Common TCP/UDP Ports
A quick reference for well-known TCP and UDP port numbers — SSH, HTTP, HTTPS, mail, databases, and more — with the service each port usually runs and common security notes.
| Port | Service | Protocol | Notes |
|---|---|---|---|
| 20/21 | FTP | TCP | File transfer — plaintext creds, avoid exposing |
| 22 | SSH | TCP | Remote shell — restrict and use key auth |
| 23 | Telnet | TCP | Unencrypted remote shell — do not use |
| 25 | SMTP | TCP | Mail relay — spam risk if open |
| 53 | DNS | TCP/UDP | Name resolution |
| 67/68 | DHCP | UDP | IP address assignment |
| 80 | HTTP | TCP | Web — should redirect to HTTPS |
| 110 | POP3 | TCP | Email retrieval — legacy, plaintext |
| 123 | NTP | UDP | Time sync — abused in amplification attacks |
| 143 | IMAP | TCP | Email retrieval — use IMAPS (993) |
| 443 | HTTPS | TCP | Encrypted web |
| 445 | SMB | TCP | File sharing — WannaCry vector, close if unused |
| 465 | SMTPS | TCP | Encrypted SMTP |
| 587 | SMTP submit | TCP | Mail submission (STARTTLS) |
| 993 | IMAPS | TCP | Encrypted IMAP |
| 995 | POP3S | TCP | Encrypted POP3 |
| 1433 | MSSQL | TCP | Microsoft SQL Server |
| 1521 | Oracle DB | TCP | Oracle database listener |
| 2375/2376 | Docker | TCP | 2376 is TLS; 2375 is plaintext — never expose |
| 3306 | MySQL / MariaDB | TCP | Database — bind to private network only |
| 3389 | RDP | TCP | Remote Desktop — top brute-force target, use VPN |
| 5432 | PostgreSQL | TCP | Database — bind to private network only |
| 5900 | VNC | TCP | Remote desktop — usually unencrypted |
| 6379 | Redis | TCP | Cache/DB — frequent unauthorized-access target |
| 8080 | HTTP-alt | TCP | Common proxy/dev HTTP port |
| 8443 | HTTPS-alt | TCP | Common alternate TLS port |
| 9000 | MinIO / PHP-FPM | TCP | Object storage / app server |
| 9092 | Kafka | TCP | Message broker |
| 27017 | MongoDB | TCP | Database — infamous for exposed instances |
| 3000 | Dev server | TCP | Node/React dev servers often run here |
| 5601 | Kibana | TCP | Elasticsearch dashboards |
| 9200 | Elasticsearch | TCP | Search engine — scrape/overwrite risk if open |
| 11211 | Memcached | UDP | Amplification attack vector |
For exposure checks, combine with the IP info tool to understand which of your IPs appear public.
How to use this reference
This is a lookup reference. Browse the table to see each well-known port, the service it usually hosts, and the security concern to watch. To check which ports are actually reachable on a host, use the Port Scanner.
FAQ
Which ports are most often targeted?
RDP (3389), SMB (445), SSH (22), and database ports like Mongo (27017), Redis (6379) and Elasticsearch (9200) are frequent targets. Any service you don’t need that is reachable publicly is risk.
Why is 445 (SMB) dangerous?
SMB has a long history of remote code execution flaws, including the WannaCry worm. Unless you specifically need Windows file sharing, it should never be exposed to the internet.
Should I close open ports?
Close or firewall anything you aren’t actively using, and don’t expose database or admin ports to the public internet. Fewer open ports means a smaller attack surface.
How do I check which of my ports are open?
Use the Port Scanner tool here. It tests TCP connectivity from Cloudflare’s edge, which is effectively how the internet sees your host.