iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes, but not with an MQTT client alone. An ESP32 can connect to an MQTT broker over TCP and exchange messages; tunneling an arbitrary TCP connection through those messages requires additional software on the ESP32 and a gateway at the other end. Whether it is practical depends on the traffic, network, and security requirements—not simply on the board’s price.
What “MQTT over TCP” means—and what it doesn’t
TCP is the network transport used to carry data between two endpoints. MQTT is a messaging protocol that can use TCP to connect a client to a broker. In the usual ESP32 example, the board connects to a broker, publishes messages, and receives messages it has subscribed to. That is not the same as forwarding a different program’s TCP byte stream through MQTT.
Espressif describes ESP-MQTT as an MQTT protocol client. Its MQTT TCP example, identified as an ESP-IDF v5.5.0 example, demonstrates connecting an ESP32 client to a broker, managing connection status, and sending and receiving messages. It is a useful starting point for MQTT messaging, not a ready-made transparent TCP proxy. The example also requires network connectivity provisioned through Wi-Fi, Ethernet, or Thread; an ESP32 board by itself is not a broker connection.
- MQTT client: Your application publishes or subscribes to defined messages.
- TCP proxy over MQTT: Software accepts or creates a separate TCP connection, packages its bytes into MQTT messages, and reconstructs the byte stream at a gateway.
So, an ESP32 connecting to a broker over TCP does not mean that any TCP application can automatically use the broker as a tunnel.
#1 Best Overall
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Support LWIP protocol, Freertos
- SupportThree Modes: AP, STA, and AP+STA
- Ultra-Low power consumption, Compatible with Arduino IDE
- ESP32 is a safe, reliable, and scalable to a variety of applications
How a TCP-over-MQTT design would work
A typical layout has a local TCP client talking to the ESP32 and a gateway process talking to the broker. The gateway then opens a TCP connection to the destination service. Replies travel back through the gateway and broker to the ESP32, which writes them to the local TCP connection.
Local TCP application
↕ TCP
ESP32 bridge ↔ MQTT broker ↔ remote gateway ↔ TCP destination
The broker carries messages between MQTT clients; it does not itself turn a topic into a TCP connection. You must implement the gateway and decide which destinations it is allowed to reach. If the ESP32 is instead meant to open the destination connection, the design changes, but the bytes still need to be framed and reassembled over MQTT.
Rank #2
- Dual-Core Performance Up to 240 MHz: Run sensor processing, wireless communication, automation logic and connected-device tasks on a 32-bit dual-core ESP32 platform designed for responsive embedded and IoT projects
- Built-in Wi-Fi and Bluetooth 4.2: Connect to 2.4 GHz Wi-Fi networks or use Bluetooth Classic and BLE for wireless sensors, smart devices, remote controls, home automation and other connected projects
- Flexible Power-Saving Modes: ESP32 power-management features support dynamic clock scaling and low-power operating modes, helping developers reduce energy use in compatible sensing, monitoring and connected-device applications, suitable for battery-powered Internet of Things (IoT) devices.
- USB-C Programming with CP2102: Connect through USB-C for power, sketch uploads and serial monitoring, while GPIO, UART, SPI and I2C interfaces support sensors, displays, motor drivers and other modules (USB-C cable not included)
- Over-the-Air Update Support: Configure OTA functionality through a compatible ESP-32 software framework to update deployed firmware over Wi-Fi without reconnecting the board by USB for every revision
What the tunnel software must add
Frame the byte stream into messages
TCP presents an ordered byte stream, not a sequence of application messages. A bridge must split that stream into MQTT payloads and make it possible for the receiver to identify which connection each payload belongs to and where its bytes fit. A message envelope might include a connection ID, direction, sequence offset, payload length, and a control type such as open, data, close, or error. Those fields are design choices, not an ESP-MQTT feature.
Keep payloads within the broker’s and client library’s configured limits, and account for envelope overhead. Do not assume a single TCP write becomes one MQTT message or that an entire TCP session fits in one payload.
Rank #3
- Powerful ESP-32 Board: Unlock the world of Internet of Things (IoT) and advanced electronics with the heart of this kit: the ESP-32 board. It features a powerful dual-core processor, integrated Wi-Fi and Bluetooth 4.2, making it perfect for building connected, smart devices that communicate with your phone or the cloud. It's fully compatible with the Arduino IDE for easy programming.
- Super Starter Kit: This kit contains over 35 different modules and electronic components, including sensors, displays, motors, and input devices. From LEDs and buttons to an OLED screen, servo motor, and keypad, you have everything needed to explore a vast range of projects in one box.
- Step by Step Online Tutorial: Jump right in with our detailed, beginner-friendly tutorial. Access 30+ projects with complete code, clear circuit diagrams, and step-by-step instructions. Learn the fundamentals of electronics, coding, and how to utilize the ESP-32's unique capabilities without any prior experience.
- Hands-on Learning for All Skill Levels: Perfect for students, makers, engineers, and hobbyists. Start with basic circuits and coding, then progress to intermediate and advanced IoT applications. Build practical projects like weather stations, smart home controllers, remote-controlled devices, and interactive gadgets. The skills you learn are the foundation for real-world innovation.
