- Telnet allows remote administration via a text terminal and is still useful for connectivity testing, but it lacks encryption, which poses significant security risks.
- SSH is the modern and secure replacement, increasing data protection and providing strong authentication, displacing Telnet in most professional and cloud environments.
- Today, Telnet should only be used in highly controlled contexts, internal networks, or on older devices; modern alternatives are recommended whenever possible.
Have you ever wondered how system administrators can access remote computers over a network and manage tasks as if they were sitting right in front of them ? That's precisely what Telnet allows, a classic protocol that has served as a bridge between computers via TCP/IP connections for decades. Although more secure alternatives like SSH exist today, Telnet still has useful functions in specific contexts and is a term that every network professional or curious user should be thoroughly familiar with.
Throughout this article, we'll delve into the world of Telnet: from its origins and operating principles to how it's used, its security risks, differences with SSH , practical examples, ways to activate it on modern systems, and why, despite everything, it remains a relevant topic in technology. If you're looking for a clear, comprehensive, and straightforward explanation to understand Telnet once and for all, you've come to the right place.
What exactly is Telnet? The origin and history of an essential protocol
Telnet is a network protocol that emerged in the late 60s as a solution for connecting remote terminals to servers or computer systems, using TCP/IP connections as its foundation. It derives from the term "Teletype Network" or "Telecommunication Network," and its primary function was to allow users and administrators to access remote machines, manage resources, troubleshoot problems, or execute commands as if they were physically present at the remote device.
This protocol was key during the expansion of the Internet and the adoption of networks in academic centers and business environments, as it offered the possibility of opening remote sessions on UNIX systems and other operating systems, facilitating collaborative work and administration without physical barriers. Telnet is used through TCP port 23 by default, although it can be configured to use other ports if necessary.
Although its popularity began decades ago, Telnet remains a standard feature in many operating systems and network environments today, both for administration and for certain diagnostic and connectivity tasks.
How does Telnet work? Technical principles and operating modes

Telnet works on a client-server architecture: the client is the starting point (the machine you connect from) and the server is the computer or device you want to access remotely.
To establish this communication, both ends must have Telnet enabled . The process is as follows:
- The client launches an access request to the server, indicating the username and password to log in.
- The server validates the credentials and, if correct, opens a virtual terminal session, allowing the user to interact using text commands.
- From there, you can run commands, browse files, monitor processes, or perform any task allowed by the remote operating system.
Telnet operates in text mode, without graphics, and allows for both basic administration and remote troubleshooting. Initial advantages included low resource consumption and ease of use for diagnostic and maintenance tasks.
The protocol offers different modes of operation adapted to communication needs:
- Default mode (half duplex): The user enters a complete line of text before sending it; this is the most basic mode.
- Character Mode: Each character is sent as it is typed, generating more traffic, but useful in real time for certain applications.
- Line mode: Entered characters are sent when the line is completed; this is common when handling long commands.
In addition to these modes, Telnet incorporates a series of commands and options negotiable between the client and server to adjust behaviors such as character echo, window size, terminal type, or the suppression of certain controls. This provides flexibility for working with different operating systems and devices.
What is Telnet used for today? Main uses, advantages, and limitations
While Telnet has been superseded for secure remote management, it still remains useful for tasks such as:
- Troubleshoot connectivity and network issues: Test whether a port is open or whether a service is responding correctly, which is essential for system administrators.
- Access remote equipment for rapid diagnosis: especially in environments where security is not critical (e.g. internal networks or older devices that do not support SSH).
- Network Device Configuration: routers, switches and other equipment that still allow Telnet access, primarily in legacy installations.
- Connecting to legacy systems or applications: some veteran enterprise systems, text-based BBSs, and public services such as online weather forecasts and classic game servers.
- Task automation and basic scripting: It is possible to use scripts with Telnet to send configuration commands or perform repetitive tests.
Telnet's advantages include its simplicity, low resource consumption, and ease of testing network services, making it a useful tool for quick administration and troubleshooting tasks. However, it has significant shortcomings:
- Does not encrypt information: All data, including passwords and commands, travel in clear text.
- Lacks advanced authentication: Anyone with access to the network can attempt to intercept or manipulate the session.
- Vulnerability to attacks and malware: Open Telnet ports are a target for exploits and unauthorized access.
For these reasons, it is only recommended in fully secure environments, isolated networks, or for testing purposes where security is not a priority.
Telnet and security: risks and reasons for its replacement
Telnet's biggest weakness lies in its security. All information transmitted between the client and server travels unencrypted, in what is known as "plain text." This means that anyone capable of intercepting network traffic—using tools like Wireshark or tcpdump—can read usernames, passwords, commands, and data transmitted during the session.
