Ubuntu test after disabling the dnsfilter
steve@LinuxUbuntu:~$ kdig -d @1.1.1.1 +tls-ca +dnssec +tls-host=cloudflare-dns.com example.com
;; DEBUG: Querying for owner(example.com.), class(1), type(1), server(1.1.1.1), port(853), protocol(TCP)
;; DEBUG: TLS, imported 133 system certificates
;; DEBUG: TLS, received certificate hierarchy:
;; DEBUG: #1, C=US,ST=California,L=San Francisco,O=Cloudflare\, Inc.,CN=cloudflare-dns.com
;; DEBUG: SHA-256 PIN: V6zes8hHBVwUECsHf7uV5xGM7dj3uMXIS9//7qC8+jU=
;; DEBUG: #2, C=US,O=DigiCert Inc,CN=DigiCert ECC Secure Server CA
;; DEBUG: SHA-256 PIN: PZXN3lRAy+8tBKk2Ox6F7jIlnzr2Yzmwqc3JnyfXoCw=
;; DEBUG: TLS, skipping certificate PIN check
;; DEBUG: TLS, The certificate is trusted.
;; TLS session (TLS1.3)-(ECDHE-SECP256R1)-(ECDSA-SECP256R1-SHA256)-(AES-256-GC
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 47411
;; Flags: qr rd ra ad; QUERY: 1; ANSWER: 2; AUTHORITY: 0; ADDITIONAL: 1
;; EDNS PSEUDOSECTION:
;; Version: 0; flags: do; UDP size: 1452 B; ext-rcode: NOERROR
;; PADDING: 25 B
;; QUESTION SECTION:
;; example.com. IN A
;; ANSWER SECTION:
example.com. 425 IN A 93.184.216.34
example.com. 425 IN RRSIG A 8 2 86400 20190407212028 20190317211731 63195 example.com. YsnnzLA57y7ewUwLWMiWDmFpDJqVASZVlo4YT50bBz1Yk9RHnT1zNLH7Rv6io0T9wri9IsXP8YDXpBKVewO6pGipA6hzL9LTkc4xXF4PIfH7rOTAR1kAuCsz4O2wfe2iMqxCID/hkK3Va6F824Onne0tQvJEocciD9i9rLlbx8E=
;; Received 256 B
;; Time 2019-03-23 16:36:04 CST
;; From 1.1.1.1@853(TCP) in 80.6 ms
steve@LinuxUbuntu:~$