I don’t understand your screenshot, but I seem to have 6 providers enabled in my unbound.conf.d/dns-over-tls.conf which in amount of IP addresses would be 18.
My goal is to not centralize my DNS queries on a single DNS provider and have DoT (which is the only encryption Unbound supports) also on port 443 to have the benefit of DoH, so even if something went down it wouldn’t affect me so much.
I am not familiar with Pi Hole, are your DNS queries encrypted or are you just sending them to those servers in plaintext allowing your ISP to hijack them into their DNS servers and track them due to usual DNS being in plaintext? Anyone in the middle of you and the target DNS server could track them due to not having encryption.
You do mention DNSCrypt though, but the custom servers don’t have stamps or anything that would hint to me that it’s in use.