Free tool
Network Port Number Reference
Search the common TCP and UDP port numbers, what service uses each one, and whether it is safe to leave that port open to the internet.
Search by port number or by service name. The last column is the part that matters: whether that port is designed to face the internet, needs care before it does, or should never be reachable from outside your network.
92 ports listed
| Port | Protocol | Service | What it does | Internet |
|---|---|---|---|---|
| 80 | TCP | HTTP | Unencrypted web traffic. Normally present only to redirect visitors to HTTPS. | Public |
| 443 | TCP/UDP | HTTPS, HTTP/3 | Encrypted web traffic. UDP on 443 carries HTTP/3 over QUIC. | Public |
| 8080 | TCP | HTTP alternate | Second web port, often a proxy, a development server or an admin panel. | With care |
| 8443 | TCP | HTTPS alternate | Secondary HTTPS port, commonly a management interface. | With care |
| 8000 | TCP | HTTP development | Development servers and application frameworks. Rarely meant to be public. | Internal only |
| 2082 | TCP | cPanel | cPanel over plain HTTP. Use 2083 instead. | Internal only |
| 2083 | TCP | cPanel over TLS | The cPanel control panel for a hosting account. | With care |
| 2086 | TCP | WHM | WHM server administration over plain HTTP. Use 2087. | Internal only |
| 2087 | TCP | WHM over TLS | Full server administration. Restrict to known addresses. | With care |
| 2095 | TCP | Webmail | cPanel webmail over plain HTTP. Use 2096. | Internal only |
| 2096 | TCP | Webmail over TLS | cPanel webmail, encrypted. | Public |
| 10000 | TCP | Webmin | Linux server administration panel. A frequent target. | Internal only |
| 25 | TCP | SMTP | Mail server to mail server delivery. Never use for sending from a client. | Public |
| 465 | TCP | SMTPS | Submitting mail over an implicit TLS connection. | Public |
| 587 | TCP | SMTP submission | The correct port for a mail client to send through, with STARTTLS. | Public |
| 110 | TCP | POP3 | Collecting mail, unencrypted. Passwords travel in clear text. | Internal only |
| 995 | TCP | POP3S | Collecting mail over TLS. | Public |
| 143 | TCP | IMAP | Reading mail on the server, unencrypted unless STARTTLS is enforced. | With care |
| 993 | TCP | IMAPS | Reading mail on the server over TLS. The normal choice. | Public |
| 4190 | TCP | ManageSieve | Server side mail filtering rules. | With care |
| 20 | TCP | FTP data | The data channel for active mode FTP. | Internal only |
| 21 | TCP | FTP control | Credentials and file contents travel unencrypted. Use SFTP or FTPS. | Internal only |
| 22 | TCP | SSH, SFTP, SCP | Encrypted shell and file transfer. Use keys, never passwords. | With care |
| 69 | UDP | TFTP | No authentication at all. Used for switch and phone firmware on a LAN only. | Internal only |
| 989 | TCP | FTPS data | FTP data channel wrapped in TLS. | With care |
| 990 | TCP | FTPS control | FTP control channel wrapped in TLS. | With care |
| 445 | TCP | SMB, Windows shares | Windows file sharing. Exposing this to the internet is how ransomware spreads. | Internal only |
| 139 | TCP | NetBIOS session | Legacy Windows file sharing. Internal networks only. | Internal only |
| 137 | UDP | NetBIOS name | Legacy Windows name resolution. | Internal only |
| 138 | UDP | NetBIOS datagram | Legacy Windows browsing and announcements. | Internal only |
| 2049 | TCP/UDP | NFS | Unix network file system. Trusts the network it runs on. | Internal only |
| 873 | TCP | rsync | File synchronisation. Often left open with no authentication. | Internal only |
| 548 | TCP | AFP | Apple file sharing, largely replaced by SMB. | Internal only |
| 23 | TCP | Telnet | Entirely unencrypted remote shell. Should not be running anywhere. | Internal only |
| 3389 | TCP/UDP | RDP | Windows remote desktop. The single most attacked port on the internet. Use a VPN. | Internal only |
| 5900 | TCP | VNC | Remote screen access, often with weak or no authentication. | Internal only |
| 5938 | TCP | TeamViewer | Outbound connection to the TeamViewer service. | Public |
| 3283 | TCP/UDP | Apple Remote Desktop | Apple remote management reporting channel. | Internal only |
| 8291 | TCP | MikroTik Winbox | MikroTik router management. Restrict to the LAN or a VPN. | Internal only |
| 8728 | TCP | MikroTik API | RouterOS API, unencrypted. | Internal only |
| 8729 | TCP | MikroTik API TLS | RouterOS API over TLS. | With care |
| 500 | UDP | IKE, IPsec | Key exchange for IPsec VPN tunnels. | Public |
| 4500 | UDP | IPsec NAT traversal | IPsec where one end sits behind NAT. | Public |
| 1194 | UDP | OpenVPN | The OpenVPN default. TCP 443 is often used to pass through restrictive networks. | Public |
| 51820 | UDP | WireGuard | Modern VPN. Silent to anyone without a valid key. | Public |
| 1723 | TCP | PPTP | Obsolete and broken encryption. Do not deploy it. | Internal only |
| 1701 | UDP | L2TP | Tunnelling, used with IPsec for the encryption it lacks. | Public |
| 3306 | TCP | MySQL, MariaDB | Should listen on localhost or the internal network only. | Internal only |
| 5432 | TCP | PostgreSQL | Internal use only. Never expose a database to the internet. | Internal only |
| 1433 | TCP | Microsoft SQL Server | Internal only. A long history of worms targeting it. | Internal only |
| 1521 | TCP | Oracle | Oracle database listener. Internal only. | Internal only |
| 27017 | TCP | MongoDB | Historically shipped with no authentication. Thousands were ransomed because of it. | Internal only |
| 6379 | TCP | Redis | No authentication by default and trivially abused to run commands. | Internal only |
| 11211 | TCP/UDP | Memcached | No authentication, and on UDP it has been used for enormous amplification attacks. | Internal only |
| 9200 | TCP | Elasticsearch | A full HTTP API over your data. Internal only. | Internal only |
| 5984 | TCP | CouchDB | HTTP database interface. Internal only. | Internal only |
| 53 | TCP/UDP | DNS | Name resolution. UDP for queries, TCP for large answers and zone transfers. | With care |
| 853 | TCP | DNS over TLS | Encrypted DNS queries. | Public |
| 67 | UDP | DHCP server | Hands out addresses. Local network only by design. | Internal only |
| 68 | UDP | DHCP client | The client side of address assignment. | Internal only |
| 123 | UDP | NTP | Time synchronisation. Has been abused for amplification attacks. | With care |
| 161 | UDP | SNMP | Device monitoring. Version 1 and 2c send the community string in clear text. | Internal only |
| 162 | UDP | SNMP trap | Alerts sent from devices to a monitoring server. | Internal only |
| 389 | TCP | LDAP | Directory lookups, unencrypted. Internal only. | Internal only |
| 636 | TCP | LDAPS | Directory lookups over TLS. | With care |
| 88 | TCP/UDP | Kerberos | Windows domain authentication. | Internal only |
| 514 | UDP | Syslog | Log collection. Unauthenticated and easily spoofed. | Internal only |
| 6514 | TCP | Syslog over TLS | Encrypted log transport. | With care |
| 179 | TCP | BGP | Routing between networks. Peers only. | Internal only |
| 1812 | UDP | RADIUS auth | Authentication for Wi-Fi, VPN and hotspot users. | Internal only |
| 1813 | UDP | RADIUS accounting | Session accounting records. | Internal only |
| 5353 | UDP | mDNS, Bonjour | Local device discovery. Should never cross a router. | Internal only |
| 1900 | UDP | SSDP, UPnP | Device discovery. A well known amplification source. Disable on the WAN. | Internal only |
| 5060 | TCP/UDP | SIP | Call signalling, unencrypted. Scanned constantly for toll fraud. | Internal only |
| 5061 | TCP | SIP over TLS | Encrypted call signalling. | With care |
| 10000-20000 | UDP | RTP media | The audio itself. A wide range, which is why VoIP and strict firewalls argue. | With care |
| 4569 | UDP | IAX2 | Asterisk to Asterisk trunking. | With care |
| 554 | TCP/UDP | RTSP | Camera video streams. Frequently exposed with default credentials. | Internal only |
| 37777 | TCP | Dahua | Dahua recorder and camera protocol. | Internal only |
| 8000 | TCP | Hikvision | Hikvision service port. Use a VPN rather than forwarding it. | Internal only |
| 34567 | TCP | XMEye, generic NVR | Common on inexpensive recorders, with a poor security record. | Internal only |
| 3702 | UDP | ONVIF discovery | How recorders find cameras on the network. | Internal only |
| 502 | TCP | Modbus | Industrial and building control. No authentication whatsoever. | Internal only |
| 3000 | TCP | Node, Grafana | Common development server and Grafana default. | With care |
| 5000 | TCP | Flask, Docker registry | Python development server and private registry default. | Internal only |
| 9000 | TCP | PHP-FPM, Portainer | PHP process manager, which must never be public, and Portainer. | Internal only |
| 2375 | TCP | Docker API | Unencrypted Docker control. Exposing it hands over the whole host. | Internal only |
| 2376 | TCP | Docker API over TLS | Docker control with certificate authentication. | Internal only |
| 6443 | TCP | Kubernetes API | Cluster control plane. | With care |
| 9090 | TCP | Prometheus, Cockpit | Metrics collection and Linux web administration. | Internal only |
| 8086 | TCP | InfluxDB | Time series database API. | Internal only |
| 25565 | TCP | Minecraft | Game server default, listed because it comes up constantly in home networks. | With care |
Nothing matches that search.
The three ports that cause most breaches
If you only check three things on a firewall, check that 3389, 445 and 22 are not open to the whole internet. Remote desktop on 3389 is scanned continuously by automated tools that try common passwords all day, and it is the most frequent way ransomware reaches a business network. Windows file sharing on 445 is how that ransomware then spreads once it is inside. SSH on 22 is safer because it can be configured properly, but only if password logins are switched off and keys are used instead.
None of these need to be public. A VPN puts all three behind a single encrypted door that does not answer strangers, and it is the one change that removes the largest amount of risk for the least effort.
Databases are never a public service
Every database port in the list above is marked internal only, and that is not caution. MongoDB, Redis and Memcached all shipped for years with no authentication enabled by default, and tens of thousands of them were found, emptied and held for ransom by people doing nothing more sophisticated than scanning the internet. A database should listen on localhost or on a private address that only the application server can reach. If a hosting provider tells you otherwise, that is worth questioning.
Cameras and recorders deserve special suspicion
CCTV equipment is the worst offender in most buildings. Recorders are routinely installed with the port forwarded straight through the router so the owner can watch from a phone, often with the factory password still set and firmware that has never been updated. Public search engines index these devices, which means anybody can find them. Remote viewing is reasonable to want. Do it through a VPN or the manufacturer's cloud relay rather than by opening the recorder to everyone.
A closed port tells an attacker less than a filtered one
There is a difference between a port that refuses a connection and one that never answers. A refusal confirms there is a live host at that address. Silence tells a scanner nothing, which is why a firewall should drop unwanted traffic rather than reject it. It is a small configuration detail that makes your network considerably less interesting to automated scanning.