Port 993: IMAP over implicit TLS
TCP 993 is the default port for IMAP over implicit TLS, where the TLS handshake begins as soon as the client connects. Mail clients use it to read and sync mailboxes on a mail access server. RFC 8314 recommends implicit TLS for IMAP rather than cleartext IMAP on port 143.
Port Details
Security Exposure
IMAP servers accept mailbox credentials, so an internet-facing 993 listener is exposed to password guessing and reuse of stolen credentials. Microsoft notes that Basic authentication makes it easier for attackers to capture credentials and that MFA enforcement is not simple, or in some cases possible, while it remains enabled.
Hardening
- +Disable cleartext IMAP on port 143, or require STARTTLS, and keep 993 as the client endpoint.
- +Support TLS 1.2 or later, which RFC 8314 requires of mail access servers, and retire SSL and TLS 1.0.
- +Use modern authentication (OAuth) and MFA where the mail platform supports it.
- +Throttle failed logins per account and per source address.
Monitoring
Log IMAP authentication failures with source address and user name, and alert on many accounts failing from the same source. Watch for successful logins from unusual locations.
Tools for Auditing and Monitoring IMAPS
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 143 and 993?→
Port 143 is plain IMAP, optionally upgraded with STARTTLS. Port 993 is IMAP over implicit TLS, which RFC 8314 recommends.
Is port 993 TCP or UDP?→
TCP. IANA lists imaps on TCP 993 and marks UDP 993 as reserved.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 993 is not guaranteed to be IMAPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).