MikroTik
MikroTik routers use the open-source RouterOS operating system, which provides routing, wireless networking, and firewall services for home and small office networks.
Configure DNS-over-HTTPS
- Access your MikroTik router:
- Open your web browser and go to your router's IP address (usually
192.168.88.1
) - Alternatively, you can use Winbox to connect to your MikroTik router
- Enter your administrator username and password
- Open your web browser and go to your router's IP address (usually
- Import root certificate:
- Download the latest bundle of trusted root certificates: https://curl.se/docs/caextract.html
- Navigate to Files. Click Upload and select the downloaded cacert.pem certificate bundle
- Go to System → Certificates → Import
- In the File Name field, choose the uploaded certificate file
- Click Import
- Configure DNS-over-HTTPS:
- Go to IP → DNS
- In the Servers section, add the following AdGuard DNS servers:
94.140.14.49
94.140.14.59
- Set Allow Remote Requests to Yes (this is crucial for DoH to function)
- In the Use DoH server field, enter the URL of the Private AdGuard DNS server:
https://d.adguard-dns.com/dns-query/*******
- Click OK
- Create Static DNS Records:
- In the DNS Settings, click Static
- Click Add New
- Set Name to
d.adguard-dns.com
- Set Type to
A
- Set Address to
94.140.14.49
- Set TTL to
1d 00:00:00
- Repeat the process to create an identical entry, but with Address set to
94.140.14.59
- Disable Peer DNS on DHCP Client:
- Go to IP → DHCP Client
- Double-click the client used for your Internet connection (usually on the WAN interface)
- Uncheck Use Peer DNS
- Click OK
- Test and verify:
- You might need to reboot your MikroTik router for all changes to take effect
- Clear your browser's DNS cache. You can use a tool like https://www.dnsleaktest.com to check if your DNS requests are now routed through AdGuard
My router does not support DNS-over-HTTPS
Use these instructions if your MikroTik router does not support DNS-over-HTTPS configuration:
- Access your MikroTik router:
- Open your web browser and go to your router's IP address (usually
192.168.88.1
) - Alternatively, you can use Winbox to connect to your MikroTik router
- Enter your administrator username and password
- Open your web browser and go to your router's IP address (usually
- Configure Plain DNS:
- Go to IP → DNS
- In the Servers section, add the following AdGuard DNS servers:
- IPv4:
94.140.14.49
and94.140.14.59
- IPv6:
2a10:50c0:0:0:0:0:ded:ff
and2a10:50c0:0:0:0:0:dad:ff
- Dedicated IPv6: Private AdGuard DNS supports dedicated IPv6 addresses. To find them, open the Dashboard, click Settings next to your device → Plain DNS server addresses → Dedicated IPv6 addresses.
- IPv4:
- Click OK
- Disable Peer DNS on DHCP Client:
- Go to IP → DHCP Client
- Double-click the client used for your Internet connection (usually on the WAN interface)
- Uncheck Use Peer DNS
- Click OK