Port 465: Message Submission over Implicit TLS
Port 465 is the IANA-registered port for email message submission over implicit TLS, where the TLS handshake starts as soon as the TCP connection opens. Mail clients use it to hand outgoing mail to their provider's submission server. IANA also lists urd (URL Rendezvous Directory for SSM) on TCP 465 and igmpv3lite on UDP 465.
Port Details
Security Exposure
A submission server accepts logins, so an exposed 465 listener draws credential guessing and reuse of stolen passwords. Microsoft notes that Basic authentication makes credential capture easier and blocks simple enforcement of MFA. Stolen credentials can also be reused against other services.
Hardening
- +Require SMTP authentication for every submission, as RFC 6409 mandates for message submission agents.
- +Accept TLS 1.2 or later only, in line with RFC 8314.
- +Prefer modern authentication (OAuth) over Basic authentication where the mail platform supports it.
- +Rate-limit and lock out repeated failed logins per account and per source address.
Monitoring
Log authentication successes and failures on the submission service and alert on spikes from single sources or across many accounts. Watch outbound mail volume per account for signs of a compromised mailbox.
SMTPS (submissions) Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | - | 9.8 | 71.7% | KEV | 2010-12-14 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | - | 7.8 | 18.0% | KEV | 2010-12-14 |
| CVE-2019-16928 | Exim Out-of-bounds Write Vulnerability | - | 9.8 | 41.6% | KEV | 2019-09-27 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | exim | 9.0 | 100.0% | KEV | 2019-06-05 |
| CVE-2018-6789 | Exim Buffer Overflow Vulnerability | - | 9.8 | 82.1% | KEV | 2018-02-08 |
Tools for Auditing and Monitoring SMTPS (submissions)
Rspamd
Free / CommercialFast open source spam and phishing filtering system for Postfix, Exim, and Sendmail.
Apache SpamAssassin
Open SourceClassic open source spam filter using heuristic scoring, Bayesian classification, and a plugin architecture.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Port 465 or 587: which should be used?→
RFC 8314 says clients and servers should implement both: implicit TLS on 465 and STARTTLS on 587. It also notes no significant difference in security between the two when both are implemented correctly.
Is port 465 deprecated?→
No. RFC 8314 registered port 465 for the submissions service, documenting its existing wide use for implicit TLS submission.
Which vulnerabilities affect the service on port 465?→
This database lists 5 CVEs related to SMTPS (submissions), 5 of them confirmed as exploited by CISA. Examples: CVE-2010-4344, CVE-2010-4345, CVE-2019-16928, CVE-2019-10149.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 465 is not guaranteed to be SMTPS (submissions). Exploited-in-the-wild data from the CISA KEV catalog (CC0).