No encryption needed, default settings are totally fine. You don’t need to touch anything besides the upstream DNS servers.

127.0.0.1 is by design.