DNS, or the Domain Name System, translates a readable domain name such as example.com into the IP address used to locate a service on a network. DNS commonly uses UDP port 53, TCP port 53, and encrypted DNS over TLS on port 853. Each port supports a different connection method, so the port involved can help identify the source of a DNS failure.
A DNS lookup usually involves a device sending a request to a DNS resolver. The resolver finds the information needed to translate the domain name into an IP address and returns the result. This process is part of the hierarchical DNS system described in the mybox DNS overview.
Table of Contents
What is UDP port 53 used for?
UDP port 53 is the most common path for ordinary DNS queries. UDP sends a request without creating a long-lived connection first. This keeps the exchange lightweight and is suitable for the short request and response used by many DNS lookups.
When UDP port 53 works, a device can normally contact its configured resolver and receive an answer for a domain. If UDP traffic is blocked by a firewall or cannot reach the resolver, domain lookups may fail even when the website itself is running.
When does DNS use TCP port 53?
DNS also uses TCP port 53. TCP provides a connection-based exchange and is used when DNS needs that type of transport. A DNS service can therefore depend on both UDP and TCP access on port 53.
Blocking TCP 53 can cause a different failure from blocking UDP 53. Basic lookups may still appear to work over UDP, while requests that need TCP cannot complete. For this reason, allowing only one transport can create an intermittent or partial DNS problem.
What is port 853 used for?
Port 853 is used for DNS over TLS, often shortened to DoT. It carries DNS queries through an encrypted TLS connection instead of sending them as ordinary DNS traffic. The encryption protects the DNS exchange while it travels between the device and the resolver.
DNS over TLS requires more than a reachable DNS address. The device or application must support DNS over TLS, and the network must allow connections to the resolver on TCP port 853. If port 853 is blocked, ordinary DNS on port 53 may still work, but the encrypted DNS connection will fail.
DNS port comparison
| Port | Transport | Role | Typical failure |
|---|---|---|---|
| 53 | UDP | Common DNS queries | The resolver cannot be reached or the response does not return. |
| 53 | TCP | DNS exchanges that use a connection-based transport | Requests that require TCP cannot complete. |
| 853 | TCP with TLS | Encrypted DNS over TLS | The encrypted DNS session cannot connect. |
How DNS ports relate to domains and DNS zones
A DNS port controls how a device communicates with a DNS service. It does not identify the domain itself and does not replace the domain’s DNS records.
A DNS zone contains the records used to answer queries for a domain. Name server, or NS, records identify the servers responsible for that zone. These are related but separate parts of DNS, as described in the mybox explanation of name servers and DNS zones.
This distinction matters during troubleshooting. A domain can have a correct DNS zone while a device cannot reach its resolver. Conversely, a resolver can be reachable while the zone does not contain the expected answer.
How to identify the source of a DNS failure
- Check the resolver path. Confirm which DNS resolver the device or network is using. If no DNS service responds, the issue may be between the device and the resolver rather than with the domain’s website.
- Separate UDP and TCP on port 53. If ordinary DNS queries fail, UDP 53 is a primary path to check. If some lookups work but others fail, TCP 53 may also need to be available.
- Check port 853 separately. A DNS over TLS failure points to the encrypted connection path, the resolver’s DoT service, or a firewall blocking TCP 853. It does not by itself prove that the domain’s DNS zone is incorrect.
- Compare the result with the DNS zone. If the resolver responds but returns no expected domain information, check the domain’s zone and its name server assignment. If the resolver cannot be reached at all, focus first on the firewall or network path.
What normal DNS behaviour looks like
A normal lookup uses the DNS service configured for the device or network and returns an IP address for a domain when the relevant DNS information is available. The lookup may use UDP 53, TCP 53, or encrypted DNS over TLS on port 853, depending on the resolver and the connection method.
DNS is separate from hosting. Hosting stores the website and makes its files available, while the domain and DNS settings direct requests toward the correct hosting environment. The mybox DNS explanation describes how readable domain names are translated into machine-readable IP addresses.