This lack of encryption has made Telnet inadvisable for any remote access on networks where there's a risk of eavesdropping, such as the Internet or corporate environments with external connections. Additionally:
- Does not offer verification of the identity of the endpoints communication, making it susceptible to man-in-the-middle attacks.
- Numerous vulnerabilities have been discovered over the years, affecting both client and server implementations.
- It is common for Internet-facing Telnet services to be attacked by automated scripts seeking access without a password or with weak credentials.
- Modern operating systems usually have Telnet disabled by default, precisely because of these risks.
In the face of these threats, the SSH (Secure Shell) protocol emerged as a natural response and substitute, encrypting all communications and providing robust authentication and verification mechanisms.
Telnet vs SSH: Key differences and when to use each one
SSH and Telnet share the goal of enabling remote access to systems and terminals, but they differ in essential aspects that have a direct impact on security and functionality.
| Feature | telnet | SSH |
|---|---|---|
| Is the data encrypted? | No | Yes, strong encryption |
| Default port | 23 (TCP) | 22 (TCP) |
| Advanced Authentication | No | Yes (public keys, certificates) |
| File Transfer | Only with external protocols | Yes (SCP, SFTP integrated) |
| Recommended use | Internal networks, legacy devices | All types of networks, especially the Internet |
| Cross-platform compatibility | High | High |
| Consumption of resources | Low | Moderate/high |
In short, Telnet can be used in closed, trusted environments (for example, LANs disconnected from the internet or when the remote device doesn't support SSH), while SSH is always the preferred option for any operation involving the transmission of sensitive data or exposure to potentially dangerous networks. Furthermore, SSH incorporates additional features, such as port forwarding, secure tunnels, and the ability to securely automate tasks.
Practical uses and real-life examples of Telnet
Beyond theory, Telnet still has practical applications that are worth knowing about, both for system testing and for occasional administration tasks.
- Check for open ports on remote servers: It is common to use Telnet to test whether services such as HTTP (port 80), HTTPS (443), or SMTP (25) are listening on a particular computer. The usual command would be:
telnet ip_address_or_domain_port
- If the port is open, the screen will be blank and you'll be able to type commands, depending on the service. If not, a connection error will occur.
- Access text-based BBS (Bulletin Board Systems): Some older forums, online gaming services, or nostalgic platforms still allow access via Telnet, just for retro entertainment.
- Test utility connections: There are interesting examples, such as checking the weather forecast, playing chess online or watching ASCII representations of movies, using commands like:
telnet towel.blinkenlights.nl 23
- Automate simple tasks on network devices: Some routers and switches allow configuration scripting via Telnet when SSH is not available.
However, for any task involving sensitive information, the recommendation remains to migrate to SSH or, failing that, protect the Telnet session using VPN tunnels or other additional security measures.
How to enable and use Telnet on Windows, Linux, and Mac
Over the years, modern operating system versions have opted to disable Telnet by default due to its risks. But you can still enable and use the protocol in a few simple steps, both in server and general-user environments.
On windows
Telnet is no longer enabled by default in Windows 10, 11, and recent Server versions. To enable it:
- Enter in the Control panel and access Programs.
- Press on Enable or disable Windows features.
- Find and check the box Telnet Client, then click Accept.
From that point on, you can open Command Prompt or PowerShell and run the telnet command to start a session. For example:
telnet server.remote.com 23
You can also enable Telnet from the command line with:
Dism /Online /Enable-feature /FeatureName:TelnetClient
Or from PowerShell:
Install-WindowsFeature -name Telnet-Client
On Linux
Most distributions maintain Telnet as an installable package, although it no longer comes pre-installed. You can install it with your distribution's package manager, for example in Ubuntu:
sudo apt update sudo apt install telnet
Then, just open the terminal and run:
telnet ip_or_domain port
On Mac OS
On older Mac systems, Telnet was available by default. In versions like macOS High Sierra (10.13) and later, Apple removed the Telnet client. If you need it, you can:
- Copy the executable from a previous version.
- Compile Telnet from source code.
- Or use external applications if you only need to perform connectivity tests.
There is also the option of using the Network Utility to scan ports, which complements the classic use of Telnet.
Telnet Advanced Commands and Options
Telnet provides a range of basic and advanced commands that allow you to negotiate options between the client and server, making it easy to adjust parameters such as terminal type, window size, and echo management.
- help o ?: displays the available commands.
- open : connects to the host or IP on the indicated port.
- quit: closes the current session.
- set/unset : Turns features such as echo, control muting, terminal type, etc. on or off.
As for the underlying protocol, Telnet negotiates options such as:
- Echo: control over the display of typed characters.
- Suppress Go Ahead: eliminates the need for additional signals to send data.
- Status, window size, terminal type, linemode…: different parameters that adapt the session to the remote device or application.
There are control and subnegotiation codes that facilitate tasks such as managing environment variables, authentication, or extending basic functionality as allowed by the client and server.
Critical Limitations and Risks of Telnet
Using Telnet today carries obvious risks:
- Any data transmitted, including passwords, can be captured by third parties with access to the network.
- Lack of strong authentication: If you know the IP and port, you can attempt access as many times as you like, sometimes without restrictions.
- Easy exploitation by malware or automated scripts: There are bots that search for open ports 23 to attempt forced access or install backdoors.
- It is not suitable for cloud environments, modern IoT devices, or critical services where security is a basic requirement.
For all these reasons, security experts and leading organizations recommend disabling Telnet whenever possible or restricting it to internal networks, disconnected from the Internet, and with additional physical access controls.
Modern Telnet Alternatives
Given the intrinsic insecurity of Telnet, there are several widely adopted alternatives:
- SSH (Secure Shell): It is the ultimate choice for remote administration, secure connectivity, and file transfers. All information is encrypted and can be authenticated using public keys. SSH also allows for port forwarding, encrypted tunnels, secure automation, and file transfers (SCP/SFTP).
- Mosh (Mobile Shell): Ideal for unstable connections, it maintains the session even if you change networks or temporarily lose connection, perfect for mobile administration.
- RDP (Remote Desktop Protocol): More oriented toward graphical administration in Windows environments; it allows you to view and manage computers with a graphical interface.
- VNC (Virtual Network Computing): remote access to the graphical interface, useful for mixed environments and, when combined with an SSH tunnel, can achieve similar security.
- VPN (Virtual Private Network): An option to create a secure channel so you can use Telnet or other services without exposing your data to third parties. While it doesn't eliminate the internal risks of Telnet, it does add an important barrier.
The choice of one alternative or the other depends on the context, but whenever security is important, SSH is the go-to solution to replace Telnet.
Cases where Telnet may still be useful or unavoidable
In certain situations, Telnet may still be necessary or useful, but always after assessing the risks and applying complementary measures:
- Internal or isolated networks without Internet access: labs, test environments, or legacy systems where SSH is not available.
- Legacy devices, industrial hardware or old equipment: where only Telnet is supported for configuration or diagnostics.
- Basic scripting and automation with simple tools: especially when risks are controlled and the infrastructure does not allow for modern alternatives.
Whenever Telnet is used, it is advisable to restrict access, monitor logs, and consider using encrypted tunnels (such as VPNs) to minimize exposure.
Telnet FAQ: Common Questions Answered
Throughout its history, Telnet has raised many questions, especially for those new to network management or looking to run quick tests. Here are the answers to the most common ones:
- Does Telnet allow file transfer?
- Not directly. Telnet only handles text sessions. To transfer files, you must use other protocols such as FTP, SCP (via SSH), or implement specific scripts.
- Is it possible to use Telnet for automation or scripting?
- Yes, You can create scripts that open Telnet sessions, send commands, and process responses. However, due to the lack of encryption, it is not recommended for sensitive tasks.
- Does Telnet support multiple simultaneous users?
- Yes, Multiple Telnet sessions can be opened to the same server, each with independent authentication.
- Is Telnet useful for IoT or cloud diagnostics?
- Only in very specific cases and when security is not a priority. Modern environments prioritize the use of encrypted protocols to protect data and devices.
- Can Telnet encrypt your communications?
- Not natively. Traffic can only be encrypted if used within a VPN or secure tunnel, but the protocol itself lacks encryption mechanisms.
Tips for using Telnet responsibly and safely
If you must use Telnet, follow these recommendations to minimize risks:
- Always use it on trusted networks and disconnected from the Internet.
- Disable the service on servers and computers that do not require it.
- Strengthen access with firewalls and IP restrictions.
- Regularly monitor access logs to detect unauthorized attempts.
- Always consider migrating to SSH or using VPNs if you are exposed to insecure networks.
- Avoid leaving ports open unnecessarily and eliminate default usernames or passwords.
The Future of Telnet: Does It Make Sense to Continue Using It?
Although Telnet is a classic tool for network and server administration, its obsolescence is clear compared to modern and secure alternatives. Except in highly controlled environments, its use is increasingly restricted to occasional diagnostics, older devices, or quick tests. Most manufacturers, developers, and cloud providers are opting for SSH and encrypted technologies, relegating Telnet to a largely symbolic role.
However, understanding Telnet remains relevant for both networking professionals and technology enthusiasts, as it helps in understanding the evolution of remote administration, the fundamentals of terminal access, and the historical challenges of cybersecurity.
Telnet represented the essence of remote administration and connectivity in the early days of modern computing. Although it has been superseded in security and functionality, it remains the starting point for understanding how remote access has evolved, the dangers of transmitting sensitive data without protection, and the importance of adopting robust protocols like SSH. Mastering Telnet is, in a way, mastering the history and foundations of modern networking.