Maybe something inspecting traffic like Zenarmor, blocklists in Unbound or other services, set to block DoT or DoH ?
FW rules?
@GreenMattermay be you can try to find the 1.1.1.1 references in aliases (Firewall: Diagnostics: Aliases -> Find references)?if that doesn't give any hint, it will probably be necessary to enable logging of default blocking rules, enable logging of other suitable blocking rules and look at the (live) log
anything?
can't tell without full understaing your setup/rules (how host route can interfere with pf-rules etc), sorryyou asked for a hint - i was try to give one )another hint - there is a "Disable Host Route" checkbox above Montor IP setting