Telnet Command: How to Enable and Use Telnet (Windows 11)

Cybersecurity Basics
12 min read
Telnet Command: How to Enable and Use Telnet (Windows 11)
On this page
  1. What Is Telnet and Why Is It Still Useful?
  2. How to Enable Telnet on Windows 11 and Windows 10
    1. Option 1: One Command (Fastest)
    2. Option 2: Windows Features Dialog
    3. Check That It Works
  3. Installing Telnet on Linux and macOS
  4. How to Use the Telnet Command
    1. What Success Looks Like
    2. What Failure Looks Like
    3. Reading the Result
    4. How to Exit Telnet
  5. Telnet Commands Inside a Session
  6. Telnet Examples: Test Ports and Talk to Services
    1. Test Whether a Port Is Open
    2. Send an HTTP Request by Hand
    3. Talk to a Mail Server (SMTP)
    4. Quick Checks for Other Services
  7. Telnet Alternatives When You Cannot Install It
    1. Windows: Test-NetConnection
    2. macOS and Linux: Netcat
    3. Anywhere curl Exists
  8. Telnet vs SSH: Never Log In Over Telnet
  9. Legal and Ethical Considerations
  10. Frequently Asked Questions
  11. Your Next Steps

You opened a firewall rule, restarted the service, and the app still cannot reach the database. Is the port actually open? One command answers that in two seconds: telnet host port. This guide shows you how to use telnet, from enabling the Telnet Client on Windows 11 to reading what a server says back when you talk to it by hand.

If you would rather try it on a real target than read about it, our free Learning Lab 102 has you find a Telnet service with Nmap and log in to it from a browser-based terminal, no setup needed.

Quick answer:

  1. Windows: the Telnet Client is off by default. Enable it once from an administrator Command Prompt with dism /online /Enable-Feature /FeatureName:TelnetClient, then open a new window.
  2. Run it: telnet <host> <port>, for example telnet 192.0.2.10 443. A blank screen or "Connected to" means the port is open. "Connect failed" or "Connection refused" means it is closed. A long hang usually means a firewall is dropping the traffic.
  3. Get out: press Ctrl + ], type quit, press Enter.

What Is Telnet and Why Is It Still Useful?

Telnet is a network protocol and command-line client that opens a plain TCP connection to any host and port, then passes whatever you type straight through to the other side.

It dates back to 1969 and was standardized in RFC 854 in 1983 as a way to log in to remote machines on port 23. SSH replaced it for that job long ago, because telnet sends everything, passwords included, in clear text.

What keeps telnet alive is a side effect of that simplicity. Point it at any TCP port and it tells you, instantly, whether something is listening. Point it at a text protocol like HTTP, SMTP or Redis and you can type the protocol yourself and watch the raw replies. If port numbers are fuzzy for you, our guide on network ports covers the basics.

Typical uses today:

  • Checking whether a port is open and reachable through the firewall
  • Debugging mail delivery by speaking SMTP by hand
  • Sending a raw HTTP request to see exactly what the server returns
  • Reading service banners (SSH, SMTP, FTP) during an authorized security assessment
  • Managing old switches, routers and embedded devices that only speak Telnet
💻
Practice this now: Learning Lab 102: Nmap and Telnet - scan a legacy network appliance, spot the Telnet service on port 23, log in with its factory-default account and escalate to root. Free, and it runs in your browser.

How to Enable Telnet on Windows 11 and Windows 10

Windows has shipped with the Telnet Client turned off since Windows Vista. Until you enable it, typing telnet gets you "'telnet' is not recognized as an internal or external command, operable program or batch file." Enabling it takes one command or a few clicks, and you need administrator rights either way.

Option 1: One Command (Fastest)

Right-click Command Prompt or Terminal, choose Run as administrator, and run:

dism /online /Enable-Feature /FeatureName:TelnetClient

Prefer PowerShell? This does the same thing, also from an elevated window:

Enable-WindowsOptionalFeature -Online -FeatureName TelnetClient

Both finish in a few seconds and do not need a restart. On Windows Server, Install-WindowsFeature Telnet-Client works too.

Option 2: Windows Features Dialog

  1. Press Win + R, type optionalfeatures, press Enter
  2. Scroll to Telnet Client and tick the box
  3. Click OK and wait for "Windows completed the requested changes"

On Windows 11 you can reach the same dialog from Settings: System > Optional features > More Windows features (on some builds it sits under Apps > Optional features). Telnet Client is not in the "View features" search list, which trips up a lot of people.

Check That It Works

Open a new Command Prompt (windows opened before the install do not see the new command) and type telnet:

Welcome to Microsoft Telnet Client

Escape Character is 'CTRL+]'

Microsoft Telnet>

Type quit to leave. You are ready to test ports.

Installing Telnet on Linux and macOS

Most Linux distributions and every recent Mac ship without a telnet client. One package fixes that:

System Install command
Debian, Ubuntu, Kali sudo apt install telnet
Fedora, RHEL, Rocky, AlmaLinux sudo dnf install telnet
Arch Linux sudo pacman -S inetutils
Alpine (containers) apk add inetutils-telnet
macOS brew install telnet (needs Homebrew)

Apple removed telnet from macOS in High Sierra (10.13), so "telnet: command not found" on a Mac is normal. If you only need to check a port and cannot install anything, macOS already includes nc: see the alternatives section below.

To confirm the install, run which telnet. It should print a path such as /usr/bin/telnet or /opt/homebrew/bin/telnet.

How to Use the Telnet Command

To use telnet, run telnet host port from Command Prompt, PowerShell or any terminal, for example telnet example.com 80. The host can be a name or an IP address, and the port comes after it, separated by a space (not a colon). Leave the port out and telnet uses 23.

What Success Looks Like

On Linux and macOS:

$ telnet 192.0.2.10 80
Trying 192.0.2.10...
Connected to 192.0.2.10.
Escape character is '^]'.

On Windows, a successful connection is easy to misread: the window clears and you get a blank screen with a blinking cursor, and the title bar changes to "Telnet 192.0.2.10". No "Connected" message. That blank screen is the success message.

What Failure Looks Like

telnet: Unable to connect to remote host: Connection refused

On Windows the same result reads:

Connecting To 192.0.2.10...Could not open connection to the host, on port 80: Connect failed

Reading the Result

What you see What it means
Connected / blank screen Something is listening and your traffic reaches it
Connection refused / Connect failed (instantly) The host answered, but nothing listens on that port (or a firewall actively rejects it)
Hangs, then times out Packets are being dropped: a firewall, a security group, or the host is down
Unknown host / name or service not known DNS could not resolve the name: try the IP address

How to Exit Telnet

Press Ctrl + ] to reach the telnet> prompt, then type quit. Ctrl + C does not close a telnet session, which catches almost everyone the first time. If the remote service has its own logout command (QUIT in SMTP, exit in a shell), that works too.

Telnet Commands Inside a Session

Once you press Ctrl + ] (or run telnet with no arguments), you are at the telnet command prompt. These commands work in both the Windows and Linux/macOS clients:

Command What it does
open host port Connect to a host (Windows accepts o)
close Close the current connection but stay in telnet
status Show whether you are connected, and to what
display Show current settings
set / unset Change options. On Windows, set localecho shows what you type
quit Exit telnet
? List every command your client supports

On Windows you can also log the whole session to a file straight from the command line: telnet /f session.txt mail.target.example 25. The full option list is in Microsoft's telnet reference.

Telnet Examples: Test Ports and Talk to Services

Test Whether a Port Is Open

Swap in the port of the service you care about:

Command Service
telnet host 22 SSH
telnet host 25 / 587 SMTP / mail submission
telnet host 80 / 443 HTTP / HTTPS
telnet host 3389 Remote Desktop (RDP)
telnet host 3306 / 5432 MySQL / PostgreSQL
telnet host 6379 Redis

Send an HTTP Request by Hand

Connect to port 80, then type the request and finish with an empty line (press Enter twice):

telnet example.com 80
GET / HTTP/1.1
Host: example.com
Connection: close

The server answers with a status line such as HTTP/1.1 200 OK, its headers, then the page. On Windows, turn on local echo first (Ctrl + ], set localecho, Enter, Enter) or you will be typing blind, and avoid Backspace: it is sent to the server as a character instead of erasing anything.

This does not work on port 443. HTTPS starts with a TLS handshake that telnet cannot do, so telnet only tells you the port is open. For a real conversation over TLS use openssl s_client -connect example.com:443.

Talk to a Mail Server (SMTP)

telnet mail.target.example 25
220 mail.target.example ESMTP Postfix
EHLO client.target.example
250-mail.target.example
250-STARTTLS
250 8BITMIME
MAIL FROM:<[email protected]>
250 2.1.0 Ok
RCPT TO:<[email protected]>
250 2.1.5 Ok
DATA
354 End data with <CR><LF>.<CR><LF>
Subject: telnet test

Hello from telnet.
.
250 2.0.0 Ok: queued
QUIT
221 2.0.0 Bye

The three-digit codes tell you where delivery breaks:

  • 220: server ready
  • 250: command accepted
  • 354: go ahead, send the message body (end it with a line containing only a dot)
  • 530: authentication required first
  • 550 / 554: rejected: unknown mailbox, relaying denied, or your IP is on a blocklist

Two gotchas. Many home ISPs and cloud providers block outbound port 25, so a timeout there may be your network, not the mail server. And port 587 expects STARTTLS before login, which telnet cannot do: use openssl s_client -starttls smtp -connect mail.target.example:587 for that part.

