I do that: well, not pihole but I run
unbound on a Pi and I've got my Firefox set to never use the "trusted resolver" (i.e. network trr set to 5... I think the default is still 0/off but you never know).
That way I'm preventing DNS over HTTPS and known ads (and known telemetry) domains cannot resolve sneakily through HTTPS.
I can still, if I want to, have unbound use DoH so that my ISP doesn't spy on me.
But on my LAN there's no DNS over HTTPS.
And unbound accepts wildcards to prevent domains from resolving, which is really sweet.
I wrote my own tiny script (in Clojure / Babashka) which combines several huge DNS blocklists, allows certain domains I'm okay with, merge what can be merged into a single line using wildcards, etc.