Port 53: DNS
TCP/UDP 53 is the port for Domain Name System. Expose only on authoritative servers. An open recursive resolver gets abused for DNS amplification DDoS attacks.
| Service | Domain Name System |
|---|---|
| Protocol | TCP/UDP |
| Exposure risk | Medium: expose with care |
| Secure alternative | DNS over TLS (853) or DNS over HTTPS (443) for client privacy |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 53 does
DNS queries normally use UDP port 53; TCP 53 is used for large responses, zone transfers (AXFR) and increasingly for everything as response sizes grow with DNSSEC. Authoritative name servers must be reachable on both.
Should port 53 be open?
Expose only on authoritative servers. An open recursive resolver gets abused for DNS amplification DDoS attacks. Where you can, use DNS over TLS (853) or DNS over HTTPS (443) for client privacy instead.
Find what's listening on port 53
- Linux:
sudo ss -tulpn | grep :53 - macOS:
sudo lsof -nP -i :53 - Windows:
netstat -ano | findstr :53, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 53/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=53/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 53" -Direction Inbound -Protocol TCP -LocalPort 53 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 53
What is port 53 used for?
Is port 53 TCP or UDP?
Is it safe to open port 53?
How do I check if port 53 is open?
nc -vz host 53 (macOS/Linux) or Test-NetConnection host -Port 53 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :53 (Linux) or netstat -ano | findstr :53 (Windows).