| 20-21 | TCP | FTPIANA File Transfer Protocol: 21 for commands, 20 for data in active mode. Unencrypted; prefer SFTP or FTPS. | File Transfer Protocol: 21 for commands, 20 for data in active mode. Unencrypted; prefer SFTP or FTPS. |
| 22 | TCP | SSH / SFTP / SCPIANA Secure Shell for encrypted remote login, plus SFTP/SCP file transfer and Git over SSH. | Secure Shell for encrypted remote login, plus SFTP/SCP file transfer and Git over SSH. |
| 23 | TCP | TelnetIANA Old unencrypted remote terminal. Still found on network gear; never expose it to the internet. | Old unencrypted remote terminal. Still found on network gear; never expose it to the internet. |
| 25 | TCP | SMTPIANA Mail delivery between servers. Often blocked for home connections to stop spam. | Mail delivery between servers. Often blocked for home connections to stop spam. |
| 53 | TCP/UDP | DNSIANA Domain Name System lookups. UDP for normal queries, TCP for large answers and zone transfers. | Domain Name System lookups. UDP for normal queries, TCP for large answers and zone transfers. |
| 67-68 | UDP | DHCPIANA Automatic IP address assignment: 67 on the server, 68 on the client. | Automatic IP address assignment: 67 on the server, 68 on the client. |
| 69 | UDP | TFTPIANA Trivial File Transfer Protocol, used for network boot (PXE) and device firmware. No authentication. | Trivial File Transfer Protocol, used for network boot (PXE) and device firmware. No authentication. |
| 80 | TCP | HTTPIANA Plain-text web traffic. Today mostly used to redirect visitors to HTTPS. | Plain-text web traffic. Today mostly used to redirect visitors to HTTPS. |
| 110 | TCP | POP3IANA Downloads email from a mailbox and usually deletes it from the server. Unencrypted. | Downloads email from a mailbox and usually deletes it from the server. Unencrypted. |
| 123 | UDP | NTPIANA Network Time Protocol keeps server and device clocks in sync. | Network Time Protocol keeps server and device clocks in sync. |
| 143 | TCP | IMAPIANA Reads email while keeping it on the server, synced across devices. Unencrypted; prefer 993. | Reads email while keeping it on the server, synced across devices. Unencrypted; prefer 993. |
| 161-162 | UDP | SNMPIANA Simple Network Management Protocol: 161 for queries, 162 for traps from routers and switches. | Simple Network Management Protocol: 161 for queries, 162 for traps from routers and switches. |
| 389 | TCP/UDP | LDAPIANA Directory services such as Active Directory and OpenLDAP for users, groups and logins. | Directory services such as Active Directory and OpenLDAP for users, groups and logins. |
| 443 | TCP/UDP | HTTPS (HTTP/3 over UDP)IANA Encrypted web traffic over TLS. UDP 443 carries HTTP/3 (QUIC). | Encrypted web traffic over TLS. UDP 443 carries HTTP/3 (QUIC). |
| 445 | TCP | SMBIANA Windows file and printer sharing (SMB/CIFS). A frequent ransomware target; keep it internal. | Windows file and printer sharing (SMB/CIFS). A frequent ransomware target; keep it internal. |
| 465 | TCP | SMTPSIANA SMTP submission with implicit TLS, used by mail clients to send email securely. | SMTP submission with implicit TLS, used by mail clients to send email securely. |
| 514 | UDP | SyslogIANA Sends system logs to a central log server. | Sends system logs to a central log server. |
| 587 | TCP | SMTP SubmissionIANA Mail submission from clients to their provider, usually with STARTTLS and login. | Mail submission from clients to their provider, usually with STARTTLS and login. |
| 636 | TCP | LDAPSIANA LDAP over TLS for encrypted directory queries. | LDAP over TLS for encrypted directory queries. |
| 853 | TCP | DNS over TLSIANA Encrypted DNS over TLS (DoT) for private name lookups. | Encrypted DNS over TLS (DoT) for private name lookups. |
| 993 | TCP | IMAPSIANA IMAP over TLS: the secure way for mail apps to read email. | IMAP over TLS: the secure way for mail apps to read email. |
| 995 | TCP | POP3SIANA POP3 over TLS for securely downloading email. | POP3 over TLS for securely downloading email. |
