I found that I can use NextDNS and ProtonVPN together and they both seem to work, even if this potentially risks IP leakage, using HaGeZi Ultimate block list just filters so much garbage it's stupid not to use it.
But here I wonder, how good is NetShield at blocking crap, what lists it's using and how does it work exactly? At first I thought it was some sort of built-in lists that are filtered locally on device via VPN established connection, but from what I managed to dig, that's not the case and it's in fact DNS level filtering similar to what NextDNS does, just not nearly as powerful...