Port 110 is POP3, and it is the cleartext one. The standard that defines it is RFC 1939, published in 1996 and still an Internet Standard as STD 53, and its own security section says plainly that the PASS command sends passwords in the clear and that RETR sends the mail itself in the clear.
The encrypted equivalent is port 995, where TLS begins the moment the connection opens. RFC 8314 asks mail providers to deprecate cleartext access as soon as practicable, so finding 110 in use is usually a migration that never finished.
The behavior worth understanding before any of that is that POP3 deletes nothing until the client says QUIT, which is why mail that was supposedly removed keeps arriving again.
- Port 110 is POP3 in the clear; port 995 is the same protocol inside TLS
- RFC 1939 is still an Internet Standard, and it documents its own weaknesses
- A session has three states, and deletion happens only in the last one
- A dropped connection removes nothing, by explicit requirement
- RFC 8314 tells providers to deprecate cleartext mail access
On this page
What uses itWhat runs on port 110
The short answer to what is port 110 is the default POP3 port: the TCP port an email client connects to when it retrieves email with the POP3 protocol.
POP3 exists to move email off a mail server and onto a machine that is not always connected. RFC 1939 describes it as a maildrop service, and the design assumption is a workstation that dials in, collects what has arrived, and disconnects. That assumption is thirty years old and it explains everything about how the protocol behaves.
A session moves through exactly three states, in order.
| State | What happens in it |
|---|---|
| AUTHORIZATION | The client identifies itself, with USER and PASS or with APOP |
| TRANSACTION | The client lists, retrieves and marks messages for deletion |
| UPDATE | The server actually removes what was marked, and the session ends |
The commands are small and there are not many of them: STAT for a count, LIST for sizes, RETR to fetch a message, DELE to mark one for deletion, TOP for the first few lines, UIDL for a stable identifier, QUIT to finish. That is close to the whole protocol.
Email portsPort 110 and the other email ports
Port 110 is one of several email ports, and each one carries a different part of the job. SMTP sends email. POP3 and IMAP are the two protocols an email client uses to receive it. Each has a cleartext port and an encrypted port.
| Port | Protocol | What it does | Encryption |
|---|---|---|---|
| 25 | SMTP | Relays email between mail servers | STARTTLS, if offered |
| 587 | SMTP submission | An email client sends outgoing email | STARTTLS |
| 465 | SMTP submission | The same, for clients set to SSL/TLS | Implicit TLS |
| 110 | POP3 | Downloads email to one client | None by default |
| 995 | POP3S | POP3 over SSL/TLS | Implicit TLS |
| 143 | IMAP | Reads email that stays on the server | STARTTLS, if offered |
| 993 | IMAPS | IMAP over SSL/TLS | Implicit TLS |
An email account set up for POP3 therefore uses two ports: 110 or 995 for the incoming server, and 587 or 465 for the outgoing SMTP server. Email clients still label the encrypted option SSL or SSL/TLS, although the protocol in use today is TLS.
Older email clients fill in the POP3 port number 110 by default when an account is added without SSL/TLS, which is how it survives on mail servers that also offer 995.
The three statesThe three states, and why the mail comes back
This is the behavior behind the support ticket, and it is a requirement rather than an accident. RFC 1939 states it directly:
> If a session terminates for some reason other than a client-issued QUIT command, the POP3 session does NOT enter the UPDATE state and MUST not remove any messages from the maildrop.
Read that again with a flaky connection in mind. The email client connects, the user authenticates with a username and password, and the client downloads forty emails and marks them for deletion.
The link drops before it sends QUIT. The server is now required to keep all forty, because the deletions were only marks and the marks are discarded. Next time the client connects, it downloads the same forty messages again.
The same rule covers a second case: a QUIT issued from the AUTHORIZATION state ends the session without entering UPDATE at all. Nothing was marked, so nothing is removed, which is correct and occasionally surprising.
Duplicate mail after an interrupted collection is POP3 working as specified. The fix is not on the server. It is a client that finishes its session, a connection that survives long enough for it to, or a move to a protocol that keeps state on the server instead.
The command that limits the damage is UIDL, which gives each message a persistent unique identifier. A client that records which identifiers it has already stored can recognize a message it has seen before, even when the server still holds it. A client that tracks messages by position in the list cannot.
