Networking · Concept · 9 min read

Port 110, and Why the Mail Keeps Coming Back

The cleartext mail port, defined by a standard from 1996 that is still current and still candid about its own weaknesses. The behavior to understand first is that nothing is deleted until the client says QUIT.

Written by Marko Ristic, Editor Updated Sep 17, 2026
110The cleartext POP3 port, where credentials and mail both travel open
995The same protocol with TLS from the first byte, which RFC 8314 prefers
1996The year RFC 1939 was published, and it is still an Internet Standard
0Messages a POP3 server may remove when a session ends without QUIT
Short answer

Port 110 is POP3, and it is the cleartext one. The standard that defines it is RFC 1939, published in 1996 and still an Internet Standard as STD 53, and its own security section says plainly that the PASS command sends passwords in the clear and that RETR sends the mail itself in the clear.

The encrypted equivalent is port 995, where TLS begins the moment the connection opens. RFC 8314 asks mail providers to deprecate cleartext access as soon as practicable, so finding 110 in use is usually a migration that never finished.

The behavior worth understanding before any of that is that POP3 deletes nothing until the client says QUIT, which is why mail that was supposedly removed keeps arriving again.

  • Port 110 is POP3 in the clear; port 995 is the same protocol inside TLS
  • RFC 1939 is still an Internet Standard, and it documents its own weaknesses
  • A session has three states, and deletion happens only in the last one
  • A dropped connection removes nothing, by explicit requirement
  • RFC 8314 tells providers to deprecate cleartext mail access
On this page

What uses itWhat runs on port 110

The short answer to what is port 110 is the default POP3 port: the TCP port an email client connects to when it retrieves email with the POP3 protocol.

POP3 exists to move email off a mail server and onto a machine that is not always connected. RFC 1939 describes it as a maildrop service, and the design assumption is a workstation that dials in, collects what has arrived, and disconnects. That assumption is thirty years old and it explains everything about how the protocol behaves.

A session moves through exactly three states, in order.

StateWhat happens in it
AUTHORIZATIONThe client identifies itself, with USER and PASS or with APOP
TRANSACTIONThe client lists, retrieves and marks messages for deletion
UPDATEThe server actually removes what was marked, and the session ends

The commands are small and there are not many of them: STAT for a count, LIST for sizes, RETR to fetch a message, DELE to mark one for deletion, TOP for the first few lines, UIDL for a stable identifier, QUIT to finish. That is close to the whole protocol.

Email portsPort 110 and the other email ports

Port 110 is one of several email ports, and each one carries a different part of the job. SMTP sends email. POP3 and IMAP are the two protocols an email client uses to receive it. Each has a cleartext port and an encrypted port.

PortProtocolWhat it doesEncryption
25SMTPRelays email between mail serversSTARTTLS, if offered
587SMTP submissionAn email client sends outgoing emailSTARTTLS
465SMTP submissionThe same, for clients set to SSL/TLSImplicit TLS
110POP3Downloads email to one clientNone by default
995POP3SPOP3 over SSL/TLSImplicit TLS
143IMAPReads email that stays on the serverSTARTTLS, if offered
993IMAPSIMAP over SSL/TLSImplicit TLS

An email account set up for POP3 therefore uses two ports: 110 or 995 for the incoming server, and 587 or 465 for the outgoing SMTP server. Email clients still label the encrypted option SSL or SSL/TLS, although the protocol in use today is TLS.

Older email clients fill in the POP3 port number 110 by default when an account is added without SSL/TLS, which is how it survives on mail servers that also offer 995.

The three statesThe three states, and why the mail comes back

This is the behavior behind the support ticket, and it is a requirement rather than an accident. RFC 1939 states it directly:

> If a session terminates for some reason other than a client-issued QUIT command, the POP3 session does NOT enter the UPDATE state and MUST not remove any messages from the maildrop.

Read that again with a flaky connection in mind. The email client connects, the user authenticates with a username and password, and the client downloads forty emails and marks them for deletion.

The link drops before it sends QUIT. The server is now required to keep all forty, because the deletions were only marks and the marks are discarded. Next time the client connects, it downloads the same forty messages again.

The same rule covers a second case: a QUIT issued from the AUTHORIZATION state ends the session without entering UPDATE at all. Nothing was marked, so nothing is removed, which is correct and occasionally surprising.

Duplicate mail after an interrupted collection is POP3 working as specified. The fix is not on the server. It is a client that finishes its session, a connection that survives long enough for it to, or a move to a protocol that keeps state on the server instead.

The command that limits the damage is UIDL, which gives each message a persistent unique identifier. A client that records which identifiers it has already stored can recognize a message it has seen before, even when the server still holds it. A client that tracks messages by position in the list cannot.

