RadiusNest › Guides

MikroTik DNS setup: servers, cache and static entries

Last updated: 2 October 2026

Your MikroTik can answer DNS for every device on the network and remember the answers, which makes browsing feel faster. It takes two settings to turn on and one firewall rule to keep safe.

1. Tell the router which DNS servers to ask

/ip dns set servers=1.1.1.1,8.8.8.8

If the internet line gets its settings by DHCP or PPPoE, the ISP's servers are added automatically and shown as dynamic-servers. To use only your own, switch that off on the client:

/ip dhcp-client set [find] use-peer-dns=no
/interface pppoe-client set [find] use-peer-dns=no

2. Let your clients ask the router

/ip dns set allow-remote-requests=yes

Without this the router only resolves names for itself. With it, any device that can reach the router may ask, so read the open-resolver section below. Then hand the router out as DNS server in DHCP:

/ip dhcp-server network set [find address=192.168.88.0/24] dns-server=192.168.88.1

Clients pick up the change when they renew their lease. More in DHCP server setup.

3. Cache size

The default cache is 2048 KiB. A busy network with a few hundred users fills it; raise it if cache-used stays close to cache-size:

/ip dns print
/ip dns set cache-size=8192KiB

4. Static entries: your own names

Give a device on your network a name everyone can use:

/ip dns static add name=router.lan address=192.168.88.1
/ip dns static add name=printer.lan address=192.168.88.20
/ip dns static print

Static entries win over the real answer, which is also how sites are blocked by name (see how to block websites). Avoid names ending in .local; phones and computers treat them specially.

5. See and flush the cache

/ip dns cache print
/ip dns cache flush

Flush after you change a static entry or when a site moved and the router still gives the old address. Devices keep their own cache too; reconnecting the Wi-Fi usually clears it.

The danger: an open resolver

With allow-remote-requests=yes, the router also answers DNS questions that arrive from the internet unless the firewall stops them. Attackers find such routers within hours and use them to flood other people. You notice it as a slow line, a processor near 100% and upload traffic on the WAN that nobody on your network is making.

Block DNS from the internet side. Here ether1 is the WAN; use pppoe-out1 if that is your line:

/ip firewall filter
add chain=input in-interface=ether1 protocol=udp dst-port=53 action=drop comment="no DNS from internet"
add chain=input in-interface=ether1 protocol=tcp dst-port=53 action=drop comment="no DNS from internet"

If your firewall already ends with a rule that drops everything else coming from the WAN, as in the basic firewall, you are covered. These two rules must sit above any rule that accepts the traffic. Test from mobile data, not from your own Wi-Fi: a DNS lookup against your public address must time out.

Common problems

  • Clients have internet by address but not by name: allow-remote-requests is off, or DHCP hands out a DNS server that does not answer.
  • The router itself cannot resolve names: no servers are set. Check with :put [:resolve mikrotik.com].
  • Hotspot login page does not open: the hotspot depends on the router's DNS. See hotspot login page not opening.
  • Phones ignore your static entries: private DNS or secure DNS in the browser asks another server directly.

Where RadiusNest fits

RadiusNest does not manage your router's DNS. Hotspot logins do depend on it, because the redirect to the login page starts with a DNS lookup, so a working resolver that is closed to the internet is part of a healthy hotspot whichever way your users are checked.

Start the free trial See pricing

Questions and answers

Which DNS servers should I use on MikroTik?

Any reliable pair works, for example 1.1.1.1 and 8.8.8.8, or the ones your ISP gives you. Set two so one can fail.

Is allow-remote-requests dangerous?

Only when port 53 is reachable from the internet. Keep it on for your LAN and drop DNS arriving on the WAN interface.

How do I clear the DNS cache on MikroTik?

Run /ip dns cache flush, or press Flush in IP, DNS, Cache in Winbox.

Related guides

Start the free trial See pricing