iCloud Private Relay is the only thing that stops Safari using your NextDNS config, turn that off and you're golden. I've been using NextDNS since it launched, I love it.

We just ran into this testing web filtering with Cloudflare DNS. You are correct that iCloud Private Relay bypasses the configured DNS servers, but there is another spot - the "Advanced Tracking and Fingerprint Protection" that is a setting in Safari (Settings, Safari, Advanced Settings.) It is on by default for the Private Mode browsing.

> iCloud Private Relay is the only thing that stops Safari using your NextDNS config

Maybe that’s true for the NextDNS configuration—I don’t know, I haven’t tested, so I’ll take your word for it—but not true for DNS settings in general.

> turn that off and you're golden.

Unless you want iCloud Private Relay, in which case you’re not.