# mDNSResponder

Canonical page: https://vitalsmac.com/glossary/mdnsresponder

Activity Monitor glossary, Processes you will see. What is mDNSResponder on Mac?

Also: Bonjour and DNS

**Short answer:** mDNSResponder is the macOS process that turns every domain name into an address. It is the Mac's DNS resolver, and it also runs Bonjour, which finds printers, AirPlay speakers, shared Macs and other devices on your local network without any setup.

When any app opens a website or connects to a server, it asks mDNSResponder for the address. It caches the answers, so repeated lookups are instant. It runs as its own system account, _mdnsresponder, not as you.

Its load follows how many names are being looked up. A browser with many tabs, a VPN, or a busy local network with many Bonjour devices all give it more to do.

## Why mDNSResponder is using CPU

Short spikes come from bursts of lookups: many new tabs, an app syncing with many servers, or devices joining the network. Sustained use usually points to something retrying lookups in a loop, a misbehaving VPN or DNS filter, or a network where Bonjour announcements never stop.

When websites fail to load by name but work by address, or a site changed servers and the Mac still goes to the old one, the cache is the suspect.

## How to flush the DNS cache

Two commands in Terminal clear the cache on recent macOS and tell mDNSResponder to reload, with no restart needed.

1. Open Terminal.
2. Run `sudo dscacheutil -flushcache`, and enter your password when asked.
3. Run `sudo killall -HUP mDNSResponder`.

## How to see what mDNSResponder is doing

It runs as its own system account, so Activity Monitor hides it until you ask for every process. Terminal can show its two jobs, DNS and Bonjour, one at a time.

1. Open Activity Monitor, choose View → All Processes and type `mdns` in the search field. You will see mDNSResponder under the _mdnsresponder account, and mDNSResponderHelper under root.
2. Watch % CPU on the CPU tab and the packet columns on the Network tab. Short spikes are normal. A steady load while you are not browsing is worth a look.
3. To see which DNS servers the Mac is using, open Terminal and run `scutil --dns`. Resolver #1 lists the servers used for most lookups under `nameserver[0]`, `nameserver[1]` and so on.
4. To test a lookup through mDNSResponder itself, run `dns-sd -G v4v6 apple.com`. It prints each address as it arrives. Press Control-C to stop.
5. To see what Bonjour finds on your network, run `dns-sd -B _services._dns-sd._udp local.`. It lists the kinds of service that devices around you announce, such as `_airplay` and `_ipp` for printers. Press Control-C to stop.

## Normal mDNSResponder use vs a problem

Normal: close to zero, with brief spikes when you open many tabs, join a network, or a device on the network wakes up.

Worth looking into: steady CPU or network use for hours, or names that fail to resolve on one network but work on another. The usual causes:

- A VPN or DNS filter that adds its own resolvers and keeps changing them. `scutil --dns` shows extra resolvers with a `domain` line when a VPN sends some names to its own servers.
- An app or script that looks up names in a tight loop, often one that keeps retrying a server it cannot reach.
- A busy local network, such as an office or a shared building, with many devices announcing themselves over Bonjour.
- A network that hands out a DNS server that is slow or does not answer, so lookups wait and retry.

## DNS and Bonjour: the two jobs

Names on the internet, such as apple.com, go to the DNS servers your network or you have set. Names ending in `.local`, such as your Mac's own network name, never leave the local network: mDNSResponder asks the devices around it directly, which is the multicast DNS that gives it the m in its name.

That is why `scutil --dns` lists resolvers for `local` marked `mdns`. If a printer or a shared Mac can be reached by its `.local` name at home but not at work, the work network is blocking those local announcements, not the internet.

## Questions people ask

### What is mDNSResponder on Mac?

The macOS process that resolves domain names to addresses for every app, and runs Bonjour to find printers, AirPlay speakers and other devices on your network.

### Can I quit mDNSResponder?

macOS restarts it at once, and nothing can look up a website while it is gone. To clear a bad answer, flush the DNS cache instead of quitting it.

### Why does mDNSResponder want to accept incoming connections?

Bonjour listens for other devices announcing themselves on the local network. macOS's firewall allows it by default; if yours asks, allowing it keeps AirPlay, printer discovery and screen sharing working.

### Is mDNSResponder safe?

Yes. It is part of macOS, signed by Apple, and lives at /usr/sbin/mDNSResponder. It runs under its own restricted system account, not as you or as root.

### What is mDNSResponderHelper?

A small companion to mDNSResponder that runs as root and handles the few tasks its restricted account cannot do by itself. It is part of macOS and is normally idle.

## In Vitals

mDNSResponder runs as a system account, so Vitals measures it when its optional helper is on. Without the helper it is counted among the processes the window says it cannot measure.

## Related

- [Listening port](https://vitalsmac.com/glossary/listening-port)
- [Unmeasured processes](https://vitalsmac.com/glossary/unmeasured-processes)
- [launchd](https://vitalsmac.com/glossary/launchd)
- [nsurlsessiond](https://vitalsmac.com/glossary/nsurlsessiond)

Looking for something better than Activity Monitor? See [the best Activity Monitor alternatives for Mac](https://vitalsmac.com/best-activity-monitor-alternatives), or [every term in the glossary](https://vitalsmac.com/glossary).
