Port 5222 · XMPP client

All network ports
Messaging & media · Registered5222/tcp

Port / TCP

5222XMPP client

XMPP client-to-server connections for federated instant messaging and presence.

If it is internet-facing: Port 5222 is routine where it is expected. Its risk lives in the service configuration behind it, not the port itself.

Exposure

Internet-facing

Transport

Encryption optional

Risk if public

Low

Exposure verdict

ReachInternet-facing

Port 5222 normally answers from the internet, but the transport is not confidential by default. Enforce the encrypted variant before the traffic leaves your network.

TransportEncryption optional

Encryption is available but negotiated or configured rather than guaranteed. A client that does not insist on it will silently fall back to plaintext.

RangeRegistered (1024–49151)

Registered with IANA on request, but bindable by any unprivileged user. Registration records intent — it does not reserve the port, so collisions between products are common.

FamilyMessaging & media

Grouped with the other messaging & media ports so a rule written for one can be checked against its neighbours.

What actually goes wrong

1 note
  • Modern servers require STARTTLS and SASL before allowing a session to open.

Recommended firewall rule

Allow it, and harden the service

This port is expected to answer from anywhere, so the firewall is not where its security comes from.

ufw

sudo ufw allow 5222/tcp

iptables

sudo iptables -A INPUT -p tcp --dport 5222 -j ACCEPT

Check what is really there

Listening locally

sudo ss -tlpn 'sport = :5222'

The bind address is the answer that matters: 127.0.0.1 is local-only, 0.0.0.0 and :: mean every interface.

Listening (macOS)

sudo lsof -nP -iTCP:5222 -sTCP:LISTEN

macOS ships lsof rather than ss; this names the owning process and user.

From outside

nmap -sV -Pn -p 5222 <host>

A version probe confirms whether XMPP client is actually what answers, rather than trusting the number. Only scan hosts you are authorised to test.

Reachability

nc -vz <host> 5222

The quick yes/no when you only need to know whether a path exists through the firewall.

Nearby and related ports

8
ProtocolTCP
Rangeregistered
Transportopportunistic
Exposurepublic