Port 5060: SIP

TCP/UDP 5060 is the port for Session Initiation Protocol (VoIP). Restrict to your SIP trunk provider's IPs; toll-fraud bots scan for it.

Port 5060 at a glance
ServiceSession Initiation Protocol (VoIP)
ProtocolTCP/UDP
Exposure riskHigh: do not expose to the internet
Secure alternativeSIP over TLS (5061)
RangeRegistered (1024–49151)

Your public IP is pre-filled. The test connects over TCP from NetKit's server, so it shows what the internet sees.

What port 5060 does

VoIP phones and PBXs (Asterisk, FreePBX, 3CX) signal calls on 5060; audio flows separately over RTP on a UDP range (often 10000-20000). 5061 is SIP over TLS.

Should port 5060 be open?

Restrict to your SIP trunk provider's IPs; toll-fraud bots scan for it. Where you can, use SIP over TLS (5061) instead.

Find what's listening on port 5060

  • Linux: sudo ss -tulpn | grep :5060
  • macOS: sudo lsof -nP -i :5060
  • Windows: netstat -ano | findstr :5060, then look up the PID in Task Manager.

Open or block it in a firewall

  • ufw: sudo ufw allow 5060/tcp (or deny)
  • firewalld: sudo firewall-cmd --add-port=5060/tcp --permanent && sudo firewall-cmd --reload
  • Windows: New-NetFirewallRule -DisplayName "Port 5060" -Direction Inbound -Protocol TCP -LocalPort 5060 -Action Allow

Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.

Questions about port 5060

What is port 5060 used for?
Session Initiation Protocol (VoIP). VoIP phones and PBXs (Asterisk, FreePBX, 3CX) signal calls on 5060; audio flows separately over RTP on a UDP range (often 10000-20000). 5061 is SIP over TLS.
Is port 5060 TCP or UDP?
Both. SIP uses TCP and UDP on port 5060.
Is it safe to open port 5060?
High: do not expose to the internet. Restrict to your SIP trunk provider's IPs; toll-fraud bots scan for it. Secure alternative: SIP over TLS (5061).
How do I check if port 5060 is open?
Use the checker on this page: it connects to your host on TCP 5060 from the internet. Locally, run nc -vz host 5060 (macOS/Linux) or Test-NetConnection host -Port 5060 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :5060 (Linux) or netstat -ano | findstr :5060 (Windows).

← Port 5000 (App / UPnP) · Port 5432 (PostgreSQL) →