FWIW, I’ll add my two cents based on my experience. My ISP’s DNS is the fastest but much like you, OP, I was looking for a resolver that did proper DNSSEC validation and also offered encryption.
After trying several public resolvers, I settled on Cloudflare (their 1.1.1.1 unfiltered service) with DoT. I find their performance better than all other public resolvers I tested, and for me, they’re almost as good as my ISP in terms of speed/latency. There’s only a slight performance hit stemming from DoT, which is expected.
Even though Cloudflare doesn’t use ECS, I’m always routed to my local POP. Everything works extremely well and fast…websites, apps, my IPTV service from my ISP, etc.