110 and 995Port 110 against port 995
The two ports run the same POP3 protocol and differ only in when encryption starts. Port 110 is the default POP3 port, and port 995 is the encrypted one that RFC 8314 tells email providers and clients to prefer.
| Port 110 | Port 995 | |
|---|---|---|
| Name | pop3 | pop3s |
| Encryption | None by default | TLS from the first byte |
| How TLS is added | STARTTLS, after the fact, if offered | Implicit, before any protocol data |
| Credentials | In the clear unless STARTTLS succeeds | Inside TLS always |
| What RFC 8314 prefers | Not this one | This one |
RFC 8314 is explicit about which of those it wants. It asks that connections to mail access servers be made using implicit TLS in preference to connecting to the cleartext port and negotiating TLS using the STARTTLS command, and that providers deprecate cleartext mail access as soon as practicable.
The reason implicit TLS is preferred over STARTTLS on 110 is the window before the upgrade. On port 995 the TLS handshake begins the moment the TCP connection is established, so there is no plaintext phase at all.
On port 110 the connection starts in the clear, and an attacker positioned in the path can strip the offer of STARTTLS out of the server's capabilities and leave the client believing encryption was never available.
Its own warningWhat the 1996 standard says about its own security
RFC 1939 has a security section, and it is unusually candid for a document of its age. Three statements from it are worth quoting because people still find each one in a penetration test report:
On passwords. *Use of the PASS command sends passwords in the clear over the network.*
On the mail itself. *Use of the RETR and TOP commands sends mail in the clear over the network.*
On username enumeration. *Servers that answer -ERR to the USER command are giving potential attackers clues about which names are valid.*
That third one is a description of username enumeration written down in 1996 and still being reported as a finding today. The protocol never fixed it, because fixing it was outside what the protocol was for.
APOP was the standard's own answer to the password problem: a challenge and response that avoids sending the shared secret. RFC 1939 adds a rule that goes with it, which is that a server implementing both should not allow both for the same mailbox, since offering the weak option alongside the strong one means an attacker simply asks for the weak one.
That is a downgrade attack described before the term was common, and it is the same logic that makes implicit TLS preferable to STARTTLS today.
What to doWhat to do about port 110 on a network you run
Find out whether anything still uses it. A listening port with no sessions is a service to switch off, not a risk to accept.
Move email clients to 995. Same protocol, same username and password, same mailboxes, with TLS from the first byte. It is a client setting rather than a migration in most cases.
Do not settle for STARTTLS on 110 as the destination. It is better than nothing and it is not what RFC 8314 asks for, because the connection still begins in the clear and the offer can be stripped.
Test the port before and after. telnet mail.example.com 110 shows whether the POP3 service answers in the clear, with a banner that starts +OK. openssl s_client -connect mail.example.com:995 does the same over TLS. Telnet is safe for reading a banner and not for typing a real password.
Check what the mailbox is actually for before switching to IMAP. If two devices read the same account, IMAP is the answer and POP3 was always the wrong tool. If a single machine is collecting mail for archiving, POP3 over 995 is fine and IMAP would keep everything on a server you were trying to empty.
Watch for enumeration on anything left exposed. The behavior RFC 1939 warns about is in the base protocol, so a port 110 or 995 service reachable from the internet is an invitation to test usernames against it. Rate limiting and generic errors are the mitigations, and neither is in the protocol.
PitfallsWhere people go wrong
Assuming deleted means deleted. Marks become deletions only in the UPDATE state, which only follows a client-issued QUIT. An interrupted session deletes nothing, by requirement.
Blaming the server for duplicate mail. The server is doing what the standard says. Look at whether the client is finishing its sessions and whether it is tracking messages by UIDL rather than by position.
Treating 110 with STARTTLS as equivalent to 995. The plaintext window before the upgrade is the difference, and it is the window a stripping attack lives in.
Leaving 110 open because a device might need it. Find the device. A port left open for a hypothetical client is a port open for everyone.
Choosing POP3 for a person with a phone and a laptop. The mail ends up on whichever device collected it first, and the read state never agrees. That is IMAP's problem to solve, not a configuration to tune.
Reading RFC 1939 as obsolete because it is from 1996. It is an Internet Standard, STD 53, and it has not been replaced. The protocol is old and current at the same time.
ComparisonPOP3 and IMAP, side by side
| Criterion | POP3 | IMAP |
|---|---|---|
| Cleartext port | 110 | 143 |
| TLS port | 995 | 993 |
| Where mail lives | On the client, after collection | On the server |
| Folders on the server | No | Yes |
| Read and unread state | Local to one client | On the server, shared |
| Several devices | Awkward, each collects separately | The design case |
| Offline access | Total, the mail is local | Depends on client caching |
| Server storage needed | Little, if mail is deleted | All of it, indefinitely |
The middle rows decide POP3 vs IMAP for most users. IMAP keeps the mailbox on the email server and every client sees the same state, which is what people expect when they read mail on a phone and a laptop.
