Port Number Reference

A reference list of common TCP/UDP port numbers and what uses them — FTP, SSH, HTTP, HTTPS, MySQL, Redis, and more. Useful for configuring firewall rules and troubleshooting "connection refused" errors, with a live search filter.

Well-known 0–1023 Registered 1024–49151 Dynamic / private 49152–65535
Port Number Table
Port Protocol TCP/UDP Range Used for
20 FTP (Data) TCP Well-known Used for FTP data transfer (active mode). Increasingly replaced by SFTP and FTPS.
21 FTP (Control) TCP Well-known Used for the FTP control connection, which carries commands and responses.
22 SSH TCP Well-known Used for encrypted remote login via SSH, and file transfer via SCP/SFTP.
23 Telnet TCP Well-known Used for unencrypted remote login via Telnet. SSH is recommended instead due to eavesdropping risk.
25 SMTP TCP Well-known Used for SMTP mail relay between mail servers.
53 DNS TCP/UDP Well-known Used for DNS name resolution. Ordinary queries use UDP; zone transfers and large responses use TCP.
67 DHCP (Server) UDP Well-known Used by a DHCP server to hand out IP addresses to clients.
68 DHCP (Client) UDP Well-known Used by a DHCP client to request an IP address assignment.
69 TFTP UDP Well-known Used for unauthenticated, lightweight file transfer via TFTP, commonly for firmware updates on network devices.
80 HTTP TCP Well-known Used for unencrypted web page delivery via HTTP.
110 POP3 TCP Well-known Used by mail clients to download email via POP3.
123 NTP UDP Well-known Used for time synchronization between computers via NTP.
143 IMAP TCP Well-known Used for managing and syncing mail across multiple devices via IMAP.
161 SNMP UDP Well-known Used for monitoring and querying network device status via SNMP.
162 SNMP Trap UDP Well-known Used to receive SNMP traps, unsolicited notifications sent by devices.
194 IRC TCP Well-known Used for real-time chat via IRC.
389 LDAP TCP Well-known Used for querying directory services (user and organization data) via LDAP.
443 HTTPS TCP Well-known Used for secure web page delivery via HTTPS (HTTP over TLS).
445 SMB TCP Well-known Used for Windows file and printer sharing via SMB.
465 SMTPS TCP Well-known Used for encrypted mail submission via SMTPS (SMTP over TLS).
587 SMTP Submission TCP Well-known The standard port mail clients use to submit outgoing mail to a mail server.
636 LDAPS TCP Well-known Used for encrypted directory service communication via LDAPS (LDAP over TLS).
993 IMAPS TCP Well-known Used for encrypted mail sync via IMAPS (IMAP over TLS).
995 POP3S TCP Well-known Used for encrypted mail retrieval via POP3S (POP3 over TLS).
1433 MSSQL TCP Registered Used for Microsoft SQL Server database connections.
3306 MySQL TCP Registered Used for MySQL/MariaDB database connections.
3389 RDP TCP Registered Used for Windows Remote Desktop connections via RDP.
5432 PostgreSQL TCP Registered Used for PostgreSQL database connections.
5900 VNC TCP Registered Used for remote desktop screen sharing via VNC.
6379 Redis TCP Registered Used for connections to the Redis in-memory data store.
8080 HTTP (Alt) TCP Registered A common alternate HTTP port, often used by proxy servers and development web servers.
8443 HTTPS (Alt) TCP Registered A common alternate HTTPS port, often used by application servers such as Tomcat.
9200 Elasticsearch TCP Registered Used for connections to the Elasticsearch REST API.
27017 MongoDB TCP Registered Used for MongoDB database connections.

What Are Port Numbers? Well-Known, Registered, and Dynamic Ranges Explained

A port number is a 16-bit identifier (0–65535) that distinguishes between the many network services running on a single computer. While an IP address identifies which computer you're talking to, a port number identifies which application on that computer the traffic is meant for. On the very same server, port 80 might be handled by a web server and port 22 by an SSH daemon — the port number is what routes incoming traffic to the correct service.

IANA (the Internet Assigned Numbers Authority) divides the full port range into three bands. Ports 0–1023, the "well-known ports," are reserved for standard services like HTTP and SSH. Ports 1024–49151, the "registered ports," can be requested and registered by companies or projects for their own protocols. Ports 49152–65535 are "dynamic (ephemeral) ports," freely assigned by the operating system as temporary source ports for outgoing connections. This reference lists the most common port numbers together with their protocol, TCP/UDP transport, range classification, and typical use — with a live search filter — so you can quickly look things up while writing firewall rules or debugging a connection problem.

