Network port detail · UDP/TCP

58

Xns-mail
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Obsolete and not a notable amplification or attack vector; no CVEs recorded against port 58/tcp. Secondary trojan-port catalogues associate 58/tcp with the late-1990s 'DMSetup' mIRC/IRC worm, but the primary 1998 advisory does not confirm port 58 as a control channel — the association is a third-party database artifact, not analyzed traffic. An open 58 is primarily an obsolescence/reconnaissance signal.
// analyst note
An open port 58 is an obsolescence/reconnaissance signal — the real XNS Mail service is extinct; fingerprint the actual listener and treat it as legacy cruft, a decoy, or a non-standard service rather than genuine XNS Mail.
[ 01 ] — Context

About port 58/tcp.

Updated  ·  Confidence: High

Port 58/tcp is registered with IANA as xns-mail with the description "XNS Mail," assignee and contact both Susie Armstrong, and a blank reference field (dual-registered on TCP and UDP). XNS Mail was the electronic-messaging component of the Xerox Network Systems (XNS) protocol suite developed at Xerox around the late 1970s and early 1980s, comprising a Mail Transport Protocol for server-to-server delivery and an Inbasket Protocol for client message retrieval. XNS was a proprietary stack that ran natively over Xerox's own transport protocols (IDP and SPP), not over TCP/IP; the assignment of "XNS Mail" to port 58 is a cataloguing artifact from the era when XNS services were listed alongside the emerging well-known TCP/IP ports, and there is no evidence XNS Mail ever ran as a TCP service on port 58 in practice. The protocol predated SMTP and was never widely adopted outside Xerox environments. XNS as a whole became obsolete as TCP/IP displaced proprietary networking stacks, though its design strongly influenced later systems such as Novell NetWare's IPX/SPX, Banyan VINES, and AppleTalk — those are distinct stacks, not XNS Mail implementations. The IANA reference field is blank, and IANA publishes no registration date for this entry. For an analyst, an open port 58 has essentially no legitimate modern explanation: the genuine XNS Mail service is extinct, so a responsive 58 is best read as an obsolescence/reconnaissance signal, an anomaly, or a non-standard listener to be fingerprinted rather than trusted at its registry label. A historical, secondary security note also associates port 58 with the late-1990s "DMSetup" mIRC/IRC worm, but that linkage comes from third-party trojan-port catalogues rather than primary malware analysis and carries no current relevance.

IANA assignment
xns-mail — "XNS Mail"; reference (blank — no RFC cited in IANA registry); assignee Susie Armstrong; dual-registered 58/tcp + 58/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (cached row 124); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023) [Confirmed]
Prevalence
rare; no legitimate modern deployments known. SANS ISC lists 58/tcp with a low (green) threat indicator (no specific nmap-services open-frequency figure was confirmed by the consulted sources) [Likely] — https://isc.sans.edu/port.html?port=58
Related ports
58/udp sibling (identically registered xns-mail); contrast SMTP (25) and modern mail submission (587)

Primary use

XNS Mail — the messaging component (Mail Transport Protocol + Inbasket Protocol) of the Xerox Network Systems suite; ran natively over XNS transport (IDP/SPP), not TCP/IP, so the port-58 assignment is a cataloguing artifact

[Likely] — https://en.wikipedia.org/wiki/Xerox_Network_Systems , https://whatportis.com/ports/58_xns-xerox-network-systems-mail

Other/unofficial uses

obsolete; no known modern software implements XNS Mail over TCP/IP. XNS design influenced IPX/SPX, Banyan VINES, and AppleTalk (distinct stacks, not XNS Mail)

[Likely] — https://en.wikipedia.org/wiki/Xerox_Network_Systems , https://networkencyclopedia.com/xerox-network-systems-xns/

Security implications

obsolete; not a notable amplification or attack vector; no CVEs recorded against port 58/tcp. Secondary trojan-port catalogues associate 58/tcp with the historical "DMSetup" mIRC/IRC worm (~1998), but the primary 1998 advisory does not confirm port 58 as a control channel, so the association is a database artifact, not analyzed traffic

[Likely] — https://isc.sans.edu/services.html , https://www.irchelp.org/security/dmsetup.txt

Typically seen on

effectively never seen in modern environments; an open 58 is anomalous and worth fingerprinting

Analyst note
An open port 58 is an obsolescence/reconnaissance signal — the real XNS Mail service is extinct; fingerprint the actual listener and treat it as legacy cruft, a decoy, or a non-standard service rather than genuine XNS Mail.
[ 02 ] — Context

About port 58/udp.

