I’m speculating, but it wouldn’t change a thing. You would still need to request domain addresses from a server somewhere, but traffic between your device and server would be encrypted in transit. The DNS server would also be verifiable to prevent imitators.
So, the request would go to the PiHole and if it was not being filtered the PiHole would make the request of whatever upstream server is configured same as before.
MangoPenguin@lemmy.blahaj.zone 1 hour ago
Maybe block the DoH endpoint and in theory the device might fall back to normal DNS, dunno if that would work.
WhyJiffie@sh.itjust.works 21 minutes ago
and also block outgoing connections to port 53 when it’s not the pihole device’s allowed IP