That's why these same DoH (and VPN) proponents are not a network security expert.
They should be using a client-side-TLS-signed (and verified) DoT only at their own DNS-forward-blocking border gateway with their wireguarded remote DNS resolver unless multiple DNS views are so desired (such as QubeOS desktops) then it is down the rabbit hole for DNS experts only.
(I frequently forget to say this often but always configure for one at the start.)
Corporate Bonus if you can scrub all TLS traffic at kernel level while running a transparent HTTPS/TLS proxy at the border gateway: that is, force all TLS through that proxy by payload detection mechanism and not just by port numbers.
When DNS over HTTPS (DoH) was announced many of its proponents seem to dismiss, or at least downplay, this concern often.