61
Summary
- // if you see it open
- No IANA-assigned service since the 2017-05-18 removal. Port sits in the privileged well-known range (0-1023), so binding requires root/admin on most OSes — an unexpected open 61/tcp is a higher-confidence indicator of misconfiguration or unauthorized software than an ephemeral-range port. No documented CVEs or active exploits against the original NI MAIL service.
- // analyst note
- treat any live listener on 61/tcp as anomalous; legitimate modern use is not expected.
About port 61/tcp.
Port 61/tcp is currently listed as Reserved in the IANA Service Name and Transport Protocol Port Number Registry: it has no service name, no assignee, no contact, no registration date, and a blank reference field, and the registry records that "This entry has been removed on 2017-05-18." The same status applies to 61/udp — both transports are dual-registered as Reserved and share the identical removal note. Before that removal, port 61 carried the service name ni-mail ("NI MAIL"), an early-1980s experimental electronic-mail facility. NI MAIL (Network Independent Mail) was built on NIFTP, the Network Independent File Transfer Protocol, and is documented in IEN 169, "A Simple NIFTP-Based Mail System" (University College London, January 1981); the MTP↔NIMAIL interface is also discussed in RFC 786 (1981). The ni-mail name appears in the historic Assigned Numbers RFCs — RFC 990 (1986), RFC 1010 (1987), and RFC 1340 (1992) — with RFC 1340 being the last major Assigned Numbers document to list it. The system never achieved widespread or production deployment and is best treated as a legacy/historic curiosity. For an analyst, there is no modern software that legitimately uses port 61, and because it sits in the privileged well-known range (0–1023) — where binding generally requires root/administrator privileges — a process found listening on 61/tcp today should be treated as anomalous and investigated rather than assumed benign. No CVEs or active exploits are documented against the original NI MAIL service, and observed scan traffic to the port is low. The IANA reference column is blank in the source and is left blank here; the "RFC 5" string seen in one fetched copy of RFC 1340 is a parsing artifact, not a real reference (RFC 5 long predates NIFTP).
- IANA assignment
- Reserved — no service name, no assignee, no contact, no registration date; Reference column blank; dual-registered 61/tcp + 61/udp; entry removed on 2017-05-18 [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (CSV, line 130)
- Range class
- well-known (0–1023) [Confirmed]
- Modification date
- 2017-05-18 (registry removal) [Confirmed] — IANA registry CSV
- Registration date
- Unknown (none recorded in the IANA registry) [Confirmed]
Common software
none known — the underlying NIFTP-based mail system was an early-1980s experiment that never reached production adoption [Confirmed]
Exposure / scanning
low observed traffic; rarely open on modern systems; full-range scans will probe it. No documented CVEs or active exploits against the original NI MAIL service
Security implications
no IANA-assigned service has used this port since the 2017-05-18 removal; the privileged range means binding to it requires root/admin on most OSes, so an unexpected open 61/tcp is a higher-confidence indicator of misconfiguration or unauthorized software than an ephemeral-range port would be
- Former service name
ni-mail("NI MAIL" / NI MAIL) prior to removal [Confirmed] — RFC 1340 (1992) Assigned Numbers- Primary historical use
- NI MAIL (Network Independent Mail), an early-1980s experimental mail system layered on NIFTP (Network Independent File Transfer Protocol); documented in IEN 169 (UCL, Jan 1981) and related to the MTP↔NIMAIL interface in RFC 786 (1981); listed in RFC 990, RFC 1010, RFC 1340[Confirmed] — IETF datatracker (RFC 1340, RFC 786), RFC 990
- Analyst note
- treat any live listener on 61/tcp as anomalous; legitimate modern use is not expected.
About port 61/udp.
Port 61/udp is not currently assigned in the IANA Service Name and Transport Protocol Port Number Registry: the entry was marked Reserved and then explicitly removed by IANA on 2017-05-18, leaving a blank service name, blank assignee, blank reference, and no registration date. Historically, however, port 61 carried the name ni-mail — "NI MAIL," a Network Independent Mail protocol from the early-1980s research Internet that ran on top of NIFTP (the Network Independent File Transfer Protocol). It appears in the assigned-numbers documents RFC 900 and RFC 1010, and the related RFC 786 (July 1981) describes the ISI TOPS20 MTP-to-NI-MAIL interface; the underlying mail system itself is sketched in IEN 169, "A Simple NIFTP-Based Mail System." NI MAIL was never given a standalone defining RFC for port 61's wire behavior, was never widely deployed, and the registry entry was eventually de-listed. For an analyst this makes port 61/udp effectively a dead number: there is no known production software, no documented scanning campaign, and no CVE tied to it. Because the port is officially unassigned, any traffic seen on 61/udp on a production host is anomalous and worth investigating, but it is not a recognized attack surface in the way active UDP services such as 161/udp (SNMP) or 1900/udp (SSDP) are. The TCP counterpart, 61/tcp, is identically registered as Reserved and was removed on the same date, 2017-05-18, with the same blank fields — so the removal applies to both transports. The IANA Reference column is blank in the authoritative source and is recorded here as blank; no RFC defines this port's service and none should be fabricated.
- IANA assignment
- Removed — entry was Reserved, then de-listed by IANA on 2017-05-18; blank service name, blank assignee, blank reference [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry (assignment note: "This entry has been removed on 2017-05-18.")
- Range class
- well-known (0–1023)
- IANA reference
- blank (no RFC cited in the registry; not fabricated) [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry
- Registration date
- Unknown (blank in source) [Unknown] — IANA the IANA Service Name and Transport Protocol Port Number Registry
- Modification/removal date
- 2017-05-18 [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry
- Related ports
- 61/tcp (identical Removed entry); contrast active UDP services 161/udp (SNMP), 1900/udp (SSDP)
Primary use
none current — historic NI MAIL only; never given a standalone defining RFC for port 61, never widely deployed
Common software
Unknown — no known production software uses 61/udp; NI MAIL was a research system (ISI TOPS20) with no documented commercial or open-source implementations
Security implications
negligible documented exposure; no known CVEs and no published scan campaigns for 61/udp. Because the number is unassigned (removed 2017-05-18), traffic on 61/udp is anomalous and warrants investigation, but it is not a recognized attack surface like 161/udp (SNMP) or 1900/udp (SSDP)
Typically seen on
nothing in normal operation; any response is an anomaly worth investigating
- Historical service name
ni-mail(NI MAIL — Network Independent Mail, a NIFTP-based experimental mail protocol of the early 1980s) [Likely] — RFC 900, RFC 1010 (assigned-numbers); RFC 786 (ISI TOPS20 MTP–NI-MAIL interface)- TCP dual registration
- 61/tcp is identically Reserved and removed 2017-05-18, with the same blank service name, blank reference, and identical assignment note [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry
- Analyst note
- An officially removed/unassigned port. Treat any 61/udp traffic as anomalous and investigate; there is no legitimate modern service expected here.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ni-mail | UDP | NI MAIL | 0.05% |
| ni-mail | TCP | NI MAIL | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.