Does the DNS Protection support DNS over TLS and DNS over HTTPS?

Does (or will) DNS Protection support DNS over TLS and DNS over HTTPS?

Currently, I'm blocking both to try to force fallback to regular DNS. But I've considered using NAT to force each type of DNS to go to Sophos. (Not sure that SFOS supports encrypted DNS, otherwise I guess we could map all DNS to the firewall itself.

Any thoughts or suggestions?