@rain@niu.moe There is no best one, you trust your DNS queries to whomever is your DNS provider. Good provider uses some sort of encryption for your DNS requests (like DNS over HTTPS, DoH in short)
and uses DNSSEC for additional security in authentication. For starters I recommend quad9, 9.9.9.9 because it has DNSSEC and DoH and it uses some blocklist for suspicios domains. For "more" secure servers you should check out https://www.opennic.org/