POP3 moves the mailbox to one machine, which is why a message read on the desktop is still unread on the phone, and why it is not the right protocol for anybody with two devices. POP3 still has a case.
A machine that must hold mail locally with no server dependency, an archive collector that pulls a mailbox down for retention, a device with very little storage on the server side. Those are real, and they are narrower than the population still using port 110 out of habit.
FAQFrequently asked questions
What is port 110 used for?
POP3, the Post Office Protocol version 3, which retrieves mail from a server to a client. It is the cleartext port: credentials and message content both travel unencrypted unless STARTTLS is negotiated afterwards. The encrypted equivalent is port 995.
Is port 110 secure?
No, not by itself. RFC 1939 says so in its own security section: the PASS command sends passwords in the clear and RETR sends the mail in the clear. STARTTLS on port 110 can encrypt a session after it starts, but the connection begins in plaintext and the upgrade offer can be removed in transit.
What is the difference between port 110 and port 995?
The same protocol with different encryption behavior. On 995 the TLS handshake begins the moment the TCP connection opens, so nothing is ever sent in the clear. On 110 the session starts unencrypted and TLS is only added if STARTTLS is offered and used. RFC 8314 states a preference for the first.
Why does my email download the same messages again?
Because the session did not end with QUIT. POP3 only deletes messages in the UPDATE state, which is entered when the client issues QUIT from the TRANSACTION state. RFC 1939 requires that a session ending any other way removes nothing, so the marked messages survive and arrive again.
What are the three POP3 states?
AUTHORIZATION, where the client proves who it is; TRANSACTION, where it lists, retrieves and marks messages; and UPDATE, where the server removes what was marked and the session closes. Deletion happens only in the third, and only if the client asked for it properly.
Should I use POP3 or IMAP?
IMAP for anybody reading mail on more than one device, because the mailbox and the read state stay on the server. POP3 only when mail must live on one machine independent of the server, such as a local archive collector or a device that needs full offline access with no server storage.
Is POP3 obsolete?
The protocol is not. RFC 1939 is an Internet Standard, STD 53, and has not been superseded. What is deprecated is using it in the clear: RFC 8314 asks providers to deprecate cleartext mail access as soon as practicable, which is about port 110 rather than about POP3. It is the same move the web made from 80 to 443, finished there and unfinished here.
What is APOP?
POP3's own alternative to sending a password, using a challenge and response so the shared secret is never transmitted. RFC 1939 adds that a server supporting both APOP and PASS should not allow both for the same mailbox, because leaving the weaker option available means an attacker will simply choose it.
What is UIDL for?
It gives each message a persistent unique identifier, so a client can tell whether it has already stored a message rather than guessing from its position in the list. A client that uses UIDL survives an interrupted session without duplicating mail; one that counts positions does not.
Can I just block port 110?
Usually, and it is worth confirming rather than assuming. Check for active sessions first, move any client that appears to 995, then close it. A listening port with no users is a service to disable rather than a risk to manage.
What are the other mail ports?
IMAP uses 143 in the clear and 993 with implicit TLS. Message submission uses 587, and 465 with implicit TLS. Port 25 is for server to server relay rather than for a mail client, and RFC 8314 deliberately excludes relay from its recommendations.
Does POP3 leave mail on the server?
Only if the client asks it to. Most clients offer a setting to retrieve without marking for deletion, which turns POP3 into a copy rather than a move. It works, at the cost of the mailbox growing indefinitely on a protocol with no folders and no server-side state to manage it.
What is the POP3 port number, and which email ports matter?
The POP3 port number is 110, and 995 for POP3 over TLS. The other email ports are 143 and 993 for IMAP, 25 for mail between servers, and 587 for submitting mail from a client, with 465 still used for submission over implicit TLS.
Keep readingRelated concepts
Read next · Ports What Is a Port Number? What a port number is before any of these protocols claim one, and how the ranges are divided. Open this next12 min- Ports · 10 min Port 80 and 443, and Why You Still Cannot Close 80 The same cleartext and TLS pairing on the web, where the migration actually finished.
- Ports · 10 min Port 22, and Why Changing It Is Not the Fix People Think The other old protocol on a well known port, and the one that solved its plaintext problem by being replaced rather than wrapped.