one check
Who looks up names for you
This asks for a name that has never existed anywhere. No cache can answer it, so whoever asks us for it is genuinely your resolver, and it asks several times, because large resolvers work in clusters.
What this one page cannot tell you
What your resolver does with the lookups. We see which addresses asked us; we cannot see logging, filtering or anything else on their side. Encrypted DNS shows up here as your provider's resolver, which is the protection working.
The interesting part is usually not a single value but the disagreement between two. The full check reads all five layers and shows you where they contradict each other.