Q: DNS - DoH and DoT?

Configure resolvers only for upstream interfaces.

There's a relevant thread: DNS Rebind Attack?