For DoH server connection error: resolving error, give RouterOS an ordinary resolver or a static record for the DoH hostname. For a certificate error, correct the clock or CA trust. Keep verify-doh-cert=yes.
Scope: RouterOS /ip/dns DoH resolver. Browser-managed DoH is a separate path.
Resolving error: provide bootstrap DNS
If both servers and dynamic-servers are empty, add the approved resolver that can resolve your DoH endpoint. Here 192.0.2.53 is a placeholder for that reachable resolver; preserve any required existing servers in the replacement list.
/ip/dns/set servers=192.0.2.53Alternatively, if the provider supplies a stable endpoint IP, add a static record for that endpoint hostname using /ip/dns/static/add name="<DoH-hostname>" address=<provider-endpoint-IP>. Replace both placeholders. A pin needs updating when the provider changes the endpoint; keep the hostname in the HTTPS URL.
Certificate error: correct the clock first
For TLS failures, compare the router date/time with real time. In /system/ntp/client/print, look for status=synchronized. If NTP is absent, configure your reachable time source; use an IP when DNS itself is broken:
/system/ntp/client/set enabled=yes servers=<approved-NTP-IP>Re-read NTP status and the clock before retrying DoH. If time is correct, select the trust path that matches the installed release.
Clock is correct: trust the provider’s CA
Read version in /system/resource/print and the fields actually shown by /certificate/settings/print. The built-in CA store was added in RouterOS 7.19; later releases expose different trust controls.
When builtin-trust-store is available
If /certificate/settings/print shows builtin-trust-store, check that its service list includes dns or uses all. With default, check the default service list in the certificate documentation for your release; the current manual includes dns. If DNS is excluded, add it to the existing service list while preserving the services already required.
Check /certificate/builtin/print for the provider’s CA. SMIPS devices have a smaller built-in list. If that CA is present and available to DNS, a duplicate manual import is unnecessary.
When those trust fields are absent
Before RouterOS 7.19, use the manual CA import below. On 7.19 or later without builtin-trust-store, check the certificate settings documented for that installed release; the property names have changed. If its built-in store cannot supply the required CA to DNS, use the manual import.
When the provider’s CA needs a manual import
Use this path if the required CA is unavailable through built-in trust. Obtain it from the provider’s authenticated documentation, verify its fingerprint, and upload the file through WinBox Files:
/certificate/import file-name=provider-root.crt passphrase="" trusted=no
/certificate/print detailCheck issuer, fingerprint and validity dates before trusting that imported CA. On releases that expose a per-certificate trust-store, also check that the certificate permits dns or all. Use its actual row number:
/certificate/set <imported-CA-id> trusted=yes
/ip/dns/set verify-doh-cert=yesIf crl-use=yes, the DoH manual requires the complete certificate chain for CRL validation; import the provider’s missing chain certificates as well. An expired or wrong-hostname server certificate requires the provider to fix the endpoint. Keep certificate verification enabled.
Connection reset by peer: check the provider’s protocol support
DoH service support depends on the installed release and architecture. Compare the provider’s exact query URL with the DNS manual’s compatibility table, including its HTTP/2 and architecture restrictions. The current manual lists HTTP/2 negotiation on ARM64, x86 and CHR; it lists Mullvad, UncensoredDNS and Quad9 DoH for those platforms only. Verify support in your installed release before selecting one of those endpoints.
Retry the failed lookup with :put [:resolve "<test-name>"], using a real uncached name. Read /log/print where topics~"dns" and repeat the client query. An idle-timeout log without a failed query needs no timeout change.
Inspect the endpoint and bootstrap
/ip/dns/print
/system/clock/print
/system/ntp/client/print
/certificate/settings/print
/certificate/print detail
/system/resource/print
/log/print where topics~"dns"Read use-doh-server for the query URL, servers/dynamic-servers for bootstrap resolvers, and verify-doh-cert for TLS validation. Read architecture-name in system resource output and compare the clock with real time. An account-specific URL may contain a token; keep it private. The DNS manual requires bootstrap resolution through an ordinary resolver or a suitable static entry.