Port 110: Post Office Protocol version 3
TCP port 110 is the Post Office Protocol version 3 (POP3) port defined in RFC 1939. Mail clients use POP3 to download messages from a mailbox on the server. RFC 8314 recommends implicit TLS on port 995 for POP access instead of cleartext POP3.
Port Details
Security Exposure
RFC 1939 notes that the PASS command sends passwords in the clear and that RETR and TOP send mail in the clear. Basic username and password authentication makes credentials easier to capture, one reason Microsoft removed Basic authentication for POP and IMAP in Exchange Online. RFC 1939 also points out that servers answering -ERR to the USER command reveal which account names are valid.
Hardening
- +Disable POP3 where users do not need it.
- +Offer POP3 only over implicit TLS on port 995 (RFC 8314), or require STLS before any login (RFC 2595).
- +Use OAuth 2.0 or other modern authentication instead of plain passwords where the mail platform supports it.
- +Rate-limit failed logins and restrict POP3 to the client networks that actually use it.
Monitoring
Log POP3 authentication attempts with source address. Alert on repeated failures across many accounts from one source and on cleartext logins on port 110.
Tools for Auditing and Monitoring POP3
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
Is POP3 on port 110 encrypted?→
Not by default. RFC 1939 POP3 sends passwords and mail in the clear; encryption requires STLS (RFC 2595) or implicit TLS on port 995 (RFC 8314).
What is the difference between port 110 and port 995?→
Port 110 is cleartext POP3. Port 995 is POP3 over implicit TLS, where the TLS handshake starts as soon as the connection opens (RFC 8314).
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 110)
- RFC 1939: Post Office Protocol, Version 3
- RFC 2595: Using TLS with IMAP, POP3 and ACAP
- RFC 8314: Cleartext Considered Obsolete: Use of TLS for Email Submission and Access
- Microsoft Learn: Deprecation of Basic authentication in Exchange Online
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 110 is not guaranteed to be POP3. Exploited-in-the-wild data from the CISA KEV catalog (CC0).