Configurable SVCB _dns.resolver.arpa record to allow DNR for custom DoH

My goal here was to keep using Pi-hole as filtering DNS, while enabling DoH/DoT on my network while Pi-hole is the upstream. I've used Unbound to accept encrypted traffic on 443/853 and forward to pi-hole. This only worked only when I've manually configured the browser to specify custom DoH. Customzing DNR should in theory allow supported client to upgrade to DoH to have "Secure DNS"

As the browser is refusing to connect with Encrypted Client Hello (ECH) when no Secure DNS is enabled (works well with public DoH, but I will not have pi-hole filters). See this topic DoH DNS and DNR in Front of Pi-hole