Skip to main content

Port Details

Port
5353
Transport
UDP
Service
mDNS
IANA service name
mdns
Range
User port (1024-49151)
Related ports

Security Exposure

mDNS is meant for the local link, so a responder reachable from the internet leaks information: Shadowserver reports that exposed mDNS can be probed by unicast and may disclose device names, services, IP and MAC addresses. CISA lists mDNS among UDP protocols abused for amplification, with an amplification factor of 2 to 10. On the local link, MITRE ATT&CK T1557.001 describes adversaries responding to mDNS traffic to poison name resolution.

Hardening

  • +Block UDP 5353 at the network perimeter in both directions.
  • +Configure responders to ignore unicast queries whose source address is not on the local link, as RFC 6762 recommends.
  • +Disable mDNS responders on servers that do not need service discovery.
  • +Segment printers, IoT devices and media devices so their mDNS traffic stays on their own VLAN.

Monitoring

Alert on UDP 5353 traffic crossing the network boundary and on large mDNS responses sent to external addresses.

Tools for Auditing and Monitoring mDNS

Responder

Open Source
Penetration Testing Tools

LLMNR, NBT-NS, and mDNS poisoner that captures network credentials and runs rogue authentication servers during authorized internal assessments.

LicenseGPL-3.0-or-later
PlatformLinux, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Frequently Asked Questions

Is port 5353 TCP or UDP?→

mDNS uses UDP port 5353 according to RFC 6762. IANA also registers TCP 5353, but queries and responses are UDP multicast.

Should port 5353 be open to the internet?→

No. mDNS is designed for the local link, and Shadowserver and CISA both flag internet-reachable mDNS as an exposure and an amplification vector.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5353 is not guaranteed to be mDNS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).