There is a lot of confusion in this thread and in a separate thread discussing the Malaysian DNS redirect legislation where people confound privacy with resistance to censorship. Whilst both do possess a certain degree of overlap, resistance to censorship requires a fundamentally different approach that does not fit within constraints of the DNS framework.
DNS has a decentralised architecture designed to be resilient to failures.
DoT, DoH and similar address the privacy aspect of the unencrypted by default DNS traffic.
None of the existing DNS, DNS extensions, DoT, DoH can circumvent serious censorship attempts at scale due to name resolution requests being encapsulated in an IP packet that exposes enough metadata that (destination address and port number) to allow the packet to be altered, redirected, dropped or blackholed even if the packet is encrypted or obfuscated. Traffic bound to a specific IP address or to a specific TCP or UDP port is the easiest to curb, it does not even require the manual intervention and is widely used by intrusion detection systems to automatically block the detected in real time malicious traffic.
The censorship resistance requires a complete replacement of DNS that would be akin to the GNU Naming System[0], which fulfils all three objectives: it is a decentralised, privacy-preserving, censorship-resistant domain name resolution protocol.
Having gone through https://dnsprivacy.org/ (which is very disorganised, to be fair), I fail to see how stubby could be of any help due to still requiring a upstream DNS server of sorts somewhere, which will be blocked if not automatically then very quickly albeit manually anyway.
[0] https://datatracker.ietf.org/doc/html/rfc9498