Common Port Numbers: TCP and UDP Reference and Lookup

Search 76 common TCP and UDP port numbers: what each service does, which are encrypted, and which ports should never be exposed to the internet.

Search more than 70 common TCP and UDP ports by number, by service name or by what they do, and see at a glance which are encrypted and which should never be exposed to the internet.

Quick answer

A port number identifies which service on a host a packet is for. 0 to 1023 are the well-known ports (22 SSH, 80 HTTP, 443 HTTPS), 1024 to 49151 are registered, and 49152 to 65535 are dynamic ports a client picks for its side of the connection. The port alone is not a security control – it only matters what is listening behind it.

How ports actually work

An IP address delivers a packet to a machine; the port number tells that machine which application should get it. A web request to your server arrives addressed to the server IP on port 443, and the web server is the process listening there. A connection is identified by four things: source IP and port, and destination IP and port.

A server listens on a fixed well-known port, while the client picks a random high port for its end. That is why one browser can hold many connections to the same web server at once: each has a different source port. Firewalls and security groups are written in the same terms, so knowing which ports a service uses is the first step in deciding what to allow.

Which ports should never face the internet

Some ports exist to be public: 80 and 443 for web traffic and 25 or 587 for mail. Most do not. Database ports such as 3306 (MySQL), 5432 (PostgreSQL) and 27017 (MongoDB), infrastructure ports such as 2375 (Docker) and 10000 (Webmin), and remote-access ports such as 3389 (RDP) and 5900 (VNC) are meant for a private network or a VPN, not the open internet.

The pattern behind most real-world breaches is not a clever exploit – it is one of these ports left reachable with weak or no authentication. Search the list above, and if a port is flagged as needing protection, check whether it is bound only to the internal interface. Anything that does not need to be public should be closed to the internet and reached through a tunnel.

Port assignments on this page follow the IANA registry and its procedures rather than vendor documentation. This reference was reviewed and fact-checked on 28 September 2026.

  • IANA Service Name and Transport Protocol Port Number Registry — the authoritative list of assigned port numbers, which every entry here was checked against. iana.org
  • RFC 6335, IANA port registry procedures — defines the well-known (0-1023), registered (1024-49151) and dynamic (49152-65535) port bands and how assignments are made. rfc-editor.org/rfc/rfc6335
  • RFC 4291, IPv6 addressing architecture — context for how transport ports sit alongside IPv6 addressing in modern deployments. rfc-editor.org/rfc/rfc4291
Cite this tool

Afroz Ahmad, “Common Port Numbers Reference”, afrozahmad.com. https://afrozahmad.com/common-port-numbers/

Suggested citation: Common Port Numbers Reference, https://afrozahmad.com/common-port-numbers/ (accessed 28 September 2026). (afrozahmad.com), reviewed 28 September 2026.

Reviewed and fact-checked on 28 September 2026.

Primary sources

Port assignments on this page follow the IANA registry and its procedures rather than vendor documentation. This reference was reviewed and fact-checked on 28 September 2026.

  • IANA Service Name and Transport Protocol Port Number Registry — the authoritative list of assigned port numbers, which every entry here was checked against. iana.org
  • RFC 6335, IANA port registry procedures — defines the well-known (0-1023), registered (1024-49151) and dynamic (49152-65535) port bands and how assignments are made. rfc-editor.org/rfc/rfc6335
  • RFC 4291, IPv6 addressing architecture — context for how transport ports sit alongside IPv6 addressing in modern deployments. rfc-editor.org/rfc/rfc4291

What are the most common port numbers I need to know?

Twenty-two for SSH, 25 and 587 for mail, 53 for DNS, 80 for HTTP, 443 for HTTPS, 3389 for Windows Remote Desktop and 3306 for MySQL. Those cover most day-to-day troubleshooting on servers and home labs.

What is the difference between TCP and UDP ports?

TCP establishes a connection, acknowledges data and retransmits anything lost, which suits web, mail and file transfer. UDP just sends packets with no connection or acknowledgement, which suits DNS, voice and video where speed matters more than the odd lost packet. The same port number can exist in both.

Should I open port 443 to the internet?

Yes, if you are running a public website, because that is what HTTPS uses. Open only what the service needs, keep the underlying software patched, and remember that 443 is scanned constantly – the port being open is normal, an unpatched server behind it is not.

Why is port 3389 considered dangerous?

It is Windows Remote Desktop, and an exposed RDP port is attacked continuously with password guessing and known vulnerabilities. Put it behind a VPN or a zero-trust gateway rather than publishing it directly, and enable network-level authentication and account lockout if it must be reachable.

What is an ephemeral port?

A temporary high-numbered port, normally in the 49152 to 65535 dynamic range, that a client picks for its side of an outgoing connection. It exists only for the life of that connection, which is why two connections to the same server use different source ports.