The DNS uses TCP Port 53 for zone transfers, for maintaining coherence between the DNS database and the server. The UDP protocol is used when a client sends a query to the DNS server. The TCP protocol should not be used for queries as it gives a lot of information, which is useful to attackers.

Where things get interesting is that SSL uses the TCP protocol on port 443. OpenVPN, which is built on OpenSSL libraries, can be configured to run TCP on that same port. Many VPN providers let you do this. When a VPN uses OpenVPN TCP on port 443, any data sent over the connection looks like regular website SSL traffic, not VPN traffic.

Xbox 360 (LIVE) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP Xbox One (LIVE) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP, 500 UDP, 3544 UDP, 4500 UDP: SG: 88 : tcp: trojan: Pwsteal.likmet.a, BackDoor-AXC BroadWave Streaming Audio Server also uses this port: SG: 88 : tcp: Kerberos - authentication system (official) Wikipedia: 88 : tcp

So destination port should be port 80. Now we put "tcp.port == 80" as Wireshark filter and see only packets where port is 80. Port 53: Port 53 is used by DNS. Let's see one DNS packet capture. Here is trying to send DNS query. So destination port should be port 53. tcpdump "(tcp and host or udp port 53" DNS uses port 53 and uses UDP for the transport layer. To filter DNS traffic, the filter udp.port==53 is used.