Port 6325Double-Take Management Service

TCP 6325 is used by Double-Take software for management and control of replication and disaster-recovery servers.

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 993 of 5,672 · top 17%

also known as dt-mgmtsvc

Technical Details

what runs on :6325

The service uses TCP and provides a management/control interface for Double-Take deployments; it is distinct from the service's replication data path. The application protocol is proprietary, and reliable public details about its handshake, framing, or default encryption are limited, so do not infer those properties from the port alone. A listener on 6325 is most plausibly a host running Double-Take software rather than a general-purpose operating-system service.

Security Information

exposure of :6325

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

remote access averages 3.8 across 216 ports — this one sits 3.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Treat this as a management interface: restrict access to trusted management hosts and private network paths, and do not expose it directly to the internet. A reachable management service may let an attacker who can authenticate interact with replication or recovery configuration; the proprietary protocol and limited public security detail are reasons to avoid assuming that traffic is encrypted or safe to expose.

the 8 most looked-up other ports in remote access — 216 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted