Port 853: DNS over TLS, DTLS and QUIC
TCP 853 is the default port for DNS over TLS (DoT), defined in RFC 7858 for encrypted queries between stub clients and recursive resolvers. UDP 853 is used by DNS over QUIC (RFC 9250) and the experimental DNS over DTLS (RFC 8094). RFC 9250 notes that the DNS over DTLS specification is experimental and has no known implementations.
Port Details
Security Exposure
A DoT resolver accepts TLS sessions, so a publicly reachable one consumes connection state for every client; RFC 7858 warns that poor TCP connection management can lead to resource exhaustion and denial of service.
Hardening
- +Expose a DoT resolver only to the client networks it is meant to serve.
- +Follow RFC 7766 DNS-over-TCP connection management practices, including idle timeouts and per-client connection limits.
- +Configure TLS per BCP 195 (RFC 9325): TLS 1.2 minimum and TLS 1.3 preferred.
- +In managed networks, block outbound TCP and UDP 853 to resolvers other than the approved ones.
Monitoring
Track outbound connections to TCP or UDP 853 that do not go to approved resolvers. On a DoT server, monitor concurrent session counts and handshake failures.
Tools for Auditing and Monitoring DNS over TLS
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
What port does DNS over TLS use?→
RFC 7858 says DoT servers must listen on TCP port 853 by default, unless client and server agree on another port.
Does DNS over QUIC use port 853?→
Yes. RFC 9250 specifies UDP port 853 for DoQ and forbids using UDP port 53 for it.
Sources
- IANA Service Name and Port Number Registry: port 853
- RFC 7858: Specification for DNS over Transport Layer Security (TLS)
- RFC 9250: DNS over Dedicated QUIC Connections
- RFC 8094: DNS over Datagram Transport Layer Security (DTLS)
- RFC 9325: Recommendations for Secure Use of TLS and DTLS
- RFC 7766: DNS Transport over TCP, Implementation Requirements
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 853 is not guaranteed to be DNS over TLS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).