I favour unbound as resolver over bind/dnsmasq/knot and utilize DoT since a while, with settings in configuration files other than “/etc/config/resolver” since uci does not parse the relevant settings.
One thing I do hope for that the changes being introduced now are respecting settings in place and do not change them considering that commits https://gitlab.labs.nic.cz/turris/turris-os-packages/merge_requests/62/diffs?commit_id=f65d9ffb6b080a58809f2b0d25eded2db8280ddc and https://gitlab.labs.nic.cz/turris/turris-os-packages/merge_requests/62/diffs?commit_id=54da059d0d4f625800cc6db3abad9ca34d6e591f seem to purposely disable DoT for unbound?
What is disturbing however in regard to predefined upstream DNS servers
How is TO guessing which public resolver would potentially suite most people? CF for instance is not a privacy friendly resolver.