Skip to main content

Port Details

Port
853
Transport
TCP / UDP
Service
DNS over TLS
IANA service name
domain-s
Range
System port (0-1023)
Related ports

Security Exposure

A DoT resolver accepts TLS sessions, so a publicly reachable one consumes connection state for every client; RFC 7858 warns that poor TCP connection management can lead to resource exhaustion and denial of service.

Hardening

  • +Expose a DoT resolver only to the client networks it is meant to serve.
  • +Follow RFC 7766 DNS-over-TCP connection management practices, including idle timeouts and per-client connection limits.
  • +Configure TLS per BCP 195 (RFC 9325): TLS 1.2 minimum and TLS 1.3 preferred.
  • +In managed networks, block outbound TCP and UDP 853 to resolvers other than the approved ones.

Monitoring

Track outbound connections to TCP or UDP 853 that do not go to approved resolvers. On a DoT server, monitor concurrent session counts and handshake failures.

Tools for Auditing and Monitoring DNS over TLS

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What port does DNS over TLS use?→

RFC 7858 says DoT servers must listen on TCP port 853 by default, unless client and server agree on another port.

Does DNS over QUIC use port 853?→

Yes. RFC 9250 specifies UDP port 853 for DoQ and forbids using UDP port 53 for it.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 853 is not guaranteed to be DNS over TLS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).