174
Summary
- // if you see it open
- No known malware, trojan, or CVE association found for port 174 in GRC Port Authority, SpeedGuide, or IANA. Given its near-total absence in scan data and lack of a defined protocol, an open 174/tcp is more likely a custom or misconfigured service than a recognizable standard one.
About port 174/tcp.
Port 174/tcp is registered with IANA under the service name mailq, description "MAILQ," with assignee/contact listed as Rayan Zachariassen. The registration is dual — 174/udp carries an identical entry — and the Reference field in the IANA Service Name and Transport Protocol Port Number Registry is blank, meaning no RFC or other formal specification is cited for this assignment; that blank is reported honestly here rather than filled with an invented citation. The name overlaps conceptually with the Unix mailq command, which lists queued outbound mail and has historically shipped alongside sendmail, but no evidence was found that sendmail, Postfix, Exim, or any other mail transfer agent actually opens a network listener on port 174 in current or historical practice; sendmail's documented network-facing ports are 25 (SMTP) and 587 (submission), not 174. This makes 174 read as a legacy/historical IANA reservation rather than an active protocol with a defined wire format. Consistent with that, nmap's scan-derived port-frequency data shows 174 is almost never found open on real hosts — roughly 0.0013% of scanned TCP hosts and 0.038% of scanned UDP hosts — and no malware, trojan, or CVE association turned up in general-purpose port databases. An analyst encountering an open 174/tcp should treat it as either an unusual custom service reusing the name, a misconfiguration, or noise, not a recognizable standard protocol.
- IANA assignment
mailq— description "MAILQ"; assignee/contact[Rayan_Zachariassen]; dual-registered 174/tcp + 174/udp with identical registry content [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- IANA Reference field
- blank — no RFC or other formal specification is cited for this assignment [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
- Registration/modification dates
- blank in the IANA registry; not recorded, reported as Unknown rather than fabricated [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency ≈0.000013 (174/tcp) and ≈0.000379 (174/udp) — extremely rarely found open in scans [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Primary use
registered IANA name only ("mailq"/MAILQ); no defined wire protocol or specification is on record
Security implications / known malware or CVE
none found associated specifically with port 174 in the sources checked
Typically seen on
no documented common software; treat as a legacy/historical reservation rather than an actively deployed service [Unknown]
- Relationship to the Unix `mailq` command
- name overlaps with the mail-queue-listing command historically associated with sendmail, but no source confirms any MTA actually binds a listener on network port 174; sendmail's documented ports are 25/587 [Unknown] — https://docstore.mik.ua/orelly/networking_2ndEd/tcp/ch10_02.htm
About port 174/udp.
Port 174/udp is registered with IANA under the service name mailq, description "MAILQ," with Rayan Zachariassen listed as both assignee and contact. The registration is a dual assignment: 174/tcp carries the identical service name, description, assignee, and contact, meaning IANA reserved the pair together rather than treating tcp and udp as independent grants. The IANA record carries no RFC or reference document, no recorded registration or modification date, no service code, and no assignment notes — these fields are blank in the source registry rather than merely unpopulated by the enrichment process, so they are correctly recorded here as unknown rather than inferred. Unlike many well-known low-numbered ports, mailq does not correspond to any mainstream, currently-maintained mail transfer agent or daemon: no version of Sendmail, Postfix, Exim, or a comparable MTA is documented as binding a live network service to TCP/UDP 174. The name likely echoes the Unix mailq / sendmail -bp local queue-listing command by convention rather than describing an active wire protocol, but no primary source confirms that link, so it is treated here as an unverified naming parallel. GRC's Port Authority database lists port 174 as name "mailq," purpose "MAILQ," with no documented trojans, malware associations, or security advisories on file. No CVE, Shodan-specific exposure data, or scanning-prevalence writeup for port 174/udp was located in this pass. For an analyst, an open port 174/udp should be treated as an unusual, low-prevalence finding with no confirmed legitimate service explaining it — worth investigating as a custom/internal use, a decoy, or a misconfiguration rather than assumed to be a standard mail-queue listener, since no standard software is known to expose it.
- IANA assignment
mailq— "MAILQ"; reference (blank — no RFC cited in IANA registry); assignee/contact [Rayan_Zachariassen] [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- Dual registration
- 174/tcp is registered under the identical service name, description, assignee, and contact [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row for 174/tcp)
- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification date, service code, assignment notes
- blank in the IANA registry for this entry — recorded as Unknown, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; IANA XML registry
- Related ports
- naming theme only overlaps mail-transport ports (e.g., 25/tcp SMTP); no technical relationship confirmed [Unknown]
Primary use / common software
no confirmed mainstream MTA or daemon (Sendmail, Postfix, Exim, etc.) found binding a live service to TCP/UDP 174; the IANA name likely parallels the Unix mailq/sendmail -bp queue-listing command in name only
Security implications / exposure history
GRC Port Authority lists no known trojans or malware association for port 174; no CVE or scanning-prevalence data located
Typically seen on
no documented typical host population [Unknown]
- Analyst note
- treat an open 174/udp as an anomalous, low-prevalence finding — no standard software is known to explain it, so investigate as custom/internal use, decoy, or misconfiguration.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| mailq | UDP | — | 0.04% |
| mailq | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.