RadiusNest › Guides

MikroTik DNS over HTTPS (DoH) setup

Last updated: 11 October 2026

With DNS over HTTPS (DoH), the router sends its DNS questions encrypted to a DoH server instead of in plain text. Your provider and anyone on the path can no longer read or change the answers. Your clients keep asking the router as before; only the router's own questions change.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

Before you start

  • RouterOS 6.47 or newer (any v7).
  • A correct clock. Certificate checks fail if the date is wrong; set NTP first.
  • The router already answers DNS for your network; see DNS setup.

1. Import the DoH server's root certificate

To check that it talks to the real DoH server, the router needs the root certificate that signed it. Open the DoH server's address in a browser, look at the certificate chain, and download that root certificate from the certificate authority's own website. Upload it to the router (Winbox → Files) and import it:

/certificate import file-name=root-ca.pem passphrase=""
/certificate print

2. Turn on DoH

/ip dns set servers=1.1.1.1 use-doh-server=https://cloudflare-dns.com/dns-query verify-doh-cert=yes

The plain server (1.1.1.1) stays because the router has to look up the DoH server's own name once. When a DoH server is set, the router uses it for the questions from your network. Only one DoH server can be set at a time.

3. Test

:put [:resolve mikrotik.com]
/ip dns cache print
/log print where topics~"dns"

An address means it works. If names stop resolving, the log usually shows a certificate error: the wrong root was imported, or the clock is wrong. To find out whether the certificate is the problem, briefly set verify-doh-cert=no; if names then resolve, fix the certificate and set it back to yes. Without the check, DoH is encrypted but anyone in the middle could pretend to be the server.

What about the clients?

  • Clients that ask the router get DoH protection for the path from the router to the internet.
  • Phones and browsers with their own DoH setting skip the router's DNS entirely. That also skips your DNS-based blocking; see block websites for what to do.
  • On a hotspot, the login page still works: the router answers DNS for the login name itself.

Turn it off

/ip dns set use-doh-server="" verify-doh-cert=no

Questions and answers

Does MikroTik support DNS over HTTPS?

Yes, from RouterOS 6.47 and in all v7 versions, with one DoH server at a time.

Why does DNS stop working after enabling DoH on MikroTik?

Usually the certificate check fails: the root certificate is missing or the router's clock is wrong. Check the log, import the right root and set NTP.

Do I still need a normal DNS server with DoH?

Yes, or a static entry for the DoH server's name, so the router can find the DoH server itself.

Related guides

Start the free trial See pricing