I mostly use 1.1.1.2 or 1.1.1.3 depending on the device. That is CF with different restrictions.
On Windows the big problem with DNS is that it can be changed randomly. Among all the garbage on Windows this is peak garbage. Any con can change the DNS that I explicitly told it use. DNS by it self is probably top 10 sec risk on desktop envs and it so completely broken by design. I hack it more or less daily to "debug" our sites.
Conservative people leave us with DNS, TLS/Public CAs and other sht and then they whine on HN day in and out why did a "root" cert of MS leak or whatever. Securing TLS or DNS with automatons at a large scale company is a complete nightmare.