News & Updates

How To Secure DNS With Google DoH On Mikrotik

By Victoria Shaw 9 min read 2939 views

How To Secure DNS With Google DoH On Mikrotik

If you’ve spent any time tweaking your network settings, you’ve probably heard about privacy concerns related to standard DNS lookups. Most ISPs intercept these queries, log them, and sometimes even inject ads or block content. It’s a bit intrusive, don’t you think? The good news is that if you are using MikroTik routers, specifically those running the newer RouterOS versions, you can switch to DNS over HTTPS (DoH). This encrypts your DNS traffic, making it slightly harder for snoopers to see exactly what sites you’re trying to visit. Google’s DoH service is one of the most reliable options for this, and setting it up is more straightforward than it sounds.

Why Bother Encrypting Your DNS?

Before we dive into the configuration steps, it helps to understand why this matters. Standard DNS operates over port 53 using plain text. Imagine walking down the street shouting every website you want to visit for everyone to hear. That’s essentially what standard DNS does. While the actual content of the webpage remains encrypted via HTTPS, the initial request to find the server’s IP address is visible to your ISP and anyone else on the network.

By switching to DNS over HTTPS, that query gets wrapped in an encrypted tunnel. It’s still just the domain name, not the full URL, but it adds a significant layer of privacy. It also prevents your ISP from easily redirecting you to their own search pages when you type a mistyped domain. Google’s DoH service is widely supported, fast, and generally reliable, making it a solid choice for home and small office networks.

Checking Your RouterOS Version

The first thing you need to check is your RouterOS version. The native interface for configuring DoH clients was introduced in RouterOS v7.7. If you are running an older version, like v6 or early v7 builds, this feature won’t be available in the menu. You might see workarounds involving certificates and proxies, but they are complex and often unstable. It’s highly recommended to upgrade to at least v7.9 or later via the Software package manager in WinBox. This ensures you have the most stable drivers and security patches.

Once you’ve confirmed your version, open WinBox and connect to your router. Navigate to the IPv6 menu on the left-hand sidebar. Don’t worry if you’re not using IPv6; the DoH configuration lives under this tab regardless of your IPv6 status. You’ll see a sub-menu labeled DNS. Click on that to reveal the settings.

Configuring Google DoH in WinBox

Inside the DNS menu, look for the DoH tab. By default, this is likely unchecked or set to dynamic. To force all DNS queries through Google’s encrypted service, you have a few options. The most direct method is to select fixed from the dropdown menu. This tells the router to ignore any other DNS servers and exclusively use the DoH server you specify.

Next, you need to add the Google DoH server. Click the DNS Server button located just below the DoH setting. In the dialog box that pops up, enter https://dns.google/dns-query. This is the standard endpoint for Google’s public DNS over HTTPS service. You can also add a secondary endpoint for redundancy, such as Cloudflare’s https://cloudflare-dns.com/dns-query, but for the scope of this article, we’ll focus on Google.

After entering the address, click OK to save. Ensure that TCP port is set to 443, as that’s the standard port for HTTPS. If you have a firewall rule blocking outbound 443 traffic from the router itself, DoH will fail. Make sure your firewall allows the router to make outgoing HTTPS connections.

Verifying The Connection

Once you’ve saved the settings, it’s time to test if everything is working. Go back to the IP menu and select DNS. You should see your configured DNS servers listed. But more importantly, check the DoH status. If it’s working, you’ll see a green checkmark or an indication that the connection is active.

To really be sure, try pinging a website from a connected device. Then, check the router’s logs. In WinBox, go to Log and filter for dnsmasq or dns entries. You should see entries indicating that queries are being sent via DoH. If you don’t see this, double-check your firewall rules. Sometimes, a strict firewall setup can block the router’s own ability to reach external DNS servers.

Another quick test is to use an online DNS leak test. Connect a device to your Wi-Fi and visit a site like DNSLeakTest.com. If you see Google’s IP addresses (8.8.8.8 or 8.8.4.4) instead of your ISP’s DNS servers, you’re good to go. This confirms that all your DNS traffic is being routed through the encrypted tunnel.

Troubleshooting Common Issues

Like any network change, this can sometimes cause hiccups. The most common issue is latency. DoH adds a tiny bit of overhead because the DNS query has to be encrypted and decrypted. For most users, this is negligible. However, if you notice slight delays in opening websites, consider switching back to dynamic mode and let the router choose between standard DNS and DoH based on availability. This is a good balance between privacy and performance.

Another issue is certificate validation. RouterOS v7 uses the system’s trust store to verify the DoH server’s certificate. If your router’s clock is wrong, certificate validation will fail. Go to the System menu and check Clock. Ensure your system time is correct, preferably synced with an NTP server. Incorrect time is a surprisingly common reason for DoH failures.

If you’re still having trouble, check the IP > DNS > Servers list. Make sure the server address is exactly correct. A typo in the URL will obviously break the connection. Also, ensure that the Use DNS Client option is checked in the main DNS menu. This option is crucial for the router to properly hide client IPs and use its own IP for DNS requests.

FAQ

Will DoH slow down my internet?

In most cases, the performance impact is minimal. You might notice a slight increase in DNS resolution time, but actual browsing speed will remain the same. If you experience noticeable lag, check your NTP settings or consider using a closer DNS provider.

Do I need to configure anything on my devices?

No. Once configured on the MikroTik router, all devices on your network automatically benefit from DoH. You do not need to change settings on your phones, laptops, or smart TVs.

Can I use Cloudflare instead of Google?

Yes. Simply replace the Google DoH URL with https://cloudflare-dns.com/dns-query in the DNS Server configuration. Cloudflare is another reputable provider that offers similar privacy benefits.

What if my router reboots?

The settings are saved in the router’s configuration. However, it’s a good practice to run /system backup save after making changes to create a backup file just in case.

Tutorial For Newbie: Using DNS over HTTPS ( DOH ) on Mikrotik v6.47
Implementing DNS-over-HTTPS (DoH) with Google DNS on MikroTik - Pratama ...
Tutorial For Newbie: Using DNS over HTTPS ( DOH ) on Mikrotik v6.47
Cara Mengaktifkan DNS Over HTTPS (DoH) Di Mikrotik – DDS WEB ID

Written by Victoria Shaw

Victoria Shaw is a Senior Journalist with over a decade of experience covering business, public affairs, and community issues. She draws on interviews, original documents, and historical context to explain consequential developments and examine what they mean for the people affected.


You Might Like