Port 53 — DNS
TCP/UDP well-known
What runs on port 53
Domain name resolution. UDP for normal queries, TCP for responses over 512 bytes and for zone transfers.
Security considerations
An open recursive resolver will be abused for DNS amplification attacks. Restrict recursion to your own networks.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :53
sudo ss -lntp | grep :53
# Windows
netstat -ano | findstr :53
Get-NetTCPConnection -LocalPort 53
# is it reachable from outside?
nc -zv example.com 53
curl -v telnet://example.com:53
Freeing the port
# find the process, then stop it
sudo lsof -ti :53 | xargs kill # Linux / macOS
netstat -ano | findstr :53 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
Usually not. Expose it only if a specific external client needs it, and restrict by source address where you can.
Quick reference
| Port | 53 |
| Protocol | TCP/UDP |
| Service | DNS |
| Range | Well-known (0–1023) — binding requires root on Unix |
Frequently asked questions
What is port 53 used for?
Domain name resolution. UDP for normal queries, TCP for responses over 512 bytes and for zone transfers.
Is it safe to open port 53?
An open recursive resolver will be abused for DNS amplification attacks. Restrict recursion to your own networks.
How do I check if port 53 is open?
Locally, sudo lsof -i :53 on macOS or Linux, or netstat -ano | findstr :53 on Windows. From outside, nc -zv host 53 tells you whether anything answers.
Why do I get "address already in use" on port 53?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :53 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.