Port 691Exchange Routing

Port 691 is used by Microsoft Exchange Server for routing email messages within and between Exchange servers in an organization. It plays a vital role in facilitating message transport and ensuring efficient communication across the messaging infrastructure..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
9,689

rank 495 of 993 · top 50%

Technical Details

what runs on :691

Port 691 is primarily associated with Microsoft Exchange Server's routing service. This service manages the transfer and delivery of emails between Exchange servers, leveraging routing groups and connectors within the Exchange environment. The routing service uses port 691 over TCP to communicate message-related commands and status updates, facilitating reliable and organized mail flow.

In earlier versions of Exchange (notably Exchange 2000 and 2003), the routing engine used a message transfer agent (MTA) to exchange routing updates and transport mail between servers. While newer versions have shifted towards different transport mechanisms, knowledge of port 691 remains important when dealing with legacy systems or during migration processes.

Effective operation of port 691 helps maintain the internal communication fabric of an Exchange organization, supporting directory lookups, message categorization, and routing logic. Administrators should monitor this port chiefly in environments where legacy Exchange routing components are still active.

Security Information

exposure of :691

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

email averages 3.9 across 42 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Unauthorized access may allow attackers to intercept or manipulate internal mail flow.
  • Exploits targeting unpatched Exchange routing services could lead to privilege escalation or denial of service.
  • Lack of encryption means data transmitted may be susceptible to eavesdropping.

Mitigations:

  • Implement network segmentation to restrict access to port 691 between trusted Exchange servers only.
  • Apply the latest security updates and patches to Exchange servers.
  • Use IPsec or VPN tunnels to encrypt inter-server communication.
  • Regularly audit Exchange routing configurations and network access controls.

Related Ports

all 42 in email

the 8 most looked-up other ports in email — 42 ports carry that label.

portservicerisk
:143IMAPcaution
:995POP3Scaution
:109POP2caution
:2096cPanel SSL Webmailsafe
:110POP3caution
:993IMAPScaution
:1352Lotus Notes RPCcaution
:24Private Mailcaution

risk mix of the 8 listed

  • safe13%
  • caution88%

3 of 8 encrypted