pjhtech Tools
MikroTik

MikroTik “DoH server connection error”: DNS over HTTPS Checks

Diagnose resolving error, SSL errors and connection reset by peer using DoH bootstrap DNS, endpoint compatibility and certificate validation.

For DoH server connection error: resolving error, give RouterOS an ordinary resolver or a static record for the DoH hostname. For a certificate error, correct the clock or CA trust. Keep verify-doh-cert=yes.

Scope: RouterOS /ip/dns DoH resolver. Browser-managed DoH is a separate path.

Resolving error: provide bootstrap DNS

If both servers and dynamic-servers are empty, add the approved resolver that can resolve your DoH endpoint. Here 192.0.2.53 is a placeholder for that reachable resolver; preserve any required existing servers in the replacement list.

Configuration change • adapt the example identifiers
/ip/dns/set servers=192.0.2.53

Alternatively, if the provider supplies a stable endpoint IP, add a static record for that endpoint hostname using /ip/dns/static/add name="<DoH-hostname>" address=<provider-endpoint-IP>. Replace both placeholders. A pin needs updating when the provider changes the endpoint; keep the hostname in the HTTPS URL.

Certificate error: correct the clock first

For TLS failures, compare the router date/time with real time. In /system/ntp/client/print, look for status=synchronized. If NTP is absent, configure your reachable time source; use an IP when DNS itself is broken:

Configuration change • adapt the example identifiers
/system/ntp/client/set enabled=yes servers=<approved-NTP-IP>

Re-read NTP status and the clock before retrying DoH. If time is correct, select the trust path that matches the installed release.

Clock is correct: trust the provider’s CA

Read version in /system/resource/print and the fields actually shown by /certificate/settings/print. The built-in CA store was added in RouterOS 7.19; later releases expose different trust controls.

When builtin-trust-store is available

If /certificate/settings/print shows builtin-trust-store, check that its service list includes dns or uses all. With default, check the default service list in the certificate documentation for your release; the current manual includes dns. If DNS is excluded, add it to the existing service list while preserving the services already required.

Check /certificate/builtin/print for the provider’s CA. SMIPS devices have a smaller built-in list. If that CA is present and available to DNS, a duplicate manual import is unnecessary.

When those trust fields are absent

Before RouterOS 7.19, use the manual CA import below. On 7.19 or later without builtin-trust-store, check the certificate settings documented for that installed release; the property names have changed. If its built-in store cannot supply the required CA to DNS, use the manual import.

When the provider’s CA needs a manual import

Use this path if the required CA is unavailable through built-in trust. Obtain it from the provider’s authenticated documentation, verify its fingerprint, and upload the file through WinBox Files:

Import the verified CA, then identify its new certificate row
/certificate/import file-name=provider-root.crt passphrase="" trusted=no
/certificate/print detail

Check issuer, fingerprint and validity dates before trusting that imported CA. On releases that expose a per-certificate trust-store, also check that the certificate permits dns or all. Use its actual row number:

Configuration change • adapt the example identifiers
/certificate/set <imported-CA-id> trusted=yes
/ip/dns/set verify-doh-cert=yes

If crl-use=yes, the DoH manual requires the complete certificate chain for CRL validation; import the provider’s missing chain certificates as well. An expired or wrong-hostname server certificate requires the provider to fix the endpoint. Keep certificate verification enabled.

Connection reset by peer: check the provider’s protocol support

DoH service support depends on the installed release and architecture. Compare the provider’s exact query URL with the DNS manual’s compatibility table, including its HTTP/2 and architecture restrictions. The current manual lists HTTP/2 negotiation on ARM64, x86 and CHR; it lists Mullvad, UncensoredDNS and Quad9 DoH for those platforms only. Verify support in your installed release before selecting one of those endpoints.

Retry the failed lookup with :put [:resolve "<test-name>"], using a real uncached name. Read /log/print where topics~"dns" and repeat the client query. An idle-timeout log without a failed query needs no timeout change.

Inspect the endpoint and bootstrap

Read-only
/ip/dns/print
/system/clock/print
/system/ntp/client/print
/certificate/settings/print
/certificate/print detail
/system/resource/print
/log/print where topics~"dns"

Read use-doh-server for the query URL, servers/dynamic-servers for bootstrap resolvers, and verify-doh-cert for TLS validation. Read architecture-name in system resource output and compare the clock with real time. An account-specific URL may contain a token; keep it private. The DNS manual requires bootstrap resolution through an ordinary resolver or a suitable static entry.

References