Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FTP means File Transfer Protocol. It is a client-server protocol for listing, uploading, downloading, renaming and deleting files on a remote system. Traditional FTP uses a control connection (normally TCP port 21) plus a separate data connection. Because plain FTP does not encrypt passwords or file contents, use SFTP, FTPS or HTTPS whenever confidentiality matters.

What “FTP” means

FTP can mean the protocol, an FTP server, an FTP account, a client application or an FTP connection. An FTP client is the program or command-line tool you use; an FTP server stores files and accepts commands. “Secure FTP” is ambiguous: FTPS is FTP protected by TLS, while SFTP is a separate file-transfer protocol carried over SSH.

Common uses

  • Uploading website files to hosting
  • Moving files between business systems
  • Publishing software or firmware
  • Exchanging files with agencies, vendors or clients
  • Accessing legacy public archives
  • Automating scheduled transfers
  • Managing files on a server or NAS

FTP is less suitable for collaborative editing, modern application APIs, browser-first public sharing and sensitive data sent without encryption.

How FTP works

RFC 959, published in October 1985, defines FTP’s basic model and its separate control and data processes: RFC 959.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
FTP client
   |
   |-- Control connection: normally TCP 21
   |
   |-- Data connection: active or passive
   |
FTP server

A typical session

  1. The client resolves the server name and opens the control connection.
  2. The server sends a greeting.
  3. The client submits a username and password, unless anonymous access is enabled.
  4. The client selects active or passive mode.
  5. It requests a listing or file operation.
  6. A data connection carries the listing or file, then closes.
  7. The control connection remains available for more commands until QUIT.

Connecting successfully to port 21 proves only that the control path works. Directory listings and transfers can still fail when the data path, firewall or NAT configuration is wrong.

Active versus passive FTP

Active mode

The client listens on a port and tells the server which port to use; the server then initiates the data connection back to the client, traditionally from server port 20. Client firewalls, NAT, VPNs and corporate networks often block that incoming connection.

Passive mode

The client asks the server for passive mode. The server supplies a data port and the client initiates the connection to it. This is usually more reliable behind NAT and firewalls, but it does not encrypt traffic or make authentication safer. Start with passive mode unless the administrator specifies otherwise.

A passive FTP server normally needs a defined TCP port range, firewall rules for that range, correct public-address advertisement and any required NAT forwarding. IIS documents these settings at its FTP firewall-support guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FTP ports

Port Typical use Qualification
TCP 21 FTP control connection Traditional default; deployments can change it
TCP 20 Active-mode data Traditional server-side arrangement, not passive FTP
Negotiated server ports Passive FTP or FTPS data Must be allowed through the server firewall and NAT
TCP 990 Implicit FTPS Common legacy convention, not the normal explicit-TLS upgrade

Microsoft describes explicit FTPS beginning on port 21 and legacy implicit FTPS on port 990 in its IIS SSL configuration and MS-FTPS documentation.

Commands and transfer modes

Command Purpose
USER, PASS Authenticate
PWD, CWD, CDUP Show, change or move up a remote directory
LIST, NLST Request directory listings
RETR, STOR, STOU, APPE Download, upload, uniquely upload or append
DELE, MKD, RMD Delete, create or remove
RNFR/RNTO Rename
TYPE I, TYPE A Binary or ASCII transfer mode
PASV, EPSV, PORT, EPRT Passive or active data setup
SIZE, MDTM, REST Size, modification time or restart point
QUIT End the session

Use binary mode for images, archives, videos, executables, PDFs, databases and other non-text files. ASCII mode is for text where line-ending or character-set conversion is intended; using it for binary data can corrupt the file. RFC 959 defines the core commands and modes, while extensions such as size, modification-time and restart operations are described in RFC 3659.

FTP addresses and authentication

An address may look like ftp://example.com/. It consists of a hostname, optional port, credentials and a remote path. Do not put passwords in URLs such as ftp://username:[email protected]/path/; URLs can leak into browser history, shell history, logs, bookmarks and screenshots.

Accounts may use usernames and passwords, per-user directories, jailed or chrooted paths, IP allowlists or anonymous access. Anonymous FTP is a public-access configuration, not a security feature; Microsoft describes it at IIS FTP security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use a separate, minimum-permission account.
  • Never reuse an administrator, email or primary website password.
  • Disable anonymous write access and prefer read-only public access.
  • Rotate credentials, review logs and restrict directory access.

Is FTP secure?

Plain FTP generally exposes usernames, passwords, commands, filenames, directory names and file contents to anyone able to observe the connection. Do not use it for confidential data or credentials on an untrusted network.

FTPS

FTPS combines FTP security extensions with TLS. Explicit FTPS starts on the FTP service, usually port 21, and upgrades to TLS. Implicit FTPS expects TLS immediately, commonly on legacy port 990. RFC 2228 and RFC 4217 describe the security extensions and TLS method: RFC 2228 and RFC 4217. Security still depends on certificate validation, TLS policy and preventing fallback to plaintext.

SFTP

SFTP is a separate SSH-based protocol, normally on TCP port 22. It commonly uses one SSH connection and supports passwords or SSH keys; an SFTP client cannot connect to an FTP-only service.

FTP, FTPS and SFTP compared

Feature FTP FTPS SFTP
Underlying protocol FTP FTP plus TLS SSH
Typical port 21 21 explicit; 990 implicit 22
Encryption None TLS SSH
Data connections Separate Separate negotiated Usually one SSH connection
Firewall complexity Moderate to high Moderate to high Usually simpler, though policies still matter
Best fit Legacy or intentionally public compatibility FTP-required partners needing TLS Secure administration and server-to-server transfer

How to connect with a GUI client

You need the hostname, protocol, port, username, password or key, encryption requirement and (if supplied) an initial remote directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Install a client from its official vendor site.
  2. Create a new connection or site entry.
  3. Enter the hostname and select FTP, explicit FTPS, implicit FTPS or SFTP as instructed.
  4. Enter the port and credentials; configure an SSH key when required.
  5. Choose passive mode for ordinary FTP or FTPS unless told otherwise.
  6. On the first secure connection, verify the TLS certificate or SSH host key with the administrator.
  7. Browse the remote directory, transfer files and confirm the queue reports success.
  8. Check the remote size and, where possible, a checksum.

FileZilla, WinSCP, Cyberduck and OpenSSH are among clients documented by AWS for relevant Transfer Family endpoints: AWS client guidance. Menu labels vary by application and version.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Command-line examples

ftp ftp.example.com

binary
pwd
ls
cd public_html
put index.html
get report.pdf
bye
curl --ftp-ssl --user 'USERNAME:PASSWORD' 
  --output report.pdf 
  'ftp://ftp.example.com/report.pdf'

Prefer an interactive prompt, environment variable or secret manager over putting a password in a command or script. For SFTP:

sftp [email protected]

pwd
lpwd
ls
cd remote-directory
lcd local-directory
put local-file.zip
get remote-file.pdf
bye

The availability and behavior of ftp, curl and sftp depend on the operating system and installed packages.

Troubleshooting FTP connections

Connection timed out

  • Confirm the hostname and protocol port.
  • Test DNS resolution and whether TCP 21 or 22 is reachable.
  • Check VPN, corporate-firewall and server status.
  • Try the provider’s secure protocol or another permitted network.

“530 Login incorrect”

  • Verify credentials, protocol, account status and required host.
  • Remove copied spaces and check shell/client handling of special characters.
  • Ask the administrator whether the account is locked, expired or directory-restricted.

“425 Can’t open data connection”

  1. Switch the client to passive mode.
  2. Confirm the server’s passive range is open and forwarded through NAT.
  3. Ensure the server advertises its public address correctly.
  4. For FTPS, check that the firewall handles encrypted FTP; SFTP may avoid this data-channel issue.

Microsoft notes passive-range requirements and that encrypted FTP can confuse some legacy FTP-aware firewalls: firewall support and MS-FTPS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Listings work but uploads fail

Check write permission, remote directory, filename rules, quota, disk space and server logs. A server can permit downloads while denying uploads.

The transferred file is corrupt

Use binary mode, re-transfer, compare sizes and checksums, and test with a known-good client. ASCII conversion or an incomplete transfer is a common cause.

Certificate not trusted

Verify the certificate with the service owner. Check expiry, hostname and trust chain, and do not blindly accept an unexpected certificate or a possible middlebox interception.

Which transfer method should you choose?

Situation Recommended starting point
Legacy FTP requirement FTPS if supported; otherwise isolate and protect plain FTP
Secure server-to-server transfer SFTP
Partner requires FTP commands FTPS
Public download or browser sharing HTTPS
Scalable cloud workflow Object-storage API or managed transfer gateway
Many external partners and auditing Managed file-transfer service
Occasional personal transfer HTTPS sharing or a free GUI client

HTTPS is often easiest for browser access and public links. Object storage suits APIs, lifecycle rules, versioning and CDN delivery. Managed services add controlled access, auditing and workflows but charge for endpoints, transfers and related infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clients and managed services

  • FileZilla Client: free FTP, FTPS and SFTP desktop access; FileZilla Pro adds cloud-storage connectivity. See the official download, Pro, pricing and CLI. The Pro page showed €12.99 per year for a single-device plan and the CLI page €9.99 when checked August 16, 2026; prices and taxes can change.
  • WinSCP: Windows client for SFTP, SCP, FTP, FTPS and automation: official download.
  • Cyberduck: macOS and Windows GUI for FTP, SFTP and cloud connections: official download.
  • OpenSSH sftp: a strong choice for macOS/Linux administration, keys and automation: OpenSSH.
  • AWS Transfer Family: managed FTP, FTPS, SFTP, AS2 and browser transfers into AWS storage. Its US East pricing example showed $0.30 per endpoint hour and $0.04 per GB for SFTP data; actual costs vary by region, protocol, storage, bandwidth and configuration. See the overview and pricing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.