
DNS
Router DNS, IP Cloud, transparent DNS: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

MikroTik firewall address list: how they work in RouterOS 7
An address list is a named list of addresses that firewall rules use instead of a manually written address. You add the entries yourself (static) or the firewall adds them automatically as traffic passes (dynamic, usually with an expiration). This mechanism is the basis for blacklists, port knocking, management allowlists, and domain filters.
Knowledge baseMikroTik IP Cloud: How RouterOS Dynamic DNS Works
IP Cloud is the free service that gives your router a fixed DNS name, serial-number.sn.mynetname.net, which follows the public IP address. The router asks the MikroTik server, "What address do you see me at?" and the name points to that answer, even behind a NAT. The name is used to find the router, not to open it.
DojoBlocking DNS over HTTPS and DNS over TLS with MikroTik
Encrypted DNS bypasses the router's filter: how to block DoT and DoH on RouterOS 7 using port 853, a name-based address list, the tls-host matcher, and Firefox's canary domain, all tested in the lab.
DojoTransparent DNS with bridge NAT: the invisible MikroTik that answers for everyone
A bridged MikroTik, invisible to the network, intercepting every DNS request to any server: bridge NAT and IP NAT working together on RouterOS 7, with an example of blocking a website.
DojoMikroTik IP Cloud: a fixed name for the router with a dynamic IP
IP Cloud is MikroTik's free dynamic DNS: it gives the router a fixed name that follows the public address even when it changes. How to enable it, how to verify it, what happens behind the ISP's modem, and why the name alone does not expose the router to the internet.
SecurityDNS cache poisoning vulnerability in RouterOS
CVE-2019-3979 is a high-risk vulnerability that allows a malicious DNS server to poison the router's DNS cache by adding unsolicited A records. It affects RouterOS versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. To mitigate the risk, you must update the firmware or block incoming DNS traffic from the untrusted network.
SecurityDNS Cache Poisoning Vulnerability in RouterOS
CVE-2019-3978 allows unauthenticated remote attackers to generate DNS queries toward arbitrary servers, potentially poisoning the router's DNS cache. RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must update the firmware to a later version or block access to the DNS service from untrusted networks.