Port 53: DNS

TCP/UDP 53 is the port for Domain Name System. Expose only on authoritative servers. An open recursive resolver gets abused for DNS amplification DDoS attacks.

Port 53 at a glance
ServiceDomain Name System
ProtocolTCP/UDP
Exposure riskMedium: expose with care
Secure alternativeDNS over TLS (853) or DNS over HTTPS (443) for client privacy
RangeWell-known (0–1023): binding needs root/admin on Unix

Your public IP is pre-filled. The test connects over TCP from NetKit's server, so it shows what the internet sees.

What port 53 does

DNS queries normally use UDP port 53; TCP 53 is used for large responses, zone transfers (AXFR) and increasingly for everything as response sizes grow with DNSSEC. Authoritative name servers must be reachable on both.

Should port 53 be open?

Expose only on authoritative servers. An open recursive resolver gets abused for DNS amplification DDoS attacks. Where you can, use DNS over TLS (853) or DNS over HTTPS (443) for client privacy instead.

Find what's listening on port 53

  • Linux: sudo ss -tulpn | grep :53
  • macOS: sudo lsof -nP -i :53
  • Windows: netstat -ano | findstr :53, then look up the PID in Task Manager.

Open or block it in a firewall

  • ufw: sudo ufw allow 53/tcp (or deny)
  • firewalld: sudo firewall-cmd --add-port=53/tcp --permanent && sudo firewall-cmd --reload
  • Windows: New-NetFirewallRule -DisplayName "Port 53" -Direction Inbound -Protocol TCP -LocalPort 53 -Action Allow

Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.

Questions about port 53

What is port 53 used for?
Domain Name System. DNS queries normally use UDP port 53; TCP 53 is used for large responses, zone transfers (AXFR) and increasingly for everything as response sizes grow with DNSSEC. Authoritative name servers must be reachable on both.
Is port 53 TCP or UDP?
Both. DNS uses TCP and UDP on port 53.
Is it safe to open port 53?
Medium: expose with care. Expose only on authoritative servers. An open recursive resolver gets abused for DNS amplification DDoS attacks. Secure alternative: DNS over TLS (853) or DNS over HTTPS (443) for client privacy.
How do I check if port 53 is open?
Use the checker on this page: it connects to your host on TCP 53 from the internet. Locally, run nc -vz host 53 (macOS/Linux) or Test-NetConnection host -Port 53 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :53 (Linux) or netstat -ano | findstr :53 (Windows).

← Port 25 (SMTP) · Port 67 (DHCP server) →