This is mainly for two reasons:
- performance: DNS requests sent through DoH are anycasted, so you can’t be sure they will take the shortest path, and using the same server as the VPN tunnel will ensure you get the fastest response
- potential detection of VPN: some services will look for mismatch between DNS requests and other types of request and might block you from using their services
As a Mullvad VPN user, there’s no advantage to use DoH when connected. DoH is there by default because we can’t assume Mullvad Browser users are using a VPN and DNS requests are encrypted.
In terms of privacy, in most case it shouldn’t matter much, because in both cases requests are encrypted.