DNS Query “sl” in Mikrotik DNS Cache

Sounds like this could be from a potential scan. The record is useless as doesn’t go to anything.


We can block this type of behavior by blocking inbound DNS request. Change in-interface to your interface or change to an interface list.

ip firewall filter add chain=input protocol=6 dst-port=53 in-interface=ether1 action=drop
ip firewall filter add chain=input protocol=17 dst-port=53 in-interface=ether1 action=drop