Port 4646DDoS Open Threat Signaling (DOTS) Signal Channel

DOTS signal channel traffic lets a client communicate with a service to request or coordinate DDoS mitigation.

transport
tcp · udp

2 transports registered

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
3/10

caution

lookups
0

rank 993 of 5,231 · top 19%

also known as dots-signal, DOTS, DOTS signal channel

Technical Details

what runs on :4646

Port 4646 is the IANA-assigned DOTS signal channel port on both UDP and TCP. The protocol uses CoAP: over UDP it runs over DTLS, while the TCP transport uses CoAP over TLS. A DOTS client initiates a secured channel to a DOTS server to exchange signaling, including mitigation requests; the UDP form uses CoAP datagrams and the TCP form uses CoAP's TCP framing. The port is also used in the SRV service names _dots-signal._udp and _dots-signal._tcp for server discovery.

Security Information

exposure of :4646

risk score

3/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.1 across 376 ports — this one sits 0.1 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

The signal channel is designed to use DTLS or TLS, with authentication and authorization needed to control which clients can request mitigation. It should normally be reachable only by intended DOTS clients, not exposed as an unauthenticated general-purpose service: misuse could trigger or alter mitigation actions and affect availability. Keep the implementation patched and restrict access to trusted peers.

the 8 most looked-up other ports in security — 376 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted