TCP & UDP Port Numbers
A searchable list of well-known and commonly abused TCP and UDP ports, what service runs on each, and a plain security note on whether it is safe to expose that port to the internet.
| Port | Protocol | Service | Description | Security note |
|---|---|---|---|---|
| 20 | TCP | FTP-DATA | File Transfer Protocol data channel | Plaintext |
| 21 | TCP | FTP | File Transfer Protocol control channel | Plaintext — prefer SFTP or FTPS |
| 22 | TCP | SSH / SFTP / SCP | Secure Shell remote administration and file transfer | Encrypted |
| 23 | TCP | Telnet | Unencrypted remote terminal | Insecure — never expose |
| 25 | TCP | SMTP | Mail transfer between servers | Often blocked by hosts to curb spam |
| 53 | TCP/UDP | DNS | Domain name resolution | Plaintext unless DoT/DoH |
| 67 | UDP | DHCP Server | Dynamic host configuration (server) | LAN only |
| 68 | UDP | DHCP Client | Dynamic host configuration (client) | LAN only |
| 69 | UDP | TFTP | Trivial File Transfer Protocol | No authentication — LAN only |
| 80 | TCP | HTTP | Unencrypted web traffic | Should redirect to 443 |
| 88 | TCP/UDP | Kerberos | Network authentication protocol | Internal |
| 110 | TCP | POP3 | Mail retrieval | Plaintext — prefer 995 |
| 111 | TCP/UDP | RPCbind | ONC RPC portmapper | Frequently abused for amplification |
| 119 | TCP | NNTP | Usenet news transfer | Legacy |
| 123 | UDP | NTP | Network time synchronisation | Can be abused for DDoS amplification |
| 135 | TCP | MSRPC | Microsoft RPC endpoint mapper | Never expose to the internet |
| 137 | UDP | NetBIOS-NS | NetBIOS name service | Never expose |
| 139 | TCP | NetBIOS-SSN | NetBIOS session service | Never expose |
| 143 | TCP | IMAP | Mail access | Plaintext — prefer 993 |
| 161 | UDP | SNMP | Network device monitoring | v1/v2c send community strings in clear |
| 162 | UDP | SNMP Trap | Device alert notifications | Internal |
| 179 | TCP | BGP | Border Gateway Protocol routing | Peer-restricted |
| 389 | TCP/UDP | LDAP | Directory services | Plaintext — prefer 636 |
| 443 | TCP | HTTPS | Encrypted web traffic (TLS) | Encrypted |
| 445 | TCP | SMB | Windows file sharing | Never expose — WannaCry vector |
| 465 | TCP | SMTPS | SMTP submission over implicit TLS | Encrypted |
| 500 | UDP | IKE / ISAKMP | IPsec VPN key exchange | VPN |
| 514 | UDP | Syslog | System log forwarding | Plaintext |
| 515 | TCP | LPD | Line printer daemon | Legacy |
| 587 | TCP | SMTP Submission | Mail submission from clients with STARTTLS | Preferred for sending mail |
| 636 | TCP | LDAPS | LDAP over TLS | Encrypted |
| 873 | TCP | rsync | File synchronisation daemon | Authenticate it |
| 993 | TCP | IMAPS | IMAP over TLS | Encrypted |
| 995 | TCP | POP3S | POP3 over TLS | Encrypted |
| 1080 | TCP | SOCKS | SOCKS proxy | Often abused as an open proxy |
| 1194 | UDP | OpenVPN | OpenVPN tunnel | VPN |
| 1433 | TCP | MSSQL | Microsoft SQL Server | Never expose publicly |
| 1521 | TCP | Oracle DB | Oracle database listener | Never expose publicly |
| 1723 | TCP | PPTP | Legacy VPN protocol | Cryptographically broken |
| 1883 | TCP | MQTT | IoT messaging | Plaintext — prefer 8883 |
| 2049 | TCP/UDP | NFS | Network File System | Internal only |
| 2082 | TCP | cPanel | cPanel control panel | Restrict by IP |
| 2375 | TCP | Docker API | Unencrypted Docker daemon API | Critical if exposed — full host takeover |
| 2376 | TCP | Docker API (TLS) | Docker daemon API over TLS | Restrict |
| 3000 | TCP | Dev server / Grafana | Common development and Grafana port | Often left exposed |
| 3128 | TCP | Squid Proxy | HTTP proxy | Often abused as open proxy |
| 3306 | TCP | MySQL / MariaDB | MySQL database | Never expose publicly |
| 3389 | TCP | RDP | Windows Remote Desktop | Top ransomware entry point — use a VPN |
| 4444 | TCP | Metasploit | Common reverse shell / payload port | Suspicious if open |
| 5060 | TCP/UDP | SIP | VoIP signalling | Plaintext — prefer 5061 |
| 5432 | TCP | PostgreSQL | PostgreSQL database | Never expose publicly |
| 5601 | TCP | Kibana | Elasticsearch dashboard | Authenticate it |
| 5672 | TCP | AMQP / RabbitMQ | Message broker | Internal |
| 5900 | TCP | VNC | Remote desktop | Weak auth — tunnel it |
| 5985 | TCP | WinRM (HTTP) | Windows Remote Management | Internal only |
| 5986 | TCP | WinRM (HTTPS) | Windows Remote Management over TLS | Internal only |
| 6379 | TCP | Redis | In-memory data store | No auth by default — critical if exposed |
| 6443 | TCP | Kubernetes API | Kubernetes control plane | Restrict tightly |
| 8000 | TCP | HTTP alternate | Common development web port | Often left exposed |
| 8080 | TCP | HTTP alternate | Proxies, Tomcat, Jenkins | Often left exposed |
| 8443 | TCP | HTTPS alternate | Alternative TLS web port | Encrypted |
| 8883 | TCP | MQTT over TLS | Secure IoT messaging | Encrypted |
| 9000 | TCP | PHP-FPM / SonarQube | FastCGI process manager | Internal |
| 9090 | TCP | Prometheus | Metrics server | Authenticate it |
| 9200 | TCP | Elasticsearch | Search and analytics API | No auth by default — critical if exposed |
| 11211 | TCP/UDP | Memcached | Distributed cache | Major DDoS amplification vector |
| 27017 | TCP | MongoDB | MongoDB database | Never expose publicly |
About this reference
A searchable list of well-known and commonly abused TCP and UDP ports, what service runs on each, and a plain security note on whether it is safe to expose that port to the internet.
This page is static data served straight from the edge, so it loads instantly and works without JavaScript. Filtering happens in your browser — nothing you type is sent anywhere.