Glossary/Processes you will see

mDNSResponder

Also: Bonjour and DNS

Quick answer

mDNSResponder is the macOS process that turns every domain name into an address. It is the Mac's DNS resolver, and it also runs Bonjour, which finds printers, AirPlay speakers, shared Macs and other devices on your local network without any setup.

When any app opens a website or connects to a server, it asks mDNSResponder for the address. It caches the answers, so repeated lookups are instant. It runs as its own system account, _mdnsresponder, not as you.

Its load follows how many names are being looked up. A browser with many tabs, a VPN, or a busy local network with many Bonjour devices all give it more to do.

Why mDNSResponder is using CPU

Short spikes come from bursts of lookups: many new tabs, an app syncing with many servers, or devices joining the network. Sustained use usually points to something retrying lookups in a loop, a misbehaving VPN or DNS filter, or a network where Bonjour announcements never stop.

When websites fail to load by name but work by address, or a site changed servers and the Mac still goes to the old one, the cache is the suspect.

How to flush the DNS cache

Two commands in Terminal clear the cache on recent macOS and tell mDNSResponder to reload, with no restart needed.

  1. Open Terminal.
  2. Run sudo dscacheutil -flushcache, and enter your password when asked.
  3. Run sudo killall -HUP mDNSResponder.

How to see what mDNSResponder is doing

It runs as its own system account, so Activity Monitor hides it until you ask for every process. Terminal can show its two jobs, DNS and Bonjour, one at a time.

  1. Open Activity Monitor, choose View → All Processes and type mdns in the search field. You will see mDNSResponder under the _mdnsresponder account, and mDNSResponderHelper under root.
  2. Watch % CPU on the CPU tab and the packet columns on the Network tab. Short spikes are normal. A steady load while you are not browsing is worth a look.
  3. To see which DNS servers the Mac is using, open Terminal and run scutil --dns. Resolver #1 lists the servers used for most lookups under nameserver[0], nameserver[1] and so on.
  4. To test a lookup through mDNSResponder itself, run dns-sd -G v4v6 apple.com. It prints each address as it arrives. Press Control-C to stop.
  5. To see what Bonjour finds on your network, run dns-sd -B _services._dns-sd._udp local.. It lists the kinds of service that devices around you announce, such as _airplay and _ipp for printers. Press Control-C to stop.

Normal mDNSResponder use vs a problem

Normal: close to zero, with brief spikes when you open many tabs, join a network, or a device on the network wakes up.

Worth looking into: steady CPU or network use for hours, or names that fail to resolve on one network but work on another. The usual causes:

  • A VPN or DNS filter that adds its own resolvers and keeps changing them. scutil --dns shows extra resolvers with a domain line when a VPN sends some names to its own servers.
  • An app or script that looks up names in a tight loop, often one that keeps retrying a server it cannot reach.
  • A busy local network, such as an office or a shared building, with many devices announcing themselves over Bonjour.
  • A network that hands out a DNS server that is slow or does not answer, so lookups wait and retry.

DNS and Bonjour: the two jobs

Names on the internet, such as apple.com, go to the DNS servers your network or you have set. Names ending in .local, such as your Mac's own network name, never leave the local network: mDNSResponder asks the devices around it directly, which is the multicast DNS that gives it the m in its name.

That is why scutil --dns lists resolvers for local marked mdns. If a printer or a shared Mac can be reached by its .local name at home but not at work, the work network is blocking those local announcements, not the internet.

Questions people ask

What is mDNSResponder on Mac?

The macOS process that resolves domain names to addresses for every app, and runs Bonjour to find printers, AirPlay speakers and other devices on your network.

Can I quit mDNSResponder?

macOS restarts it at once, and nothing can look up a website while it is gone. To clear a bad answer, flush the DNS cache instead of quitting it.

Why does mDNSResponder want to accept incoming connections?

Bonjour listens for other devices announcing themselves on the local network. macOS's firewall allows it by default; if yours asks, allowing it keeps AirPlay, printer discovery and screen sharing working.

Is mDNSResponder safe?

Yes. It is part of macOS, signed by Apple, and lives at /usr/sbin/mDNSResponder. It runs under its own restricted system account, not as you or as root.

What is mDNSResponderHelper?

A small companion to mDNSResponder that runs as root and handles the few tasks its restricted account cannot do by itself. It is part of macOS and is normally idle.

Related

Looking for something better than Activity Monitor? See the best Activity Monitor alternatives for Mac, or browse every term in the glossary.