Port 587: SMTP submission
TCP 587 is the port for Mail submission (STARTTLS). Fine on mail submission servers with authentication required.
| Service | Mail submission (STARTTLS) |
|---|---|
| Protocol | TCP |
| Exposure risk | Low: normally safe to expose |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 587 does
The port email clients and apps use to send mail through a provider such as Gmail (smtp.gmail.com:587), Microsoft 365 or SendGrid. The connection starts in plain text and upgrades with STARTTLS, and the client must log in.
Should port 587 be open?
Fine on mail submission servers with authentication required.
Find what's listening on port 587
- Linux:
sudo ss -tulpn | grep :587 - macOS:
sudo lsof -nP -i :587 - Windows:
netstat -ano | findstr :587, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 587/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=587/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 587" -Direction Inbound -Protocol TCP -LocalPort 587 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 587
What is port 587 used for?
Mail submission (STARTTLS). The port email clients and apps use to send mail through a provider such as Gmail (smtp.gmail.com:587), Microsoft 365 or SendGrid. The connection starts in plain text and upgrades with STARTTLS, and the client must log in.
Is port 587 TCP or UDP?
TCP. SMTP submission uses TCP port 587.
Is it safe to open port 587?
Low: normally safe to expose. Fine on mail submission servers with authentication required.
How do I check if port 587 is open?
Use the checker on this page: it connects to your host on TCP 587 from the internet. Locally, run
nc -vz host 587 (macOS/Linux) or Test-NetConnection host -Port 587 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :587 (Linux) or netstat -ano | findstr :587 (Windows).