Beware of third-party DNS resolvers.
DoH provides the benefit of encrypted DNS transactions, but it can also bring issues to enterprises, including a false sense of security, bypassing of DNS monitoring and protections, concerns for internal network configurations and information, and exploitation of upstream DNS traffic, NSA officials wrote in published recommendations.
NSA recommended enterprise DNS architecture with DoH