Operators are advised to apply all "Threat mitigations" from RFC 8932 "Recommendations for DNS Privacy Service Operators" (thereby meeting its level of "minimally compliant") and additionally apply the "Optimizations" on EDNS Client Subnet listed in section 5.3.1.
How about this?