In fact, I've analyzed several apps that used some kind of binary/text monstrosity over HTTP (not even HTTPS) to resolve IP addresses, usually Chinese manufacturer bloatware. They've been doing this crap for years! When I looked at the apps, the resolver IP had seemingly even been hard-coded into the Java code.
If you think your network is leak-free just because you've blocked port 53, you've either been missing leaks or hadn't had any kind of software actually try to evade your blocks. DoH doesn't add anything that wasn't already possible.
If you want control over your network, block all outgoing traffic and force every device to go through an intercepting HTTPS proxy and apply filtering heuristics like "this looks double encrypted" or "this looks like an IP address". It's practically impossible to do these days because we've lost control over the devices we've bought, though.
It should be noted that there's no sign of this feature being enabled across all Android devices automatically. For most devices, it's an opt-in feature you can toggle in the settings and broken DNS servers won't trigger a fallback. In other words: it doesn't change a thing about your situation, though your situation may not be what you expect it to be.
Google just wants you to use them for DNS so they can still see where you are going :-)
DNS-based blocking will never block a determined tracker.
You can always block UDP 443 to stop this, given it’s over QUIC.