nicetool.dev logo

Common Ports

Search by port number, service or keyword, or filter by category.

PortProtocolService
20-21TCP

FTPIANA

File Transfer Protocol: 21 for commands, 20 for data in active mode. Unencrypted; prefer SFTP or FTPS.

22TCP

SSH / SFTP / SCPIANA

Secure Shell for encrypted remote login, plus SFTP/SCP file transfer and Git over SSH.

23TCP

TelnetIANA

Old unencrypted remote terminal. Still found on network gear; never expose it to the internet.

25TCP

SMTPIANA

Mail delivery between servers. Often blocked for home connections to stop spam.

53TCP/UDP

DNSIANA

Domain Name System lookups. UDP for normal queries, TCP for large answers and zone transfers.

67-68UDP

DHCPIANA

Automatic IP address assignment: 67 on the server, 68 on the client.

69UDP

TFTPIANA

Trivial File Transfer Protocol, used for network boot (PXE) and device firmware. No authentication.

80TCP

HTTPIANA

Plain-text web traffic. Today mostly used to redirect visitors to HTTPS.

110TCP

POP3IANA

Downloads email from a mailbox and usually deletes it from the server. Unencrypted.

123UDP

NTPIANA

Network Time Protocol keeps server and device clocks in sync.

143TCP

IMAPIANA

Reads email while keeping it on the server, synced across devices. Unencrypted; prefer 993.

161-162UDP

SNMPIANA

Simple Network Management Protocol: 161 for queries, 162 for traps from routers and switches.

389TCP/UDP

LDAPIANA

Directory services such as Active Directory and OpenLDAP for users, groups and logins.

443TCP/UDP

HTTPS (HTTP/3 over UDP)IANA

Encrypted web traffic over TLS. UDP 443 carries HTTP/3 (QUIC).

445TCP

SMBIANA

Windows file and printer sharing (SMB/CIFS). A frequent ransomware target; keep it internal.

465TCP

SMTPSIANA

SMTP submission with implicit TLS, used by mail clients to send email securely.

514UDP

SyslogIANA

Sends system logs to a central log server.

587TCP

SMTP SubmissionIANA

Mail submission from clients to their provider, usually with STARTTLS and login.

636TCP

LDAPSIANA

LDAP over TLS for encrypted directory queries.

853TCP

DNS over TLSIANA

Encrypted DNS over TLS (DoT) for private name lookups.

993TCP

IMAPSIANA

IMAP over TLS: the secure way for mail apps to read email.

995TCP

POP3SIANA

POP3 over TLS for securely downloading email.

1194UDP

OpenVPNIANA

Default port of OpenVPN tunnels (TCP is also possible).

1433TCP

Microsoft SQL ServerIANA

Default port of Microsoft SQL Server.

1521TCP

Oracle DatabaseConvention

Oracle Database listener (TNS). Oracle's official IANA ports for TLS are 2483/2484.

1883TCP

MQTTIANA

MQTT message broker for IoT devices; 8883 is the TLS version.

2049TCP/UDP

NFSIANA

Network File System for mounting remote directories on Linux and Unix.

2375-2376TCP

Docker APIIANA

Docker daemon API: 2375 unencrypted, 2376 with TLS. Exposing 2375 gives full control of the host.

3000TCP

Node.js / Next.js / Rails dev serverConvention

Common default for Node.js, Next.js, Express and Rails development servers.

3306TCP

MySQL / MariaDBIANA

Default port of MySQL and MariaDB.

3389TCP/UDP

RDPIANA

Remote Desktop Protocol for Windows. A favorite brute-force target; put it behind a VPN.

5000TCP

Flask dev serverConvention

Default port of the Flask development server; also used by macOS AirPlay Receiver.

5173TCP

Vite dev serverConvention

Default port of the Vite development server.

5432TCP

PostgreSQLIANA

Default port of PostgreSQL.

5672TCP

AMQP (RabbitMQ)IANA

AMQP protocol used by RabbitMQ and other message brokers.

5900TCP

VNCIANA

VNC remote desktop (display :0; display :1 uses 5901).

6379TCP

RedisConvention

Default port of Redis and Valkey. Has no password by default; never expose it publicly.

6443TCP

Kubernetes API serverConvention

Kubernetes API server, used by kubectl and cluster components.

8000TCP

Django / Python http.serverConvention

Default for Django runserver and python -m http.server.

8080TCP

HTTP alternate / proxyIANA

Alternative HTTP port for proxies, Tomcat and app servers running without root.

8443TCP

HTTPS alternateConvention

Common alternative HTTPS port for admin panels and app servers.

9092TCP

Apache KafkaConvention

Apache Kafka brokers for event streaming.

9200TCP

Elasticsearch / OpenSearchConvention

Elasticsearch and OpenSearch REST API (9300 for node-to-node traffic).

11211TCP/UDP

MemcachedIANA

Memcached in-memory cache. Disable UDP; open servers were abused for DDoS amplification.

27017TCP

MongoDBConvention

Default port of MongoDB.

51820UDP

WireGuardConvention

Default port of WireGuard VPN tunnels.

What is a network port?

An IP address identifies a machine, and a port number (0 to 65535) identifies a service on that machine, so one server can run a web server on port 443 and SSH on port 22 at the same time. Ports 0 to 1023 are "well-known" and normally need administrator rights to bind, 1024 to 49151 are registered ports, and 49152 and above are dynamic ports used for outgoing connections. IANA keeps the official registry, but many popular tools such as dev servers, Redis or Kafka use ports by convention. Knowing them is essential for configuring firewalls, cloud security groups, Docker port mappings and for reading netstat or ss output.

Features

  • • Around 50 ports developers and sysadmins meet every day
  • • Protocol (TCP, UDP or both) and a plain explanation of each service
  • • Marks which ports are IANA-assigned and which are just conventions
  • • Instant search by number, service or keyword, plus category filters
  • • Covers web, SSH and VPN, email, databases, message brokers and dev servers

Simple reference

The table is part of the page and the search runs in your browser. Nothing is scanned: this is a reference, not a port scanner.

Reference only, no scanning.

How to use the Common Ports

  1. 1

    Type a port number such as 5432, a service name such as "redis" or a word such as "vpn" in the search box.

  2. 2

    Use the category chips to list, for example, all database ports before writing firewall rules.

  3. 3

    Check the protocol column: DNS, NTP, DHCP and WireGuard need UDP rules, not only TCP.

  4. 4

    Look at the badge: IANA ports are official assignments, Convention ports are popular defaults that you can and often should change.

Practical examples

Opening a cloud firewall

For a typical web server, allow 443 (and 80 for redirects) from anywhere, 22 only from your office IP, and keep database ports such as 3306 or 5432 closed to the internet.

Docker port mappings

docker run -p 8080:80 nginx publishes the container port 80 on host port 8080. Use the list to pick host ports that do not clash with services already running.

Reading netstat or ss

When ss -tlnp shows something listening on 6379 or 27017, you know a Redis or MongoDB instance is running and should check it is not exposed publicly.

Email client setup

Use 587 with STARTTLS or 465 with implicit TLS to send mail, 993 for IMAP over TLS and 995 for POP3 over TLS. Port 25 is for server-to-server delivery and is often blocked for home users.

Frequently asked questions

What is the difference between TCP and UDP ports?+

They are separate number spaces: TCP port 53 and UDP port 53 are different sockets. TCP is connection-oriented and reliable, UDP is faster with no handshake, which suits DNS queries, VoIP, games and VPNs.

Which ports should never be open to the internet?+

Databases (3306, 5432, 6379, 27017, 9200), Docker API (2375), SMB (445), RDP (3389) and Telnet (23) are common targets. Keep them on a private network or behind a VPN.

Does changing the SSH port improve security?+

It cuts noise from automated scans but is not real protection. Use key-based authentication, disable password login and consider allow-listing IPs or fail2ban.

Why do dev servers use 3000, 5173 or 8000?+

They are above 1024, so no admin rights are needed, and each framework picked its own default. Any free port works, change it if two projects clash.