You opened a firewall rule, restarted the service, and the app still cannot reach the database. Is the port actually open? One command answers that in two seconds: telnet host port. This guide shows you how to use telnet, from enabling the Telnet Client on Windows 11 to reading what a server says back when you talk to it by hand.
If you would rather try it on a real target than read about it, our free Learning Lab 102 has you find a Telnet service with Nmap and log in to it from a browser-based terminal, no setup needed.
Quick answer:
- Windows: the Telnet Client is off by default. Enable it once from an administrator Command Prompt with
dism /online /Enable-Feature /FeatureName:TelnetClient, then open a new window. - Run it:
telnet <host> <port>, for exampletelnet 192.0.2.10 443. A blank screen or "Connected to" means the port is open. "Connect failed" or "Connection refused" means it is closed. A long hang usually means a firewall is dropping the traffic. - Get out: press
Ctrl + ], typequit, press Enter.
What Is Telnet and Why Is It Still Useful?
Telnet is a network protocol and command-line client that opens a plain TCP connection to any host and port, then passes whatever you type straight through to the other side.
It dates back to 1969 and was standardized in RFC 854 in 1983 as a way to log in to remote machines on port 23. SSH replaced it for that job long ago, because telnet sends everything, passwords included, in clear text.
What keeps telnet alive is a side effect of that simplicity. Point it at any TCP port and it tells you, instantly, whether something is listening. Point it at a text protocol like HTTP, SMTP or Redis and you can type the protocol yourself and watch the raw replies. If port numbers are fuzzy for you, our guide on network ports covers the basics.
Typical uses today:
- Checking whether a port is open and reachable through the firewall
- Debugging mail delivery by speaking SMTP by hand
- Sending a raw HTTP request to see exactly what the server returns
- Reading service banners (SSH, SMTP, FTP) during an authorized security assessment
- Managing old switches, routers and embedded devices that only speak Telnet
How to Enable Telnet on Windows 11 and Windows 10
Windows has shipped with the Telnet Client turned off since Windows Vista. Until you enable it, typing telnet gets you "'telnet' is not recognized as an internal or external command, operable program or batch file." Enabling it takes one command or a few clicks, and you need administrator rights either way.
Option 1: One Command (Fastest)
Right-click Command Prompt or Terminal, choose Run as administrator, and run:
dism /online /Enable-Feature /FeatureName:TelnetClient
Prefer PowerShell? This does the same thing, also from an elevated window:
Enable-WindowsOptionalFeature -Online -FeatureName TelnetClient
Both finish in a few seconds and do not need a restart. On Windows Server, Install-WindowsFeature Telnet-Client works too.
Option 2: Windows Features Dialog
- Press
Win + R, typeoptionalfeatures, press Enter - Scroll to Telnet Client and tick the box
- Click OK and wait for "Windows completed the requested changes"
On Windows 11 you can reach the same dialog from Settings: System > Optional features > More Windows features (on some builds it sits under Apps > Optional features). Telnet Client is not in the "View features" search list, which trips up a lot of people.
Check That It Works
Open a new Command Prompt (windows opened before the install do not see the new command) and type telnet:
Welcome to Microsoft Telnet Client
Escape Character is 'CTRL+]'
Microsoft Telnet>
Type quit to leave. You are ready to test ports.
Installing Telnet on Linux and macOS
Most Linux distributions and every recent Mac ship without a telnet client. One package fixes that:
| System | Install command |
|---|---|
| Debian, Ubuntu, Kali | sudo apt install telnet |
| Fedora, RHEL, Rocky, AlmaLinux | sudo dnf install telnet |
| Arch Linux | sudo pacman -S inetutils |
| Alpine (containers) | apk add inetutils-telnet |
| macOS | brew install telnet (needs Homebrew) |
Apple removed telnet from macOS in High Sierra (10.13), so "telnet: command not found" on a Mac is normal. If you only need to check a port and cannot install anything, macOS already includes nc: see the alternatives section below.
To confirm the install, run which telnet. It should print a path such as /usr/bin/telnet or /opt/homebrew/bin/telnet.
How to Use the Telnet Command
To use telnet, run telnet host port from Command Prompt, PowerShell or any terminal, for example telnet example.com 80. The host can be a name or an IP address, and the port comes after it, separated by a space (not a colon). Leave the port out and telnet uses 23.
What Success Looks Like
On Linux and macOS:
$ telnet 192.0.2.10 80
Trying 192.0.2.10...
Connected to 192.0.2.10.
