Why would clients request dns.quad9.net?

This thread might help with deciding on further actions: Blocking DNS-over-HTTPS (DoH)