Port 10024Zimbra SMTP to Amavis
This port is commonly used within Zimbra Collaboration Suite for internal communication between the mail transfer agent (Postfix) and Amavis, an open-source content filter. It facilitates email scanning, virus filtering, and spam detection before mail delivery, ensuring cleaner email flows within an organization’s email infrastructure..
- transport
- tcp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 8,674
single transport
payload readable on path
used by convention
caution
rank 584 of 993 · top 59%
Technical Details
what runs on :10024Port 10024 is primarily used in the Zimbra Collaboration Suite, an open-source email and collaboration platform. Within Zimbra, this port serves for internal SMTP traffic between Postfix (the mail transfer agent) and the Amavis content filter. When Postfix receives an email, it forwards it over TCP port 10024 to Amavis for content scanning.
Amavis integrates antivirus and antispam tools, scanning the emails for malware, viruses, and unsolicited messages. Accepted mails are then handed back from Amavis to Postfix through a separate port for final delivery to the mailbox or onward routing. This separation ensures that incoming emails are filtered thoroughly before users engage with them.
Typically, this port operates internally within the server or trusted LAN environments, rather than being exposed externally. Proper functioning requires that both Postfix and Amavis are configured correctly to send and receive messages on port 10024, maintaining seamless scanning and delivery workflows within Zimbra’s architecture.
Security Information
exposure of :10024risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
email averages 3.9 across 42 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Port 10024, being used internally for scanning emails, can become a target if exposed externally or misconfigured. Common vulnerabilities include:
- Spoofing attacks where malicious actors inject crafted messages during the communication
- Relay abuses if access controls are lax, allowing unauthorized or unauthenticated use
- Denial-of-Service (DoS) by overwhelming Amavis or the MTA with large volumes of spam or malformed messages
- Man-in-the-middle attacks on unencrypted communication which could expose or alter email content
Mitigations involve:
- Restricting port access to localhost or trusted internal networks via firewalls
- Enabling SMTP authentication and proper access controls
- Keeping Zimbra, Postfix, and Amavis updated with security patches
- Optionally encrypting internal SMTP traffic using TLS or stunnel if higher security is required
- Monitoring logs regularly to detect unusual activity
Because port 10024 handles unfiltered emails, its protection is crucial to prevent infection and abuse within an organization's messaging backbone.
Related Ports
the 8 most looked-up other ports in email — 42 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :143 | IMAP | TCPUDP | caution | 20.7k | |
| :995 | POP3S | TCPtls | caution | 18.8k | |
| :109 | POP2 | TCP | caution | 17.9k | |
| :2096 | cPanel SSL Webmail | TCPtls | Web Services | safe | 17.4k |
| :110 | POP3 | TCP | caution | 15.5k | |
| :993 | IMAPS | TCPtls | caution | 14.5k | |
| :1352 | Lotus Notes RPC | TCP | caution | 12.3k | |
| :24 | Private Mail | TCPUDP | caution | 11.7k |
risk mix of the 8 listed
- safe13%
- caution88%
3 of 8 encrypted