With a goal being to circumvent tracking I wonder why DNSSEC was used instead of DoH DNS over HTTPS?
The author of the article states they don't care about tracking of requests by their ISP, so they don't bother to implement in flight protection of DNS.
Agreed though, the DoH recursor should use DNSSEC in actual DNS upstream queries. IMO you want to use both.