What it means
A router DNS setting tells many local devices which resolver to ask for a website's network address. DNS over HTTPS or DNS over TLS describes an encrypted transport for those questions. You can change the resolver without enabling encryption, and a browser can use its own encrypted resolver despite the router's choice.
A real-world example
You enter a public DNS address on your router, then assume nobody on the network can see DNS requests. That assumption may be false if devices still send ordinary unencrypted DNS to the resolver.
What to do
Choose a resolver based on its published policies, configure the router carefully and use a provider diagnostic to verify the actual path. If encrypted DNS matters, check each supported device or router's DoH/DoT controls separately.
The distinction that matters
Neither choice is a VPN nor a guarantee that a destination site is honest. Cloudflare's router instructions discuss network-wide resolver changes; its DNS explainer describes encrypted transport.
Cloudflare router DNS setup Cloudflare DNS encryption explainer