Hmm...not sure how one could achieve this "have all that traffic routed through the DoT server" (emphasis on "the" server, singular), when using Unbound on the router as a recursive DNS solution that reaches out to many DNS servers. Maybe if using Unbound simply as a substitute for dnsmasq and Stubby, where one can define one or two DNS servers.
I have tried all the presented solutions here, including removing the GUI interface DNS servers, as well as setting this "Tools > Other Settings > "Wan: Use local caching DNS server as system resolver (default: No)" to Yes" followed by a reboot, to observe behavior after the reboot. I had brief periods where it appeared to be settling into all "green" status, but that didn't last long, and was immediately followed by lengthy sections of mostly "red" DNS inquiries. Not sure what else could be done, but it seems out of reach to get fully encrypted responses in all cases when Unbound is setup as a recursive DNS server on the router.