Your filtering can still break these devices.
Obviously, it would work with DoT (853) only with cert verification disabled.