DoHoT implemented with dnscrypt-proxy is my personally fav way to solve this ...
https://github.com/alecmuffett/dohot
speed (over tor) is not a concern either when much of it is served from the cache. alec muffet has the right ideas. but you might want to study his threat-model before copy pasting.