Port 53: Domain Name System
Port 53 carries the Domain Name System (DNS). RFC 1035 defines DNS service on both UDP port 53 and TCP port 53, and RFC 7766 requires all general-purpose DNS implementations to support TCP as well as UDP. Authoritative servers answer for their own zones, while recursive resolvers look up names on behalf of clients.
Port Details
Security Exposure
Open recursive resolvers are abused for DNS amplification, where spoofed queries make the server send large responses to a victim (CISA alert TA13-088A). CISA lists DNS with a bandwidth amplification factor of 28 to 54. Authoritative servers can be abused the same way even when configured correctly, which makes response rate limiting the main defense there.
Hardening
- +Disable recursion on name servers that are only authoritative for their own zones.
- +Restrict recursive resolution to clients on the organization's own networks.
- +Enable Response Rate Limiting on authoritative servers; CISA notes that on Windows Server 2016 the Set-DnsServerResponseRateLimiting cmdlet turns it on.
- +Run authoritative and recursive services on separate systems, as CISA recommends.
- +Apply BCP 38 ingress filtering at network edges to drop packets with spoofed source addresses.
Monitoring
Watch for unusually large or high-volume responses to a single destination. CISA names DNS responses without a matching request as the main indicator of an amplification attack.
DNS Vulnerabilities
2 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-3393 | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | Palo Alto Networks | 8.7 | 29.1% | KEV | 2024-12-27 |
| CVE-2020-1350 | Microsoft Windows DNS Server Remote Code Execution Vulnerability | Microsoft | 10.0 | 96.7% | KEV | 2020-07-14 |
Tools for Auditing and Monitoring DNS
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Is DNS TCP or UDP?→
Both. RFC 1035 defines DNS on UDP and TCP port 53, and RFC 7766 requires general-purpose implementations to support both transports.
What is an open DNS resolver?→
An open resolver answers recursive queries from any client on the internet. CISA alert TA13-088A says the most common form of DNS amplification it observed involves servers that allow unrestricted recursion for any internet client.
Should port 53 be open to the internet?→
Authoritative servers need port 53 reachable to answer for their zones, with recursion disabled. Recursive resolvers should accept queries only from authorized internal clients (CISA TA13-088A).
Which vulnerabilities affect the service on port 53?→
This database lists 2 CVEs related to DNS, 2 of them confirmed as exploited by CISA. Examples: CVE-2024-3393, CVE-2020-1350.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 53 is not guaranteed to be DNS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).