110 and 995Port 110 against port 995

The two ports run the same POP3 protocol and differ only in when encryption starts. Port 110 is the default POP3 port, and port 995 is the encrypted one that RFC 8314 tells email providers and clients to prefer.

Port 110Port 995
Namepop3pop3s
EncryptionNone by defaultTLS from the first byte
How TLS is addedSTARTTLS, after the fact, if offeredImplicit, before any protocol data
CredentialsIn the clear unless STARTTLS succeedsInside TLS always
What RFC 8314 prefersNot this oneThis one

RFC 8314 is explicit about which of those it wants. It asks that connections to mail access servers be made using implicit TLS in preference to connecting to the cleartext port and negotiating TLS using the STARTTLS command, and that providers deprecate cleartext mail access as soon as practicable.

The reason implicit TLS is preferred over STARTTLS on 110 is the window before the upgrade. On port 995 the TLS handshake begins the moment the TCP connection is established, so there is no plaintext phase at all.

On port 110 the connection starts in the clear, and an attacker positioned in the path can strip the offer of STARTTLS out of the server's capabilities and leave the client believing encryption was never available.

Its own warningWhat the 1996 standard says about its own security

RFC 1939 has a security section, and it is unusually candid for a document of its age. Three statements from it are worth quoting because people still find each one in a penetration test report:

On passwords. *Use of the PASS command sends passwords in the clear over the network.*

On the mail itself. *Use of the RETR and TOP commands sends mail in the clear over the network.*

On username enumeration. *Servers that answer -ERR to the USER command are giving potential attackers clues about which names are valid.*

That third one is a description of username enumeration written down in 1996 and still being reported as a finding today. The protocol never fixed it, because fixing it was outside what the protocol was for.

APOP was the standard's own answer to the password problem: a challenge and response that avoids sending the shared secret. RFC 1939 adds a rule that goes with it, which is that a server implementing both should not allow both for the same mailbox, since offering the weak option alongside the strong one means an attacker simply asks for the weak one.

That is a downgrade attack described before the term was common, and it is the same logic that makes implicit TLS preferable to STARTTLS today.

What to doWhat to do about port 110 on a network you run

Find out whether anything still uses it. A listening port with no sessions is a service to switch off, not a risk to accept.

Move email clients to 995. Same protocol, same username and password, same mailboxes, with TLS from the first byte. It is a client setting rather than a migration in most cases.

Do not settle for STARTTLS on 110 as the destination. It is better than nothing and it is not what RFC 8314 asks for, because the connection still begins in the clear and the offer can be stripped.

Test the port before and after. telnet mail.example.com 110 shows whether the POP3 service answers in the clear, with a banner that starts +OK. openssl s_client -connect mail.example.com:995 does the same over TLS. Telnet is safe for reading a banner and not for typing a real password.

Check what the mailbox is actually for before switching to IMAP. If two devices read the same account, IMAP is the answer and POP3 was always the wrong tool. If a single machine is collecting mail for archiving, POP3 over 995 is fine and IMAP would keep everything on a server you were trying to empty.

Watch for enumeration on anything left exposed. The behavior RFC 1939 warns about is in the base protocol, so a port 110 or 995 service reachable from the internet is an invitation to test usernames against it. Rate limiting and generic errors are the mitigations, and neither is in the protocol.

PitfallsWhere people go wrong

Assuming deleted means deleted. Marks become deletions only in the UPDATE state, which only follows a client-issued QUIT. An interrupted session deletes nothing, by requirement.

Blaming the server for duplicate mail. The server is doing what the standard says. Look at whether the client is finishing its sessions and whether it is tracking messages by UIDL rather than by position.

Treating 110 with STARTTLS as equivalent to 995. The plaintext window before the upgrade is the difference, and it is the window a stripping attack lives in.

Leaving 110 open because a device might need it. Find the device. A port left open for a hypothetical client is a port open for everyone.

Choosing POP3 for a person with a phone and a laptop. The mail ends up on whichever device collected it first, and the read state never agrees. That is IMAP's problem to solve, not a configuration to tune.

Reading RFC 1939 as obsolete because it is from 1996. It is an Internet Standard, STD 53, and it has not been replaced. The protocol is old and current at the same time.

ONE PATH DELETES ANYTHING. TWO THROW THE MARKS AWAY.The POP3 session, per RFC 1939. DELE only marks; UPDATE is where removal happens.AUTHORIZATIONUSER and PASS, or APOPTRANSACTIONRETR, DELE, UIDL, LISTUPDATEthe only place mail is removedauth okQUITQUIT from heresession ends, UPDATE never enteredconnection dropsMUST NOT remove any messagesSo an interrupted collection deletes nothing, and delivers the same mail again.That is the standard working as written, not a server fault.A client tracking messages by UIDL notices. One counting positions in the list does not.
The three states and the one path that removes anything. The two dashed exits are both required by RFC 1939 to discard every deletion the client marked, which is the whole explanation for duplicated mail.

