There is a bunch of public dnscrypt servers to which your client can randomly fan out encrypted queries.

There are but I will wait until all the authoritative resolvers support TLS. If I wanted to hide my traffic from my ISP then I would just use DoT from my firewall Unbound instance to a few Unbound instances I already have around the web.

« I’ll keep my house door open until there is a really secure lock installed ». You either care about tampering and snooping or you don’t.

I understand your concerns. I personally do not share these concerns though I did when I resided in California that is for sure.

I know just about everyone at my ISP. I know where many of them live. We all live in the same small tight knit community. They tried really hard to get me to join their network team.