While applications shouldn't be able to override the system-set DNS servers. Many of DoH's "pitfalls" are that people got way too comfortable passively reading the plaintext DNS queries as they traveled over the network. Like honestly this move to encrypted DNS should not have been a big surprise as everything became encrypted.