ComparisonPOP3 and IMAP, side by side

CriterionPOP3IMAP
Cleartext port110143
TLS port995993
Where mail livesOn the client, after collectionOn the server
Folders on the serverNoYes
Read and unread stateLocal to one clientOn the server, shared
Several devicesAwkward, each collects separatelyThe design case
Offline accessTotal, the mail is localDepends on client caching
Server storage neededLittle, if mail is deletedAll of it, indefinitely

The middle rows decide POP3 vs IMAP for most users. IMAP keeps the mailbox on the email server and every client sees the same state, which is what people expect when they read mail on a phone and a laptop.

POP3 moves the mailbox to one machine, which is why a message read on the desktop is still unread on the phone, and why it is not the right protocol for anybody with two devices. POP3 still has a case.

A machine that must hold mail locally with no server dependency, an archive collector that pulls a mailbox down for retention, a device with very little storage on the server side. Those are real, and they are narrower than the population still using port 110 out of habit.

FAQFrequently asked questions

What is port 110 used for?

POP3, the Post Office Protocol version 3, which retrieves mail from a server to a client. It is the cleartext port: credentials and message content both travel unencrypted unless STARTTLS is negotiated afterwards. The encrypted equivalent is port 995.

Is port 110 secure?

No, not by itself. RFC 1939 says so in its own security section: the PASS command sends passwords in the clear and RETR sends the mail in the clear. STARTTLS on port 110 can encrypt a session after it starts, but the connection begins in plaintext and the upgrade offer can be removed in transit.

What is the difference between port 110 and port 995?

The same protocol with different encryption behavior. On 995 the TLS handshake begins the moment the TCP connection opens, so nothing is ever sent in the clear. On 110 the session starts unencrypted and TLS is only added if STARTTLS is offered and used. RFC 8314 states a preference for the first.

Why does my email download the same messages again?

Because the session did not end with QUIT. POP3 only deletes messages in the UPDATE state, which is entered when the client issues QUIT from the TRANSACTION state. RFC 1939 requires that a session ending any other way removes nothing, so the marked messages survive and arrive again.

What are the three POP3 states?

AUTHORIZATION, where the client proves who it is; TRANSACTION, where it lists, retrieves and marks messages; and UPDATE, where the server removes what was marked and the session closes. Deletion happens only in the third, and only if the client asked for it properly.

Should I use POP3 or IMAP?

IMAP for anybody reading mail on more than one device, because the mailbox and the read state stay on the server. POP3 only when mail must live on one machine independent of the server, such as a local archive collector or a device that needs full offline access with no server storage.

Is POP3 obsolete?

The protocol is not. RFC 1939 is an Internet Standard, STD 53, and has not been superseded. What is deprecated is using it in the clear: RFC 8314 asks providers to deprecate cleartext mail access as soon as practicable, which is about port 110 rather than about POP3. It is the same move the web made from 80 to 443, finished there and unfinished here.

What is APOP?

POP3's own alternative to sending a password, using a challenge and response so the shared secret is never transmitted. RFC 1939 adds that a server supporting both APOP and PASS should not allow both for the same mailbox, because leaving the weaker option available means an attacker will simply choose it.

What is UIDL for?

It gives each message a persistent unique identifier, so a client can tell whether it has already stored a message rather than guessing from its position in the list. A client that uses UIDL survives an interrupted session without duplicating mail; one that counts positions does not.

Can I just block port 110?

Usually, and it is worth confirming rather than assuming. Check for active sessions first, move any client that appears to 995, then close it. A listening port with no users is a service to disable rather than a risk to manage.

What are the other mail ports?

IMAP uses 143 in the clear and 993 with implicit TLS. Message submission uses 587, and 465 with implicit TLS. Port 25 is for server to server relay rather than for a mail client, and RFC 8314 deliberately excludes relay from its recommendations.

Does POP3 leave mail on the server?

Only if the client asks it to. Most clients offer a setting to retrieve without marking for deletion, which turns POP3 into a copy rather than a move. It works, at the cost of the mailbox growing indefinitely on a protocol with no folders and no server-side state to manage it.

What is the POP3 port number, and which email ports matter?

The POP3 port number is 110, and 995 for POP3 over TLS. The other email ports are 143 and 993 for IMAP, 25 for mail between servers, and 587 for submitting mail from a client, with 465 still used for submission over implicit TLS.

Read next · Ports What Is a Port Number? What a port number is before any of these protocols claim one, and how the ranges are divided. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.