Port 5352DNS Long-Lived Queries

DNS extension for keeping queries open and delivering answers when matching records change.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 994 of 2,612 · top 38%

also known as dns-llq

Technical Details

what runs on :5352

LLQ extends DNS query exchanges with a setup and lease mechanism for persistent queries, after which the server sends DNS-formatted responses as matching records are added, removed, or changed. It can use UDP or TCP on port 5352; DNS message framing is retained, including the two-byte length prefix for TCP. LLQ is separate from ordinary DNS service on port 53 and does not provide encryption by itself.

Security Information

exposure of :5352

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

network services averages 3.0 across 992 ports — this one sits 1.0 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Traffic is normally cleartext, so query contents and change notifications can be observed or modified by an on-path attacker. An exposed implementation may also consume resources through long-lived or numerous queries; internet exposure is generally unnecessary unless the service is deliberately used for wide-area discovery.

the 8 most looked-up other ports in network services — 992 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted