Port 691Exchange Routing
Port 691 is used by Microsoft Exchange Server for routing email messages within and between Exchange servers in an organization. It plays a vital role in facilitating message transport and ensuring efficient communication across the messaging infrastructure..
- transport
- tcp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 9,689
single transport
payload readable on path
registered with iana
caution
rank 495 of 993 · top 50%
Technical Details
what runs on :691Port 691 is primarily associated with Microsoft Exchange Server's routing service. This service manages the transfer and delivery of emails between Exchange servers, leveraging routing groups and connectors within the Exchange environment. The routing service uses port 691 over TCP to communicate message-related commands and status updates, facilitating reliable and organized mail flow.
In earlier versions of Exchange (notably Exchange 2000 and 2003), the routing engine used a message transfer agent (MTA) to exchange routing updates and transport mail between servers. While newer versions have shifted towards different transport mechanisms, knowledge of port 691 remains important when dealing with legacy systems or during migration processes.
Effective operation of port 691 helps maintain the internal communication fabric of an Exchange organization, supporting directory lookups, message categorization, and routing logic. Administrators should monitor this port chiefly in environments where legacy Exchange routing components are still active.
Security Information
exposure of :691risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
email averages 3.9 across 42 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common Vulnerabilities:
- Unauthorized access may allow attackers to intercept or manipulate internal mail flow.
- Exploits targeting unpatched Exchange routing services could lead to privilege escalation or denial of service.
- Lack of encryption means data transmitted may be susceptible to eavesdropping.
Mitigations:
- Implement network segmentation to restrict access to port 691 between trusted Exchange servers only.
- Apply the latest security updates and patches to Exchange servers.
- Use IPsec or VPN tunnels to encrypt inter-server communication.
- Regularly audit Exchange routing configurations and network access controls.
Related Ports
the 8 most looked-up other ports in email — 42 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :143 | IMAP | TCPUDP | caution | 20.7k | |
| :995 | POP3S | TCPtls | caution | 18.8k | |
| :109 | POP2 | TCP | caution | 17.9k | |
| :2096 | cPanel SSL Webmail | TCPtls | Web Services | safe | 17.4k |
| :110 | POP3 | TCP | caution | 15.5k | |
| :993 | IMAPS | TCPtls | caution | 14.5k | |
| :1352 | Lotus Notes RPC | TCP | caution | 12.3k | |
| :24 | Private Mail | TCPUDP | caution | 11.7k |
risk mix of the 8 listed
- safe13%
- caution88%
3 of 8 encrypted