Port 5222: Extensible Messaging and Presence Protocol (client-to-server)
Port 5222 is the IANA-registered xmpp-client port that XMPP clients use to reach their home server for chat, presence and messaging. RFC 6120 names 5222 as the fallback port for client-to-server streams and 5269 for server-to-server streams. IANA registers 5222 for TCP only; the UDP entry is reserved.
Port Details
Security Exposure
XMPP servers that accept client connections from the internet are exposed to password guessing against user accounts and to flaws in the server software. Clients can be downgraded to plaintext if an attacker strips the STARTTLS offer, which RFC 7590 describes. The Openfire XMPP server has a KEV-listed path traversal in its administrative console (CVE-2023-32315).
Hardening
- +Require STARTTLS on every client stream and refuse plaintext authentication.
- +Follow RFC 7590 and RFC 7525 guidance on TLS versions and cipher suites.
- +Enforce strong passwords or SCRAM-based SASL mechanisms for user accounts.
- +Keep the XMPP server software patched and keep its web administration console off the internet.
- +Limit 5222 to the user populations that need it when the service is internal.
Monitoring
Track failed SASL authentications per account and per source address, and alert on sessions that complete without TLS.
Tools for Auditing and Monitoring XMPP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
What is port 5222 used for?→
Port 5222 is the XMPP client-to-server port. RFC 6120 uses it for client connections and 5269 for server-to-server federation.
Is XMPP on port 5222 encrypted?→
XMPP on 5222 starts in plaintext and upgrades with STARTTLS. RFC 7590 states that TLS support is mandatory for XMPP implementations.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5222 is not guaranteed to be XMPP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).