| 1194 | UDP | OpenVPNIANA Default port of OpenVPN tunnels (TCP is also possible). | Default port of OpenVPN tunnels (TCP is also possible). |
| 1433 | TCP | Microsoft SQL ServerIANA Default port of Microsoft SQL Server. | Default port of Microsoft SQL Server. |
| 1521 | TCP | Oracle DatabaseConvention Oracle Database listener (TNS). Oracle's official IANA ports for TLS are 2483/2484. | Oracle Database listener (TNS). Oracle's official IANA ports for TLS are 2483/2484. |
| 1883 | TCP | MQTTIANA MQTT message broker for IoT devices; 8883 is the TLS version. | MQTT message broker for IoT devices; 8883 is the TLS version. |
| 2049 | TCP/UDP | NFSIANA Network File System for mounting remote directories on Linux and Unix. | Network File System for mounting remote directories on Linux and Unix. |
| 2375-2376 | TCP | Docker APIIANA Docker daemon API: 2375 unencrypted, 2376 with TLS. Exposing 2375 gives full control of the host. | Docker daemon API: 2375 unencrypted, 2376 with TLS. Exposing 2375 gives full control of the host. |
| 3000 | TCP | Node.js / Next.js / Rails dev serverConvention Common default for Node.js, Next.js, Express and Rails development servers. | Common default for Node.js, Next.js, Express and Rails development servers. |
| 3306 | TCP | MySQL / MariaDBIANA Default port of MySQL and MariaDB. | Default port of MySQL and MariaDB. |
| 3389 | TCP/UDP | RDPIANA Remote Desktop Protocol for Windows. A favorite brute-force target; put it behind a VPN. | Remote Desktop Protocol for Windows. A favorite brute-force target; put it behind a VPN. |
| 5000 | TCP | Flask dev serverConvention Default port of the Flask development server; also used by macOS AirPlay Receiver. | Default port of the Flask development server; also used by macOS AirPlay Receiver. |
| 5173 | TCP | Vite dev serverConvention Default port of the Vite development server. | Default port of the Vite development server. |
| 5432 | TCP | PostgreSQLIANA Default port of PostgreSQL. | Default port of PostgreSQL. |
| 5672 | TCP | AMQP (RabbitMQ)IANA AMQP protocol used by RabbitMQ and other message brokers. | AMQP protocol used by RabbitMQ and other message brokers. |
| 5900 | TCP | VNCIANA VNC remote desktop (display :0; display :1 uses 5901). | VNC remote desktop (display :0; display :1 uses 5901). |
| 6379 | TCP | RedisConvention Default port of Redis and Valkey. Has no password by default; never expose it publicly. | Default port of Redis and Valkey. Has no password by default; never expose it publicly. |
| 6443 | TCP | Kubernetes API serverConvention Kubernetes API server, used by kubectl and cluster components. | Kubernetes API server, used by kubectl and cluster components. |
| 8000 | TCP | Django / Python http.serverConvention Default for Django runserver and python -m http.server. | Default for Django runserver and python -m http.server. |
| 8080 | TCP | HTTP alternate / proxyIANA Alternative HTTP port for proxies, Tomcat and app servers running without root. | Alternative HTTP port for proxies, Tomcat and app servers running without root. |
| 8443 | TCP | HTTPS alternateConvention Common alternative HTTPS port for admin panels and app servers. | Common alternative HTTPS port for admin panels and app servers. |
| 9092 | TCP | Apache KafkaConvention Apache Kafka brokers for event streaming. | Apache Kafka brokers for event streaming. |
| 9200 | TCP | Elasticsearch / OpenSearchConvention Elasticsearch and OpenSearch REST API (9300 for node-to-node traffic). | Elasticsearch and OpenSearch REST API (9300 for node-to-node traffic). |
| 11211 | TCP/UDP | MemcachedIANA Memcached in-memory cache. Disable UDP; open servers were abused for DDoS amplification. | Memcached in-memory cache. Disable UDP; open servers were abused for DDoS amplification. |
| 27017 | TCP | MongoDBConvention Default port of MongoDB. | Default port of MongoDB. |
| 51820 | UDP | WireGuardConvention Default port of WireGuard VPN tunnels. | Default port of WireGuard VPN tunnels. |