Can't you proxy it over a local DNS-over-https server that will provide filtering/caching and then have it query the upstream server?
I wouldn't want to proxy all HTTPS traffic (may not be possible if software ignores system-wide TLS CAs and uses bundled trust chain).
DoH introduces bunch new problems without solving any that I had.
Can't you proxy it over a local DNS-over-https server that will provide filtering/caching and then have it query the upstream server?