TCP Port 2053 – alt-HTTPS (Cloudflare Proxied Range)

TCP Port 2053 – alt-HTTPS (Cloudflare Proxied Range)

Port 2053 is one of the alternate HTTPS ports that Cloudflare proxies by default for customer domains. Its IANA registration (“lot105-ds-upd”) is an obscure historical entry unrelated to current operational use; users who encounter port 2053 in their network logs are almost always seeing traffic to or from a service running behind Cloudflare’s content delivery network.

Cloudflare proxies HTTPS traffic for customer domains by default on six TCP ports: 443, 2053, 2083, 2087, 2096, and 8443. The first port (443) is the standard HTTPS port. The middle four ports (2053, 2083, 2087, 2096) are conventional alternate ports historically associated with cPanel-style web hosting administration: 2083 is the standard port for cPanel SSL admin, 2087 for WHM SSL, and 2096 for Webmail SSL. Port 2053 is in this range but is not tied to any specific cPanel service; it functions as a generic alternate HTTPS port that customers can use for self-hosted admin panels, internal tools, or other web-based services they want proxied through Cloudflare without using port 443. Port 8443 rounds out the list as a separate well-known alt-HTTPS port.

When a Cloudflare customer puts a domain through Cloudflare’s proxy and runs an HTTPS service on TCP/2053, the traffic goes from end users to Cloudflare’s edge on port 2053, then from Cloudflare’s edge to the customer’s origin server on the same port. Caching is disabled by default for traffic on the alt-port range; only Enterprise customers can enable caching via a cache rule.

The same population of users who encounter port 2053 in their network logs are encountering it because either they themselves configured a service on it behind Cloudflare, or because a service they connect to is doing so. There is no widely-deployed standard service that uses port 2053 by default; Cloudflare’s anycast network simply makes the port reachable for proxied customer services.

Inbound or outbound TCP/2053 outside of an explicit Cloudflare-proxied service configuration is unusual and is generally treated as either a misconfigured admin interface or a deliberate scan.

About TCP Port 2053

The Internet Assigned Numbers Authority (IANA) registers port 2053 for lot105-ds-upd. The IANA description reads: ‘Lot105 DSuper Updates’.

Security Considerations

Our data shows zero IDS rules referencing port 2053. As with the other ports in this dataset that have no rule activity, the absence reflects the rule sets in this dataset rather than a low-risk profile. Port 2053 is uncommon enough as a service port that it has not attracted the broad-pattern detection rules that target ports 80, 443, 8080, and similar.

The dominant security consideration for port 2053 is that any service running on it is, by the nature of the port, a non-default deployment. Operators choose port 2053 (or one of the other Cloudflare alt-HTTPS ports) typically for one of two reasons: to put an admin interface on a port that is not 443 in order to reduce visibility from generic web scanning, or because their hosting environment uses Cloudflare’s proxied-ports list as a way to expose services without renting additional IP addresses. Both reasons assume that port 2053 itself is not a target of widespread automated scanning, which is approximately true today but is not a guarantee against targeted scanning.

Defensive practice is the same as for any internet-exposed HTTPS service: keep TLS implementations current, require strong authentication on any admin interface, use Cloudflare’s WAF and Access products where available, and avoid the assumption that running a service on a non-standard port provides meaningful protection against a determined attacker.

Inbound TCP/2053 from the public internet to a host that has not been intentionally configured as a Cloudflare-proxied origin is unusual and warrants investigation. Outbound TCP/2053 from end-user devices is uncommon and is typically benign when directed at Cloudflare’s anycast IP ranges in the course of normal browsing of a Cloudflare-proxied site that uses the port.

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry.

© 2002-2026 AuditMyPC.com