Port 53: DNS
Port 53 is used by DNS, the system that turns names like example.com into IP addresses.
What runs on port 53
DNS servers listen on UDP 53 for ordinary lookups and on TCP 53 for large answers and zone transfers. Every device asks a DNS server on port 53 before it connects to almost anything by name. Encrypted variants exist (DNS over TLS on 853, DNS over HTTPS on 443), but plain port 53 is still the default.
On a home network
Your router almost always runs a small DNS forwarder on port 53 and hands its own address to your devices as their DNS server. Pi-hole, AdGuard Home and some NAS boxes also listen on 53 when you set them up as network-wide ad blockers.
If port 53 is reachable from the internet
Port 53 open on the LAN side of your router is expected. Open to the internet, it usually means an open resolver, a DNS server that answers anyone. Open resolvers are the raw material for DNS amplification attacks, where attackers send small spoofed queries and the server fires much larger answers at a victim. Unless you deliberately run a public authoritative DNS server, 53 should not answer from outside.
How to check whether it is open on your network
From outside your network, send a DNS query to your public IP; if you get an answer, something is acting as an open resolver. RECON's Exposure Check covers this kind of outside-in test.
To find out whether port 53 is open on something in your home, and whether the internet can reach it, the app scans your Wi-Fi from your phone and checks your public address from the outside. It says what it checked and what it could not. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.