Checking only UDP access for DNS is an incomplete diagnostic. Due to situations requiring TCP, some queries may work while others may fail.
Basic approach
Classic DNS uses both UDP and TCP transports. Situations such as large responses and switching to TCP after an truncated UDP response increase the importance of TCP access. Encrypted DNS methods may use different transport schemes.
Application steps
- Record whether the problem is concentrated on certain record types or large responses.
- Check the UDP and TCP access policies between the client and the resolver separately.
- Compare timeout, truncation, and retry behavior in network logs.
Practical example
If a small A query succeeds but the larger signed response fails, simply changing the registration of the domain name may not be the right approach. TCP obstruction or packet size issue on the transport path should be investigated.
Interpret the result correctly
Opening a TCP 53 connection does not in itself prove successful DNS resolution. The response to the appropriate query should also be evaluated. Do not present the result of a general port checker and the protocol-level DNS test as the same measurement.
Source and follow-up reading
Protocol or command details: RFC 7766. The steps and example scenario are IPScans editorial narrative.