Shocked that it has taken me so long, thanks to a heads-up from a friend & #nixos via #claudecode, to see that I should have set up:
(1) #ECH on my #reverseproxy serving my sites
(2) #DoT on my daily driver.
#DNS url names (web addresses) are *not* #encrypted by default even on sensible operating systems!
The incessant leakage to #ISP & intermediaries of site names visited in 99.9% of cases is an egregious #privacy issue I never knew of. Using #DoH is next? All fixes rely on #CloudFlare OMG

@adingbatponder for anonymous #DNS providers, checkout @mullvadnet :

Free #DNS servers with #DoT, #DoH and optional block lists. No need to be a paying customer.

https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

DNS over HTTPS and DNS over TLS

Our public DNS service

Mullvad VPN
@hugo @mullvadnet That is a very nice service ! Thanks for the tip. Was not aware of how cool #mullvad was and its #browser (I was after the same functions in my flake as a level 2/3 #DNS #privacy tool for also all url connections performed also by programs and CLI). #DoT #DoH