To do this you disable the "Use Peer DNS" option in the DHCP client or PPPoE client settings (depending on which method you are using with your ISP).
If you only need to use plain DNS, then put the NextDNS IP addresses under Servers.
If you want to use DNS-over-HTTPS, then first, add static A and AAAA records for dns.nextdns.io under /ip dns static, then configure the DoH URL in "Use DoH Server", something like https://dns.nextdns.io/yourID.
Note: In older guides like this one: NextDNS in Mikrotik - Discussions - NextDNS Help Center there is a step where you have to import CA certificates. This is no longer needed with recent RouterOS versions, as the root CA certificate used by dns.nextdns.io (Sectigo Public Server Authentication Root E46) is already included in RouterOS.