Skip to main content

Port Details

Port
53
Transport
UDP / TCP
Service
DNS
IANA service name
domain
Range
System port (0-1023)

Security Exposure

Open recursive resolvers are abused for DNS amplification, where spoofed queries make the server send large responses to a victim (CISA alert TA13-088A). CISA lists DNS with a bandwidth amplification factor of 28 to 54. Authoritative servers can be abused the same way even when configured correctly, which makes response rate limiting the main defense there.

Hardening

  • +Disable recursion on name servers that are only authoritative for their own zones.
  • +Restrict recursive resolution to clients on the organization's own networks.
  • +Enable Response Rate Limiting on authoritative servers; CISA notes that on Windows Server 2016 the Set-DnsServerResponseRateLimiting cmdlet turns it on.
  • +Run authoritative and recursive services on separate systems, as CISA recommends.
  • +Apply BCP 38 ingress filtering at network edges to drop packets with spoofed source addresses.

Monitoring

Watch for unusually large or high-volume responses to a single destination. CISA names DNS responses without a matching request as the main indicator of an amplification attack.

DNS Vulnerabilities

2 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Palo Alto Networks8.729.1%KEV2024-12-27
CVE-2020-1350
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Microsoft10.096.7%KEV2020-07-14

Tools for Auditing and Monitoring DNS

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is DNS TCP or UDP?→

Both. RFC 1035 defines DNS on UDP and TCP port 53, and RFC 7766 requires general-purpose implementations to support both transports.

What is an open DNS resolver?→

An open resolver answers recursive queries from any client on the internet. CISA alert TA13-088A says the most common form of DNS amplification it observed involves servers that allow unrestricted recursion for any internet client.

Should port 53 be open to the internet?→

Authoritative servers need port 53 reachable to answer for their zones, with recursion disabled. Recursive resolvers should accept queries only from authorized internal clients (CISA TA13-088A).

Which vulnerabilities affect the service on port 53?→

This database lists 2 CVEs related to DNS, 2 of them confirmed as exploited by CISA. Examples: CVE-2024-3393, CVE-2020-1350.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 53 is not guaranteed to be DNS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).