For DNS over TLS, you need to create a config file in /etc/systemd/resolved.conf.d/ like this:

[Resolve]
DNS=1.1.1.1#cloudflare-dns.com 8.8.8.8#dns.google
FallbackDNS=9.9.9.9#dns.quad9.net
DNSOverTLS=yes
Cache=yes

DoT vs DoH

FeatureDoT (TLS)DoH (HTTPS)
Port853443
ProtocolTLS over TCPHTTPS over TLS
Blocks easier?Easier (853 blocked)Harder (hidden in HTTPS)
PurposePure DNS encryptionDNS encrypted + mixed into web traffic

Related: systemd-resolved