://github.com/mikispag/dns-over-tls-forwarder