From owner-freebsd-questions@FreeBSD.ORG Wed Jun 3 23:50:10 2015 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id A90805FE for ; Wed, 3 Jun 2015 23:50:10 +0000 (UTC) (envelope-from joeb1@a1poweruser.com) Received: from s119.web-hosting.com (s119.web-hosting.com [162.213.253.105]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 848D81040 for ; Wed, 3 Jun 2015 23:50:09 +0000 (UTC) (envelope-from joeb1@a1poweruser.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=a1poweruser.com; s=default; h=Content-Transfer-Encoding:Content-Type:Subject:To:MIME-Version:From:Date:Message-ID; bh=8l+cdv6qku4w1TZ81jE3F5LSIbu8SuB3GydE9knr33k=; b=dLd/9RNE7vqYchNNB0EkrMeJUrO2rixkHGN644fNk2eLsiBDixbMLx668PTSHInxH7qRCtYdBXdf4ay/71FXNkUdIZy0iQ12DzynSLoaMHS6Ohr295nxePlK3EwZwYh/pfLxl1SDvDEK4OvquXaujjlN4rDJkJDEC0jgm6GaSeg=; Received: from cpe-76-190-244-6.neo.res.rr.com ([76.190.244.6]:1113 helo=[10.0.10.5]) by server119.web-hosting.com with esmtpsa (TLSv1:DHE-RSA-CAMELLIA256-SHA:256) (Exim 4.82) (envelope-from ) id 1Z0HgX-00464m-2G for freebsd-questions@freebsd.org; Wed, 03 Jun 2015 19:02:58 -0400 Message-ID: <556F87A6.8090105@a1poweruser.com> Date: Wed, 03 Jun 2015 19:03:02 -0400 From: joeb1 User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20130801 Thunderbird/17.0.8 MIME-Version: 1.0 To: "freebsd-questions@freebsd.org" Subject: port 53 under attack Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-OutGoing-Spam-Status: No, score=-1.0 X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - server119.web-hosting.com X-AntiAbuse: Original Domain - freebsd.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - a1poweruser.com X-Get-Message-Sender-Via: server119.web-hosting.com: authenticated_id: joeb1@a1poweruser.com X-Source: X-Source-Args: X-Source-Dir: X-From-Rewrite: unmodified, already matched X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Jun 2015 23:50:10 -0000 Hello list : My firewall blocks unsolicited inbound traffic on port 53. I realize this is the DNS port. But I am getting over 200K hits per day from ip addresses from all over the world. My host has a dynamic ip address. Is there any valid reason for this to be happening?