For demonstration, Cloudflare's 1.1.1.1 was used. It can change to any other DNS provider that supports DoH.
/ip dns set servers=1.1.1.1,1.0.0.1/system ntp client set enabled=yes server-dns-names=time.cloudflare.com/tool fetch url=https://curl.se/ca/cacert.pem/certificate import file-name=cacert.pem passphrase=""/ip dns set use-doh-server=https://1.1.1.1/dns-query verify-doh-cert=yes