I've tested dnscrypt-proxy v2 with both current and beta versions of pihole (see here). Turns out there are a lot of dnscrypt-proxy servers that don't handle DNSSEC very well.
Servers I found to handle DNSSEC correctly are:
'dnscrypt.eu-dk', 'dnscrypt.eu-nl', 'scaleway-fr', 'de.dnsmaschine.net', 'dnscrypt.me'
I haven't tested them all, but I'm convinced the 'd0wn' servers don't do very well.
I abandoned dnscrypt-proxy and I'm using the unbound solution, DNSSEC is handled by unbound.