Unbound / AdGuard / NextDNS

Simplicity really.

unbound and stubby was THE way to do encrypted DNS when the standards were set and the start to encrypt DNS began. However they can be tricky to configure and are not easy if you have no knowledge of SSH or editing files under linux.

AGH rolls the DNS encryption into an adblocking client. Once installed it is far easier to configure due to having a webgui. Its one service to setup and maintain instead of multiple interconnecting ones.

Also if you are using NextDNS then AGH is the client they recommend to use as NextDNS's client is problematic.