Escape character is '^]'.
On Windows, a successful connection is easy to misread: the window clears and you get a blank screen with a blinking cursor, and the title bar changes to "Telnet 192.0.2.10". No "Connected" message. That blank screen is the success message.
What Failure Looks Like
telnet: Unable to connect to remote host: Connection refused
On Windows the same result reads:
Connecting To 192.0.2.10...Could not open connection to the host, on port 80: Connect failed
Reading the Result
| What you see | What it means |
|---|---|
| Connected / blank screen | Something is listening and your traffic reaches it |
| Connection refused / Connect failed (instantly) | The host answered, but nothing listens on that port (or a firewall actively rejects it) |
| Hangs, then times out | Packets are being dropped: a firewall, a security group, or the host is down |
| Unknown host / name or service not known | DNS could not resolve the name: try the IP address |
How to Exit Telnet
Press Ctrl + ] to reach the telnet> prompt, then type quit. Ctrl + C does not close a telnet session, which catches almost everyone the first time. If the remote service has its own logout command (QUIT in SMTP, exit in a shell), that works too.
Telnet Commands Inside a Session
Once you press Ctrl + ] (or run telnet with no arguments), you are at the telnet command prompt. These commands work in both the Windows and Linux/macOS clients:
| Command | What it does |
|---|---|
open host port |
Connect to a host (Windows accepts o) |
close |
Close the current connection but stay in telnet |
status |
Show whether you are connected, and to what |
display |
Show current settings |
set / unset |
Change options. On Windows, set localecho shows what you type |
quit |
Exit telnet |
? |
List every command your client supports |
On Windows you can also log the whole session to a file straight from the command line: telnet /f session.txt mail.target.example 25. The full option list is in Microsoft's telnet reference.
Telnet Examples: Test Ports and Talk to Services
Test Whether a Port Is Open
Swap in the port of the service you care about:
| Command | Service |
|---|---|
telnet host 22 |
SSH |
telnet host 25 / 587 |
SMTP / mail submission |
telnet host 80 / 443 |
HTTP / HTTPS |
telnet host 3389 |
Remote Desktop (RDP) |
telnet host 3306 / 5432 |
MySQL / PostgreSQL |
telnet host 6379 |
Redis |
Send an HTTP Request by Hand
Connect to port 80, then type the request and finish with an empty line (press Enter twice):
telnet example.com 80
GET / HTTP/1.1
Host: example.com
Connection: close
The server answers with a status line such as HTTP/1.1 200 OK, its headers, then the page. On Windows, turn on local echo first (Ctrl + ], set localecho, Enter, Enter) or you will be typing blind, and avoid Backspace: it is sent to the server as a character instead of erasing anything.
This does not work on port 443. HTTPS starts with a TLS handshake that telnet cannot do, so telnet only tells you the port is open. For a real conversation over TLS use openssl s_client -connect example.com:443.
Talk to a Mail Server (SMTP)
telnet mail.target.example 25
220 mail.target.example ESMTP Postfix
EHLO client.target.example
250-mail.target.example
250-STARTTLS
250 8BITMIME
MAIL FROM:<[email protected]>
250 2.1.0 Ok
RCPT TO:<[email protected]>
250 2.1.5 Ok
DATA
354 End data with <CR><LF>.<CR><LF>
Subject: telnet test
Hello from telnet.
.
250 2.0.0 Ok: queued
QUIT
221 2.0.0 Bye
The three-digit codes tell you where delivery breaks:
- 220: server ready
- 250: command accepted
- 354: go ahead, send the message body (end it with a line containing only a dot)
- 530: authentication required first
- 550 / 554: rejected: unknown mailbox, relaying denied, or your IP is on a blocklist
Two gotchas. Many home ISPs and cloud providers block outbound port 25, so a timeout there may be your network, not the mail server. And port 587 expects STARTTLS before login, which telnet cannot do: use openssl s_client -starttls smtp -connect mail.target.example:587 for that part.
Quick Checks for Other Services
- Redis (6379): type
PING. A healthy server replies+PONG, or-NOAUTH Authentication required.if a password is set. - SSH (22): the server greets you with its version, such as
SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13. - MySQL (3306): you get a burst of binary with a readable version string in it. That is the handshake; the port is fine.
In practice, those greetings are why testers still reach for telnet during authorized assessments. A banner often gives away the exact software version, which you can then check against known vulnerabilities. The appliance in Learning Lab 102 announces its vendor and firmware the moment you connect, which is more than Nmap's version scan manages on that host.
