It's easy enough to set up pi-hole.net on a machine on your LAN and configure your home router to hand out DHCP records that will instruct LAN machines to use it, but if I wanted to have DNS-based ad-blocking at the coffee shop or library or elsewhere I previously had my pi-hole listening on a public IPv4's port 53 and deal with resolve.conf etc... and boy howdy does running an internet-accessible DNS resolver suck! My server would receive millions of requests, weird reflection attacks like [1], probes, the whole nine, it made the dashboarding useless for personal tracking.
But now my pi-hole only listens on my LAN network and its tailnet address, and any machine connected to the tailnet including my phone will use the pi-hole without configuration on any network via MagicDNS.
[1]: https://www.linuxquestions.org/questions/linux-newbie-8/ther...