Dojo
Practical howtos on MikroTik and RouterOS 7: tested configurations, ready-to-copy commands.

Send emails from MikroTik with Gmail: SMTP and app passwords
A MikroTik can send emails (alerts, backups, reports) using a Gmail account as the SMTP server: smtp.gmail.com, port 587, STARTTLS. However, the password is not the account password: you need an app password, which Google only issues when two-step verification is enabled. In RouterOS 7, the configuration is located in /tool e-mail.
DojoUnauthorized DHCP server: how to detect and block it with MikroTik
An unauthorized DHCP server, often a mall WiFi router connected "backwards", can bring a LAN to its knees in minutes. With MikroTik, you can detect it using /ip dhcp-server alert, which notifies you when a server other than the valid one responds, and block it using bridge DHCP snooping, which in RouterOS 7 accepts DHCP responses only from trusted ports.
DojoWireless scan on a remote MikroTik without losing the result
A frequency scan stops the radio for a few seconds: if you reach the remote router through that wireless link, you lose the connection and the result. The solution is to run the scan in the background on the router itself, saving the result to a file to read once the link is back. In RouterOS 7, this is done with :execute and the file= parameter, which works with both the wifi and wireless packages.
DojoHow to hide your MikroTik routers from traceroute
A traceroute launched by a client shows each router in your network, along with their addresses. By using a mangle rule that increments the TTL (action=change-ttl new-ttl=increment:1), every MikroTik router becomes invisible to traceroute, because the packet passes through it without "consuming" a hop. The rule must be limited to client traffic and applied carefully to avoid complicating troubleshooting.
DojoCAPsMAN and WiFi RouterOS 7: enabling client isolation
Client isolation prevents devices connected to the same WiFi network from communicating with each other: in a hotspot or guest network, it is the first defense against people snooping on others' phones. In RouterOS 7, with the new wifi package and its CAPsMAN, it is enabled with client-isolation=yes in the datapath; with the old wireless package, default-forwarding remains, and in CAPsMAN v1, client-to-client-forwarding.
DojoHow to aggregate multiple internet connections with MikroTik: ECMP and PCC in RouterOS 7
With a MikroTik, you can use two or more internet connections together. ECMP (multiple default routes with the same distance) is the simplest method but does not let you decide which line a connection uses; PCC (Per Connection Classifier) assigns each connection to a line and keeps it there until the end. In RouterOS 7, PCC uses routing tables (/routing table) and gateway checking with check-gateway. We build it in six steps.
DojoHow to reset a MikroTik configuration with RouterOS 7
To reset a MikroTik from the terminal, use the /system reset-configuration command: with no-defaults=yes, the router boots empty instead of with the factory configuration; with run-after-reset, it runs a script immediately after rebooting. If the router no longer responds, use the reset button or, as a last resort, Netinstall.
DojoMikroTik Hotspot: Protecting the LAN from WiFi Clients
In a MikroTik hotspot, guest clients must not be able to reach the customer's network (servers, printers, NAS). A single firewall rule using the hotspot=from-client matcher is enough; if the network to protect is not known in advance because the WAN gets its address via DHCP, a DHCP client script automatically updates it in an address list.
DojoMikroTik DHCP server: run a script on every lease
The RouterOS DHCP server can run a script every time it assigns or releases an address: this is the lease-script. Inside the script, variables such as $leaseBound, $leaseActIP, and $leaseActMAC are already available, allowing you to log new devices, send email notifications, or add the client to an address list with an expiration.
DojoHow to create a WiFi hotspot with MikroTik and RouterOS 7
A WiFi hotspot with a captive portal on MikroTik is built in seven steps: reset, WAN, guest network on a bridge, radio, /ip hotspot setup wizard, test, and final cleanup. In RouterOS 7, the radio part changes significantly, as recent models use the new wifi package instead of wireless. The addresses in the example are from my lab: adapt them to your network.