Port 5353: Multicast DNS
Port 5353 carries Multicast DNS, which lets hosts on the same link resolve names ending in .local and discover services without a DNS server. RFC 6762 defines mDNS as DNS-like queries and responses sent over IP multicast to UDP port 5353. IANA lists mdns on both TCP and UDP 5353.
Port Details
Security Exposure
mDNS is meant for the local link, so a responder reachable from the internet leaks information: Shadowserver reports that exposed mDNS can be probed by unicast and may disclose device names, services, IP and MAC addresses. CISA lists mDNS among UDP protocols abused for amplification, with an amplification factor of 2 to 10. On the local link, MITRE ATT&CK T1557.001 describes adversaries responding to mDNS traffic to poison name resolution.
Hardening
- +Block UDP 5353 at the network perimeter in both directions.
- +Configure responders to ignore unicast queries whose source address is not on the local link, as RFC 6762 recommends.
- +Disable mDNS responders on servers that do not need service discovery.
- +Segment printers, IoT devices and media devices so their mDNS traffic stays on their own VLAN.
Monitoring
Alert on UDP 5353 traffic crossing the network boundary and on large mDNS responses sent to external addresses.
Tools for Auditing and Monitoring mDNS
Responder
Open SourceLLMNR, NBT-NS, and mDNS poisoner that captures network credentials and runs rogue authentication servers during authorized internal assessments.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Frequently Asked Questions
Is port 5353 TCP or UDP?→
mDNS uses UDP port 5353 according to RFC 6762. IANA also registers TCP 5353, but queries and responses are UDP multicast.
Should port 5353 be open to the internet?→
No. mDNS is designed for the local link, and Shadowserver and CISA both flag internet-reachable mDNS as an exposure and an amplification vector.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5353 is not guaranteed to be mDNS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).