My setup is similar: A server at home runs Unbound for recursive DNS, filtered by Hagezi's blacklists. The phone (running GrapheneOS) consumes the DNS service through a Wireguard tunnel. This is 100% self-hosted and does not rely on Tailscale or a third-party DNS service. All the mobile carrier or WiFi hotspot used sees is a single encrypted connection to the server.
I absolutely love this. I thought Tailscale was necessary to establish that kind of wireguard tunnel. Would you have a link to a tutorial or write-up on how you got this set up?