- Quality & Great Support: Elegoo is committed to quality. We provide a clear, detailed tutorial guide, refined code, and a well-organized component kit. All modules are carefully selected for reliability and ease of use. Our dedicated technical support team and active online community are ready to help you succeed in your learning journey.
Manage ordering, flow control, and buffers
A TCP sender can produce data faster than a small device, broker, or gateway can forward it. The bridge needs bounded buffers and a policy for slowing or pausing the local TCP sender when MQTT delivery falls behind. Otherwise memory use can grow until the device fails or data is dropped.
MQTT QoS controls delivery behavior for MQTT messages; it does not provide TCP stream semantics to your proxy. In particular, the tunnel still needs a way to associate bytes with a connection, handle duplicate or delayed data where relevant, and decide when the receiving side has accepted enough data to let the sender continue. Application-level sequence numbers and acknowledgments may be appropriate, depending on the reliability model.
Rank #4
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Support LWIP protocol, Freertos;ESP32 is a safe, reliable, and scalable to a variety of applications
- SupportThree Modes: AP, STA, and AP+STA
- Ultra-Low power consumption, Compatible with Arduino IDE
- 1PCS 30Pin ESP32 Development Board 2.4GHz WiFi Dual Cores Microcontroller Integrated with Antenna RF Low Noise Amplifiers Filters
Handle connection identity and reconnects
Each proxied TCP session needs an identity so that data and close events reach the right socket. Define what happens if the ESP32 disconnects, the gateway restarts, or the broker connection returns after an interruption. Decide whether an interrupted TCP session is aborted or resumed; resuming safely requires session state and byte-position tracking at both ends. MQTT reconnection alone does not restore an arbitrary TCP connection.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Restrict access and protect the payload
Use broker authentication and topic-level access controls so clients cannot subscribe to or publish other users’ tunnel traffic. The gateway should also enforce an allowlist or other destination policy rather than accepting arbitrary host-and-port requests from untrusted MQTT messages. TLS for the ESP32-to-broker connection protects that network leg when configured and verified correctly. If the broker or another intermediary should not be able to read tunnel contents, add end-to-end encryption between the bridge and gateway as well.
Best Value
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Ultra-Low power consumption, works perfectly with the Arduino IDE
- Support LWIP protocol, Freertos
- SupportThree Modes: AP, STA, and AP+STA
- ESP32 is a safe, reliable, and scalable to a variety of applications
Choose an MQTT transport for the deployment
Espressif documents MQTT client transports including TCP, TLS, WebSocket, and secure WebSocket across its documentation. The right choice depends on what the network permits and what security is required. Verify the configuration options against the ESP-MQTT component version you actually build with.
| Transport | When to consider it | Important qualification |
|---|---|---|
| MQTT over TCP | The broker is reachable directly and the deployment’s security policy permits a non-TLS connection. | It does not encrypt the connection. Authentication and network protections still matter. |
| MQTT over TLS | The broker is reachable and the connection should be protected with TLS. | Configure certificate verification; do not treat encryption without peer verification as secure broker identity. |
| MQTT over WebSocket | The network or broker endpoint is set up to accept MQTT through WebSocket. | It is a different transport configuration, not a TCP tunnel feature. |
| MQTT over secure WebSocket | The deployment requires WebSocket transport protected by TLS. | Confirm endpoint support and certificate verification for the selected client component. |
An older ESP-IDF v4.4 guide gives example default ports of 1883 for TCP, 8883 for TLS, 80 for WebSocket, and 443 for secure WebSocket. These are version-specific documentation examples, not universal requirements; a broker can be configured differently.
Start with ESP-MQTT, then build the bridge separately
- Choose and pin the software version. Espressif’s current stable ESP-MQTT documentation says the component moved out of ESP-IDF beginning with v6.0 and directs users to add the
espressif/mqttcomponent. The documented TCP example identifies ESP-IDF v5.5.0. Do not assume setup instructions for one version apply unchanged to another. - Provision the network and validate messaging. First establish the board’s Wi-Fi, Ethernet, or Thread connectivity and run a basic MQTT publish/subscribe path against a broker you control. Confirm connection-state handling and the selected transport before adding proxy logic.
- Implement a separate stream protocol. Add local TCP socket handling, message framing, per-connection identity, bounded buffers, backpressure, and close/error behavior. Build the corresponding gateway that reassembles messages and manages destination sockets.
- Test failure cases before relying on it. Test broker outages, reconnects, slow receivers, oversized payloads, duplicate or delayed messages, multiple sessions, and gateway restarts. Measure throughput and latency on the actual board, broker, network, and workload; the cited Espressif examples do not establish performance figures for a generic TCP-over-MQTT tunnel.
When this approach is—and isn’t—a good fit
MQTT is a natural fit when the application already exchanges compact, structured messages with a broker. A byte-stream tunnel may be useful when both ends are under your control and MQTT is the permitted route between them, but it adds framing, buffering, session management, and security work that a normal MQTT client does not provide.
Recommended Free Tools
If an application requires transparent forwarding of arbitrary TCP traffic, a purpose-built IP or TCP tunneling design may be more suitable. If the need is only to report sensor readings or issue device commands, use MQTT messages directly rather than wrapping a TCP connection inside them. In either case, select an ESP32 development board based on the exact variant, available pins, USB interface, power requirements, and board-revision documentation; the documentation cited here does not establish a particular retail model or current price.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

