Yes, you're right. The relay routing/IP address hiding is done only for Safari traffic, but all DNS traffic is encrypted using Oblivious DNS over HTTPS which can be a better option than DoH or DoT using 1.1.1.1 in certain use cases.The thing is it only works in Safari. The rest of your internet traffic does not go through this. Better off to use something like 1.1.1.1 Cloudflare app which does apply to all traffic. (That actually works well too) and you can still exclude certain networks that perhaps won't allow it just like PR does. In my experience, 1.1.1.1 works way better than Apples PR and it applies to all traffic.