I'm having the same setup, currently not having dnscrypt installed, only CF as system DNS. I just killed my WAN connections (after 128 days uptime, but hey...) but I can't reproduce the issue you're experiencing. As soon as WAN is up again, everything works as supposed. Are these ads you're experiencing gone after rebooting the router? Aren't they accidently ads which weren't blocked in the first place?Just system DNS