If you want real security, the router's DNS should be the resolver instead of a caching forwarder.At the moment the DNS server has changed and it is working as expected with the settings as shown (the issue was resolved after a hard reset). Why would it be more beneficial to switch “Prevent client auto DoH” and “Enable DNSSEC support” to Yes? And would that mean that then I could disable the Dns over Tls as it would honour the wan dns settings? Or I got that wrong??
DNSSEC encrypts the connection between the local DNS in the router and the external DNS.
DOH is used to bypass the system DNS stack which would cause DNS leaks on the client. That is why this activity should be forbidden to perform on your network if you want real security.