I have an issue using the Cloudflare Gateway DoH in Windows 11.
Without the WARP client, if i only configure windows to the DNS IPs from Gateway, and use the DoH option integrated in the system, i cannot resolve any domain.
Using only the IPs (not secure by DoH) works just fine.
There is some limitation in use DoH directly in Windows?
If for some reason you want to add these DoH server definitions but leave them to use unencrypted DNS for now, you can set the -AutoUpgrade flag to false instead of true as in the examples above.
If I understand it correctly, it works as follows: Windows has multiple DNS-over-HTTPS template settings configured by default, including Quad9 and Google Public DNS. For all of those, the Auto-upgrade settings property is disabled by default, so that configuring the DNS forwarding to 9.9.9.9 for example does not automatically enable DoH. This way, you can also configure custom DoH templates for Cloudflare once, and then toggle DoH on and off by toggling this autoupgrade setting.