---
title: How to block DNS resolution from outside in Mikrotik
slug: how-to-block-dns-resolution-from-outside-in-mikrotik
description: Enhance your network security by learning how to block incoming DNS service connections on port 53 to mitigate cyber threats like DDoS attacks. 
docTags: 
createdAt: 2024-02-05T13:02:30.029Z
---

## Overview

It is very important to block the DNS service on port 53 for incoming connections on your Router or Firewall. Doing this increases your network security and helps avoid cyber attacks such as DDOS.

## Configuration Steps

To secure your network, connect to your MikroTik using Winbox and open a New Terminal. Copy and paste the following commands into the console:

:::CodeblockTabs
routeros

```bash
/ip firewall filter 
add chain=input in-interface=IN-INT protocol=udp dst-port=53 action=drop
add chain=input in-interface=IN-INT protocol=tcp dst-port=53 action=drop

/ip firewall filter
add chain=forward in-interface=IN-INT protocol=udp dst-port=53 action=drop
add chain=forward in-interface=IN-INT protocol=tcp dst-port=53 action=drop
```
:::

:::hint{type="info"}
Before executing the commands, you must replace IN-INT in the code above with the actual name of your MikroTik WAN interface.
:::

:::hint{type="warning"}
If you use multiple WAN interfaces on your MikroTik, you must re-run the commands above multiple times, replacing IN-INT with the names of all your other WAN interfaces to ensure complete protection.
:::

