My current approach is AdGuard Home, WireGuard VPN to my home network the majority of the time.
This was all pretty simple to setup given hardware that supports VPN, DDNS, etc.
Worth noting too that just blocking hostnames is not enough; Netflix, as an example, uses Google's DNS servers (plain UDP) on some/most clients.
If the network the client operates on can't prevent DNS to other servers, that's a simple "bypass" vector.
AFAIK, the best you can get, given sufficient time, patience, and hardware is:
• something like the above
• blocking outbound DOT (853), DOQ (784, IIRC) excepting, perhaps, upstreams you trust
• blocking HTTPS to known DOH endpoints (Cloudflare, Google, etc)
• DNAT for plain DNS cases like the Netflix example above. (to your DNS server(s))
Even that there's plenty of hypothetical opportunities for clients to just use another DOH resolver outside of your domain/IP block lists.