Port 53: DNS

Domain name lookups; UDP for most queries, TCP for large answers and zone transfers. An open resolver answering anyone on the internet gets used for DNS amplification floods. Authoritative servers must be public; resolvers should only answer your own network.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Port Lookup

Port 53 at a glance

Port53
ProtocolTCP/UDP
ServiceDNS
Open to the Internet?Only to addresses that need it
See What Is Listeningss -lntup | grep ':53 '
Test From Outsidenc -zv your-server 53
Block with UFWufw deny 53/tcp; ufw deny 53/udp
Block with nftablesnft add rule inet filter input meta l4proto { tcp, udp } th dport 53 drop

DNS uses TCP/UDP port 53. Domain name lookups; UDP for most queries, TCP for large answers and zone transfers.

An open resolver answering anyone on the internet gets used for DNS amplification floods. Authoritative servers must be public; resolvers should only answer your own network.

Allow port 53 only from the addresses that need it: your office, a VPN or a bastion host. The firewall rule generator builds those rules for nftables, iptables and UFW.

Questions

What is port 53 used for?
DNS. Domain name lookups; UDP for most queries, TCP for large answers and zone transfers.
Is it safe to open port 53?
Only to addresses that need it. An open resolver answering anyone on the internet gets used for DNS amplification floods. Authoritative servers must be public; resolvers should only answer your own network.
How do I check if port 53 is open?
On the server, ss -lntup | grep ':53 ' shows what is listening. From another machine, nc -zv your-server 53 shows whether the firewall lets it through.
How do I block port 53?
With UFW: ufw deny 53/tcp and ufw deny 53/udp. With nftables, add a drop rule for dport 53 in your input chain.

Abuse from open ports on your VMs?

Frabs spots amplification, scans and floods leaving any VM and stops them, without touching your firewall.