⇅

Common TCP/UDP Ports

A quick reference for well-known TCP and UDP port numbers — SSH, HTTP, HTTPS, mail, databases, and more — with the service each port usually runs and common security notes.

PortServiceProtocolNotes
20/21FTPTCPFile transfer — plaintext creds, avoid exposing
22SSHTCPRemote shell — restrict and use key auth
23TelnetTCPUnencrypted remote shell — do not use
25SMTPTCPMail relay — spam risk if open
53DNSTCP/UDPName resolution
67/68DHCPUDPIP address assignment
80HTTPTCPWeb — should redirect to HTTPS
110POP3TCPEmail retrieval — legacy, plaintext
123NTPUDPTime sync — abused in amplification attacks
143IMAPTCPEmail retrieval — use IMAPS (993)
443HTTPSTCPEncrypted web
445SMBTCPFile sharing — WannaCry vector, close if unused
465SMTPSTCPEncrypted SMTP
587SMTP submitTCPMail submission (STARTTLS)
993IMAPSTCPEncrypted IMAP
995POP3STCPEncrypted POP3
1433MSSQLTCPMicrosoft SQL Server
1521Oracle DBTCPOracle database listener
2375/2376DockerTCP2376 is TLS; 2375 is plaintext — never expose
3306MySQL / MariaDBTCPDatabase — bind to private network only
3389RDPTCPRemote Desktop — top brute-force target, use VPN
5432PostgreSQLTCPDatabase — bind to private network only
5900VNCTCPRemote desktop — usually unencrypted
6379RedisTCPCache/DB — frequent unauthorized-access target
8080HTTP-altTCPCommon proxy/dev HTTP port
8443HTTPS-altTCPCommon alternate TLS port
9000MinIO / PHP-FPMTCPObject storage / app server
9092KafkaTCPMessage broker
27017MongoDBTCPDatabase — infamous for exposed instances
3000Dev serverTCPNode/React dev servers often run here
5601KibanaTCPElasticsearch dashboards
9200ElasticsearchTCPSearch engine — scrape/overwrite risk if open
11211MemcachedUDPAmplification attack vector

For exposure checks, combine with the IP info tool to understand which of your IPs appear public.

How to use this reference

This is a lookup reference. Browse the table to see each well-known port, the service it usually hosts, and the security concern to watch. To check which ports are actually reachable on a host, use the Port Scanner.

FAQ

Which ports are most often targeted?

RDP (3389), SMB (445), SSH (22), and database ports like Mongo (27017), Redis (6379) and Elasticsearch (9200) are frequent targets. Any service you don’t need that is reachable publicly is risk.

Why is 445 (SMB) dangerous?

SMB has a long history of remote code execution flaws, including the WannaCry worm. Unless you specifically need Windows file sharing, it should never be exposed to the internet.

Should I close open ports?

Close or firewall anything you aren’t actively using, and don’t expose database or admin ports to the public internet. Fewer open ports means a smaller attack surface.

How do I check which of my ports are open?

Use the Port Scanner tool here. It tests TCP connectivity from Cloudflare’s edge, which is effectively how the internet sees your host.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.