DNS
Name resolution
Security: Tunnelling and C2 channel; validate DNSSEC, log queries, block open recursion
UDP, TCP · Encrypted: No
Port
Conventionally used by DNS. Port assignments are conventions, so confirm the actual listener before you write a rule around this number.
Name resolution
Security: Tunnelling and C2 channel; validate DNSSEC, log queries, block open recursion
UDP, TCP · Encrypted: No
Decide reachability from the identity of the caller, not from the port number. If the service on this port carries credentials or administrative control, restrict it to an administrative network, require strong authentication, and log every session that reaches it.
Open the interactive map centred on this entity to see everything it connects to and travel outwards from there.