How to Enable DoH on MikroTik
Overview
The DNS over HTTPS protocol, commonly referred to as DoH, allows you to encrypt DNS requests, improving both security and privacy while browsing. Follow the steps below to enable this secure protocol on MikroTik routers using our servers.
Configuration Steps
Connect to the Router and Open the Console
Access your MikroTik router using WinBox or the web interface. Once connected, open the MikroTik terminal by clicking on New Terminal from the main menu.
Download and Import the Root Certificate
You must download and install the root certificate to ensure proper certificate verification. Type or paste the following commands into the terminal:
/tool fetch url=https://download.fsflt.com/fs_rootca/fs_rootca.pem
/certificate import file-name=fs_rootca.pemEnable the Encrypted Protocol
Enable the service by specifying your unique server URL and requesting certificate verification. Paste this command into the terminal:
/ip dns set use-doh-server=https://doh.fsflt.com/123456 verify-doh-cert=yesYou must replace 123456 in the URL with your specific customer code or the unique token generated in your dashboard under the DoH section.
Verify Operation
Check that the router is correctly using the encrypted servers by running this verification command:
/ip dns printMake sure the use-doh-server field in the output is correctly set to your specific URL.
If you are using a multi-WAN configuration or a local DNS setup, ensure that your firewall or NAT rules allow HTTPS traffic on port 443 to the domain doh.fsflt.com.