Port 1883: MQTT
TCP 1883 is the port for MQTT (IoT messaging). Not without TLS and authentication; open brokers leak sensor data and accept commands.
| Service | MQTT (IoT messaging) |
|---|---|
| Protocol | TCP |
| Exposure risk | High: do not expose to the internet |
| Secure alternative | MQTT over TLS (port 8883) |
| Range | Registered (1024–49151) |
What port 1883 does
IoT devices and home-automation systems (Home Assistant, Zigbee2MQTT) publish and subscribe through an MQTT broker such as Mosquitto. 8883 is MQTT over TLS.
Should port 1883 be open?
Not without TLS and authentication; open brokers leak sensor data and accept commands. Where you can, use MQTT over TLS (port 8883) instead.
Find what's listening on port 1883
- Linux:
sudo ss -tulpn | grep :1883 - macOS:
sudo lsof -nP -i :1883 - Windows:
netstat -ano | findstr :1883, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 1883/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=1883/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 1883" -Direction Inbound -Protocol TCP -LocalPort 1883 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 1883
What is port 1883 used for?
MQTT (IoT messaging). IoT devices and home-automation systems (Home Assistant, Zigbee2MQTT) publish and subscribe through an MQTT broker such as Mosquitto. 8883 is MQTT over TLS.
Is port 1883 TCP or UDP?
TCP. MQTT uses TCP port 1883.
Is it safe to open port 1883?
High: do not expose to the internet. Not without TLS and authentication; open brokers leak sensor data and accept commands. Secure alternative: MQTT over TLS (port 8883).
How do I check if port 1883 is open?
Use the checker on this page: it connects to your host on TCP 1883 from the internet. Locally, run
nc -vz host 1883 (macOS/Linux) or Test-NetConnection host -Port 1883 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :1883 (Linux) or netstat -ano | findstr :1883 (Windows).