How to Use the Port Number Reference

  1. Type the port number or service name you're looking for Enter a port number (e.g. 443) or a protocol name (e.g. SSH, MySQL) in the search box, and only matching rows will remain visible.
  2. Narrow by TCP or UDP Typing "TCP" or "UDP" filters by transport-layer type as well — useful since the same number can carry different meanings for each.
  3. Read the description column Each row's description explains exactly what service normally uses that port, giving you a citable reason before writing a firewall rule.
  4. Check the range classification See whether a port falls under well-known, registered, or dynamic, and use that to decide which range is appropriate for your own application.

Tips for getting more out of it

  • When writing firewall rules, open only the ports you actually need and default-deny everything else — the security fundamentals haven't changed in decades.
  • If you see "connection refused," first check whether the service is actually listening on that port with tools like netstat -an or ss -tlnp.
  • Well-known ports (0–1023) like 80 and 443 usually require administrator privileges to bind on most operating systems, which is why non-privileged apps often use alternates like 8080.
  • The same service often uses a different port for its plaintext and encrypted variants (e.g. 80/HTTP vs 443/HTTPS, 21/FTP vs 990/FTPS) — don't mix them up.
  • The port numbers in this reference apply directly to security group rules in cloud environments like AWS, GCP, and Azure.

Common Use Cases for the Port Number Reference

Writing firewall rules

When deciding which ports to allow in iptables, ufw, or a cloud security group, use this list to confirm the standard number and purpose before opening it.

Diagnosing "connection refused" errors

When a connection fails, check what service the target port is actually meant for to confirm you're even trying to reach the right one.

Security audits and open-port inventories

When auditing which ports a server exposes, cross-reference this list to spot anything open that shouldn't be.

Designing Docker or cloud port mappings

When exposing container or cloud instance ports, use this reference to pick numbers that won't collide with well-known services, or to choose a familiar alternate like 8080 or 8443.

Port Number Glossary

Well-known port
A port in the 0–1023 range, reserved by IANA exclusively for widely used standard services such as HTTP and SSH.
TCP (Transmission Control Protocol)
A reliability-focused transport protocol that confirms delivery and retransmits lost data, used where accuracy matters, such as loading web pages or transferring files.
UDP (User Datagram Protocol)
A lightweight transport protocol that skips delivery confirmation, used where speed matters more than guaranteed delivery, such as DNS lookups or online gaming.
Port scan
The act of probing a target computer's ports one by one from the outside to see which are open, used both by attackers doing reconnaissance and by defenders running vulnerability checks.
Firewall
A network defense mechanism that allows traffic only to specific ports or IP addresses and blocks everything else.
Ephemeral port (dynamic port)
A temporary source port the operating system automatically assigns to a client for each connection, drawn from the 49152–65535 range.
Socket
The combination of an IP address and a port number, which together uniquely identify one endpoint of a network connection.

Frequently Asked Questions

An IP address identifies the "building" (the computer) you're communicating with, while a port number identifies the specific "room" (application or service) inside that building. On the same server, port 80 might route to a web server and port 22 to an SSH server — the port number determines which service receives the traffic.

TCP is a reliability-focused protocol that confirms delivery and retransmits lost data, used for things like loading web pages and transferring files. UDP is a lightweight protocol that skips acknowledgments, used where speed matters more than guaranteed delivery, such as DNS lookups, online gaming, and video streaming.

First confirm the service (process) is actually running and listening on that port. If it is, check whether a firewall (iptables, ufw, a cloud security group, etc.) is blocking traffic to that port.

New sites should generally run exclusively on port 443 (HTTPS). Keeping port 80 (HTTP) around only to redirect to 443 is considered current best practice.

It's common to pick a number in the 1024–49151 "registered ports" range, ideally one that doesn't collide with other common services (e.g. 8080 or a number in the 3000s). Avoid the 0–1023 "well-known ports," which are reserved for established standard services.
Tool-kun

Side Note — Why do port numbers only go up to 65535?

Port numbers are limited to the 0–65535 range because the port number field in the TCP/UDP header is defined as 16 bits (2 bytes). Two to the power of 16 is 65536, so excluding port 0, the usable range is 1 through 65535. This design was fixed when TCP/IP was standardized in the early 1980s and has never changed since.

IANA (the Internet Assigned Numbers Authority) divides all ports into three ranges. Ports 0–1023, the "well-known ports," are reserved for widely used services like HTTP and SSH. Ports 1024–49151, the "registered ports," can be requested and registered by companies or projects. Ports 49152–65535 are "dynamic/private ports," freely used by clients as temporary source ports.

Even famous ports like 80 (HTTP) and 443 (HTTPS) weren't assigned their current purpose from the start. Port 443 was allocated for HTTPS in 1994, when Netscape requested it from IANA while developing SSL (Secure Sockets Layer).

To reduce the risk of port-scanning attacks, some production servers change the default SSH port (22) away from its standard value, a technique sometimes called "port knocking." This is security through obscurity, though, and is never a substitute for fundamentals like strong authentication and keeping software patched.