RadiusNest › Guides

How to block websites on MikroTik

Last updated: 2 October 2026

Nearly every site uses HTTPS now, so old methods that read web addresses no longer work. These are the three that do, from simplest to strongest.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

1. Block by DNS

Answer the site's name with nothing, for every device that uses the router as DNS server.

RouterOS v7 and v6.47 or newer:

/ip dns static add name=example.com type=NXDOMAIN match-subdomain=yes

Older versions:

/ip dns static add name=example.com address=127.0.0.1

Make devices that set their own DNS server use the router anyway:

/ip firewall nat add chain=dstnat in-interface=bridge protocol=udp dst-port=53 action=redirect
/ip firewall nat add chain=dstnat in-interface=bridge protocol=tcp dst-port=53 action=redirect

2. Block by TLS host

The router can read the site name at the start of an HTTPS connection:

/ip firewall filter add chain=forward protocol=tcp dst-port=443 tls-host=*.example.com action=reject reject-with=tcp-reset comment="block example.com"

Place this rule above the rule that accepts established connections, and disable FastTrack, or it never sees the name.

3. Block by address list

The router looks up the name and blocks the addresses it finds:

/ip firewall address-list add list=blocked address=example.com
/ip firewall filter add chain=forward dst-address-list=blocked action=drop

This suits small sites. Big services use many changing addresses.

The limits

  • Secure DNS in browsers and phones skips method 1. Method 2 still works.
  • Apps often use addresses without names you would recognise.
  • Tunnels and proxy apps hide the site completely. No router rule blocks everything a determined user can do.

Block only at certain hours

Add a time to any filter rule:

/ip firewall filter set [find comment="block example.com"] time=8h-17h,mon,tue,wed,thu,fri

Questions and answers

Why does my layer7 rule not block HTTPS sites?

Layer7 patterns read unencrypted content. HTTPS hides it. Use DNS or TLS host rules instead.

Can I block a site for one user only?

Yes. Add src-address= with that device's address to the filter rule.

The site still opens after I added the rule. Why?

The device cached the DNS answer, the rule sits below an accept rule, or FastTrack is on. Clear the cache and check the rule order.

Related guides

Start the free trial See pricing