TCP port 53 from here. Zone transfers need to ensure that all the data reached its destination so that a secondary DNS server can be sure it is serving out the right records. With UDP, there would be no way to know if the zone file transfer completed properly.