Is there a way to force using encryption for DNS via DHCP?
On android phones, I can set it up using a separated toggle, but on Windows machines I need to set it manually.
The DNS between your PC and router does not need to be encrypted. Just make sure your LAN clients use the router for their only DNS. Use the router to enable DoT to upstream resolvers.