Forgive my ignorance, why doesn't DoT doesn't suffer this same issue? Isn't it still making it impossible to manage DNS traffic? If not, what's the point of DoT again?
DoH hides itself as being web traffic, despite the fact it isn't. With DoT, you can more easily control it because it uses a dedicated port.
DoT fulfills its job which is simply to provide privacy to the DNS queries you make. DoH tries to also bypass firewalls and evade blocking by firewalls (think corporate firewalls, or the Chinese GFW) by hiding itself.
For example, if they see a lot of hosts around the world all sending high volumes data to each other over the DoT port it's a fairly safe bet that it's not actually DNS traffic.
You can also easily configure a firewall rule that allows port 853 traffic ONLY to an authorized DoT server. Can't do that with DoH.