Updated  ·  Confidence: High

Port 58/udp is registered with IANA as xns-mail with the description "XNS Mail," assignee and contact both [Susie_Armstrong], and a blank reference field (dual-registered on 58/tcp and 58/udp). XNS Mail is the electronic-mail transport component of the Xerox Network Systems (XNS) protocol suite, developed at Xerox PARC in the late 1970s and derived from the earlier PARC Universal Packet (PUP) work. XNS ran over its own transport layers — the Internet Datagram Protocol (IDP) and Sequenced Packet Protocol (SPP) — rather than over TCP/IP, so the IANA assignment of port 58 to xns-mail on both TCP and UDP is essentially a mapping artifact from translating the XNS service namespace into the TCP/IP port registry. XNS was historically significant: it directly influenced early LAN stacks at vendors such as Novell (IPX/SPX), 3Com, and Ungermann-Bass before TCP/IP became dominant. For an analyst today the protocol is of historical interest only. XNS Mail and the wider XNS suite are extinct in operational networks, superseded entirely by Internet-standard email protocols (SMTP, IMAP, POP3). No modern software is known to listen on this port, no RFC is cited in the IANA registry (the reference field is blank), and no CVEs, exploit tools, or malware families are documented against 58/udp. Port 58/udp does not appear in Shodan's list of actively tracked ports, indicating negligible internet-facing exposure and effectively no scan telemetry. Because no legitimate service is expected here in modern infrastructure, any unexpected inbound traffic on 58/udp is best treated as background noise or unsolicited probe traffic, and standard hardening is to block traffic to ports carrying no assigned service in the environment.

IANA assignment
xns-mail — "XNS Mail"; reference (blank — no RFC cited in IANA registry); assignee/contact [Susie_Armstrong]; dual-registered 58/tcp + 58/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 124–125)
Range class
well-known (0–1023) [Confirmed]
Current status
obsolete — XNS Mail and the XNS suite are extinct in operational networks, superseded by SMTP/IMAP/POP3 [Confirmed] — https://whatportis.com/ports/58_xns-xerox-network-systems-mail
Prevalence/exposure
not present in Shodan's tracked-ports list (negligible internet-facing exposure; effectively no scan telemetry) [Likely] — https://data-status.shodan.io/ports.html
Related ports
58/tcp (same dual registration); broader legacy Xerox/XNS service cluster

Primary use

XNS Mail, the mail-transport component of the Xerox Network Systems suite (late-1970s Xerox PARC; runs over XNS IDP/SPP, not TCP/IP)

[Confirmed] — https://en.wikipedia.org/wiki/Xerox_Network_Systems

Other/unofficial uses

none documented; XNS was native to Xerox equipment and influenced early LAN stacks (Novell IPX/SPX, 3Com, Ungermann-Bass)

[Likely] — https://itexus.com/xerox-network-systems-xns-pioneering-networking-protocols/

Security implications

no known CVEs, exploit tools, or malware associated with 58/udp; community database reports no virus/trojan activity; treat any inbound traffic as noise or probe traffic and block where no service is in use

[Likely] — https://www.auditmypc.com/udp-port-58.asp

Typically seen on

nothing in modern infrastructure; historically Xerox XNS network equipment

Analyst note
An open 58/udp is not expected in any current environment; investigate as anomaly, decoy, or probe traffic rather than a legitimate service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
xns-mail UDP XNS Mail 0.04%
xns-mail TCP XNS Mail 0.00%
IANA name
xns-mail
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.