Telnet Alternatives When You Cannot Install It
Locked-down laptop, no admin rights, or a minimal container? These built-in tools answer the same "is the port open?" question.
Windows: Test-NetConnection
Test-NetConnection example.com -Port 443
Look at the last line of the output: TcpTestSucceeded : True means the port is open. It ships with Windows PowerShell and needs no admin rights; tnc is the short alias. See Microsoft's documentation for more options.
macOS and Linux: Netcat
$ nc -vz example.com 443
Connection to example.com port 443 [tcp/https] succeeded!
-z just checks the port; drop it to get an interactive session like telnet's. Our guide on how to use Netcat goes much further.
Anywhere curl Exists
curl speaks the telnet protocol, and Windows 10 and 11 ship with curl.exe: curl -v telnet://192.0.2.10:3306 prints "Connected to" on success.
Telnet and nc check one port at a time. To check hundreds, you want a port scanner: our Nmap cheat sheet has the commands.
Telnet vs SSH: Never Log In Over Telnet
Telnet has no encryption at all. Your username, your password, every command and every line of output cross the network as plain text. Anyone who can capture traffic on the path (a compromised router, a shared Wi-Fi network, a mirrored switch port) can read the whole session in Wireshark with "Follow TCP Stream".
SSH does the same job with encryption, server authentication (so you know you reached the right machine), integrity checks and key-based logins. For remote administration, SSH wins every time.
Telnet's weakness still matters in the real world. The Mirai botnet in 2016 spread to hundreds of thousands of cameras and routers simply by logging in over Telnet with factory-default passwords. If you find a device on your own network with port 23 open, disable Telnet or isolate the device.
The rule of thumb: use telnet to test connections, never to log in with credentials you care about.
Legal and Ethical Considerations
Critical reminder: Only connect to systems you own or have explicit written permission to test. Even a simple port check can trip intrusion detection and break an acceptable use policy, and unauthorized access attempts are illegal in most countries.
- Test your own servers and the services you administer
- On client work, stay inside the written scope of the engagement
- In bug bounty programs, follow the program's rules on scanning and service testing
- Never try credentials on devices you do not control, even "default" ones
Training labs exist so you can practice all of this legally: every target on HackerDNA labs is yours to connect to, scan and break into.
Frequently Asked Questions
How do I enable telnet on Windows 11?
Open Command Prompt as administrator and run dism /online /Enable-Feature /FeatureName:TelnetClient. Or go to Settings > System > Optional features > More Windows features, tick Telnet Client and click OK. Then open a new Command Prompt and use telnet host port.
Why do I get "'telnet' is not recognized as an internal or external command"?
The Telnet Client is not enabled, or you are using a window that was open before you enabled it. Enable it (see above) and open a new Command Prompt.
How do I telnet to a specific port in cmd?
Put the port after the host with a space: telnet 192.0.2.10 8080. Do not use a colon (host:8080), which telnet treats as part of the host name.
How do I test if a port is open with telnet?
Run telnet host port. A blank screen (Windows) or "Connected to" (Linux/macOS) means open. "Connect failed" or "Connection refused" means closed. A long wait followed by a timeout means a firewall is dropping the traffic.
How do I exit telnet?
Press Ctrl + ], type quit and press Enter. Ctrl + C does not work.
What is the default telnet port?
Port 23. If you type telnet host without a port, the client connects to 23.
Can I use telnet to test HTTPS?
Only to check that port 443 is open. Telnet cannot do the TLS handshake, so for an actual HTTPS conversation use openssl s_client -connect host:443 or curl -v https://host.
How do I install telnet on a Mac?
Install Homebrew, then run brew install telnet. For a quick port check without installing anything, use the built-in nc -vz host port.
Is telnet still used in 2026?
Yes, mostly as a diagnostic tool for testing ports and text protocols, and on legacy network gear. For logging in to systems, SSH replaced it because telnet sends passwords in plain text.
Your Next Steps
You now have the whole telnet workflow: enable the client, run telnet host port, read the result, and escape with Ctrl + ] and quit. Keep it for testing, and use SSH whenever a password is involved.
The best way to make it stick is to use it on a real target. In the free Learning Lab 102 you scan an appliance, connect to its Telnet service and escalate to root, all from your browser. For the bigger picture of how testers enumerate services, the Network Penetration Testing course picks up from there, and Hacking 101 covers the fundamentals if you are just starting out.
Start with HackerDNA's free tier: no credit card required.