Port 853DNS over TLS

Encrypted DNS resolution using TLS, conventionally on TCP port 853.

transport
tcp · udp

2 transports registered

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
3/10

caution

lookups
0

rank 994 of 2,854 · top 35%

Technical Details

what runs on :853

DoT runs DNS over a TLS connection, normally using TCP, with the TLS handshake preceding DNS queries. Each DNS message is framed with a two-byte length field, as specified for DNS over TCP, and the default TLS service is port 853. Plain DNS generally uses port 53, while DNS over HTTPS uses port 443; RFC 8094 defines DNS over DTLS for UDP 853.

Security Information

exposure of :853

risk score

3/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.3 across 294 ports — this one sits 0.3 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

TLS encrypts DNS contents and provides server authentication when certificate validation is used, but the resolver can still observe queries and clients can expose connection metadata. Publicly reachable recursive resolvers should be access-controlled or deliberately operated as public services, because open resolvers can be abused for query load and DNS-related denial-of-service activity.

the 8 most looked-up other ports in security — 294 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted