DNS seems one of the clean and effective ways to block a great deal of malicious known domains, ads and trackers, systemwide, without installing third party workarounds. Having only DoT available, susceptible to being blocked is a bit lacking here. I think this is a mechanism and field GOS could also improve on as they do in other areas, instead of waiting for AOSP. I was reading an article the other day about how advertisers use their network to reveal people's location without apps and devs even knowing it was possible. Remember that the next time someone tries to guilt you into enabling ads to support creators.
edit: here https://archive.is/ZowJM