Blocking DNSCrypt entirely and forcing a fallback to the approved (censored) DNS servers is still not any harder to accomplish than censoring unencrypted DNS with or without DNSSEC. DNSCrypt as it currently exists is not any more censorship-resistant except where it is completely unknown to the censoring party. The only real security (against censorship) that it offers is security through obscurity, so saying that DNSSEC's problem is a lack of encryption is complete bullshit.