Quick Checks for Other Services

  • Redis (6379): type PING. A healthy server replies +PONG, or -NOAUTH Authentication required. if a password is set.
  • SSH (22): the server greets you with its version, such as SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.
  • MySQL (3306): you get a burst of binary with a readable version string in it. That is the handshake; the port is fine.

In practice, those greetings are why testers still reach for telnet during authorized assessments. A banner often gives away the exact software version, which you can then check against known vulnerabilities. The appliance in Learning Lab 102 announces its vendor and firmware the moment you connect, which is more than Nmap's version scan manages on that host.

Telnet Alternatives When You Cannot Install It

Locked-down laptop, no admin rights, or a minimal container? These built-in tools answer the same "is the port open?" question.

Windows: Test-NetConnection

Test-NetConnection example.com -Port 443

Look at the last line of the output: TcpTestSucceeded : True means the port is open. It ships with Windows PowerShell and needs no admin rights; tnc is the short alias. See Microsoft's documentation for more options.

macOS and Linux: Netcat

$ nc -vz example.com 443
Connection to example.com port 443 [tcp/https] succeeded!

-z just checks the port; drop it to get an interactive session like telnet's. Our guide on how to use Netcat goes much further.

Anywhere curl Exists

curl speaks the telnet protocol, and Windows 10 and 11 ship with curl.exe: curl -v telnet://192.0.2.10:3306 prints "Connected to" on success.

Telnet and nc check one port at a time. To check hundreds, you want a port scanner: our Nmap cheat sheet has the commands.

Telnet vs SSH: Never Log In Over Telnet

Telnet has no encryption at all. Your username, your password, every command and every line of output cross the network as plain text. Anyone who can capture traffic on the path (a compromised router, a shared Wi-Fi network, a mirrored switch port) can read the whole session in Wireshark with "Follow TCP Stream".

SSH does the same job with encryption, server authentication (so you know you reached the right machine), integrity checks and key-based logins. For remote administration, SSH wins every time.

Telnet's weakness still matters in the real world. The Mirai botnet in 2016 spread to hundreds of thousands of cameras and routers simply by logging in over Telnet with factory-default passwords. If you find a device on your own network with port 23 open, disable Telnet or isolate the device.

The rule of thumb: use telnet to test connections, never to log in with credentials you care about.

Critical reminder: Only connect to systems you own or have explicit written permission to test. Even a simple port check can trip intrusion detection and break an acceptable use policy, and unauthorized access attempts are illegal in most countries.

  • Test your own servers and the services you administer
  • On client work, stay inside the written scope of the engagement
  • In bug bounty programs, follow the program's rules on scanning and service testing
  • Never try credentials on devices you do not control, even "default" ones

Training labs exist so you can practice all of this legally: every target on HackerDNA labs is yours to connect to, scan and break into.

Frequently Asked Questions

How do I enable telnet on Windows 11?

Open Command Prompt as administrator and run dism /online /Enable-Feature /FeatureName:TelnetClient. Or go to Settings > System > Optional features > More Windows features, tick Telnet Client and click OK. Then open a new Command Prompt and use telnet host port.

Why do I get "'telnet' is not recognized as an internal or external command"?

The Telnet Client is not enabled, or you are using a window that was open before you enabled it. Enable it (see above) and open a new Command Prompt.

How do I telnet to a specific port in cmd?

Put the port after the host with a space: telnet 192.0.2.10 8080. Do not use a colon (host:8080), which telnet treats as part of the host name.

How do I test if a port is open with telnet?

Run telnet host port. A blank screen (Windows) or "Connected to" (Linux/macOS) means open. "Connect failed" or "Connection refused" means closed. A long wait followed by a timeout means a firewall is dropping the traffic.

How do I exit telnet?

Press Ctrl + ], type quit and press Enter. Ctrl + C does not work.

What is the default telnet port?

Port 23. If you type telnet host without a port, the client connects to 23.

Can I use telnet to test HTTPS?

Only to check that port 443 is open. Telnet cannot do the TLS handshake, so for an actual HTTPS conversation use openssl s_client -connect host:443 or curl -v https://host.

How do I install telnet on a Mac?

Install Homebrew, then run brew install telnet. For a quick port check without installing anything, use the built-in nc -vz host port.

Is telnet still used in 2026?

Yes, mostly as a diagnostic tool for testing ports and text protocols, and on legacy network gear. For logging in to systems, SSH replaced it because telnet sends passwords in plain text.

Your Next Steps

You now have the whole telnet workflow: enable the client, run telnet host port, read the result, and escape with Ctrl + ] and quit. Keep it for testing, and use SSH whenever a password is involved.

The best way to make it stick is to use it on a real target. In the free Learning Lab 102 you scan an appliance, connect to its Telnet service and escalate to root, all from your browser. For the bigger picture of how testers enumerate services, the Network Penetration Testing course picks up from there, and Hacking 101 covers the fundamentals if you are just starting out.

Start with HackerDNA's free tier: no credit card required.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
30,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed