TCP & UDP Port Numbers

A searchable list of well-known and commonly abused TCP and UDP ports, what service runs on each, and a plain security note on whether it is safe to expose that port to the internet.

67 entries

PortProtocolServiceDescriptionSecurity note
20TCPFTP-DATAFile Transfer Protocol data channelPlaintext
21TCPFTPFile Transfer Protocol control channelPlaintext — prefer SFTP or FTPS
22TCPSSH / SFTP / SCPSecure Shell remote administration and file transferEncrypted
23TCPTelnetUnencrypted remote terminalInsecure — never expose
25TCPSMTPMail transfer between serversOften blocked by hosts to curb spam
53TCP/UDPDNSDomain name resolutionPlaintext unless DoT/DoH
67UDPDHCP ServerDynamic host configuration (server)LAN only
68UDPDHCP ClientDynamic host configuration (client)LAN only
69UDPTFTPTrivial File Transfer ProtocolNo authentication — LAN only
80TCPHTTPUnencrypted web trafficShould redirect to 443
88TCP/UDPKerberosNetwork authentication protocolInternal
110TCPPOP3Mail retrievalPlaintext — prefer 995
111TCP/UDPRPCbindONC RPC portmapperFrequently abused for amplification
119TCPNNTPUsenet news transferLegacy
123UDPNTPNetwork time synchronisationCan be abused for DDoS amplification
135TCPMSRPCMicrosoft RPC endpoint mapperNever expose to the internet
137UDPNetBIOS-NSNetBIOS name serviceNever expose
139TCPNetBIOS-SSNNetBIOS session serviceNever expose
143TCPIMAPMail accessPlaintext — prefer 993
161UDPSNMPNetwork device monitoringv1/v2c send community strings in clear
162UDPSNMP TrapDevice alert notificationsInternal
179TCPBGPBorder Gateway Protocol routingPeer-restricted
389TCP/UDPLDAPDirectory servicesPlaintext — prefer 636
443TCPHTTPSEncrypted web traffic (TLS)Encrypted
445TCPSMBWindows file sharingNever expose — WannaCry vector
465TCPSMTPSSMTP submission over implicit TLSEncrypted
500UDPIKE / ISAKMPIPsec VPN key exchangeVPN
514UDPSyslogSystem log forwardingPlaintext
515TCPLPDLine printer daemonLegacy
587TCPSMTP SubmissionMail submission from clients with STARTTLSPreferred for sending mail
636TCPLDAPSLDAP over TLSEncrypted
873TCPrsyncFile synchronisation daemonAuthenticate it
993TCPIMAPSIMAP over TLSEncrypted
995TCPPOP3SPOP3 over TLSEncrypted
1080TCPSOCKSSOCKS proxyOften abused as an open proxy
1194UDPOpenVPNOpenVPN tunnelVPN
1433TCPMSSQLMicrosoft SQL ServerNever expose publicly
1521TCPOracle DBOracle database listenerNever expose publicly
1723TCPPPTPLegacy VPN protocolCryptographically broken
1883TCPMQTTIoT messagingPlaintext — prefer 8883
2049TCP/UDPNFSNetwork File SystemInternal only
2082TCPcPanelcPanel control panelRestrict by IP
2375TCPDocker APIUnencrypted Docker daemon APICritical if exposed — full host takeover
2376TCPDocker API (TLS)Docker daemon API over TLSRestrict
3000TCPDev server / GrafanaCommon development and Grafana portOften left exposed
3128TCPSquid ProxyHTTP proxyOften abused as open proxy
3306TCPMySQL / MariaDBMySQL databaseNever expose publicly
3389TCPRDPWindows Remote DesktopTop ransomware entry point — use a VPN
4444TCPMetasploitCommon reverse shell / payload portSuspicious if open
5060TCP/UDPSIPVoIP signallingPlaintext — prefer 5061
5432TCPPostgreSQLPostgreSQL databaseNever expose publicly
5601TCPKibanaElasticsearch dashboardAuthenticate it
5672TCPAMQP / RabbitMQMessage brokerInternal
5900TCPVNCRemote desktopWeak auth — tunnel it
5985TCPWinRM (HTTP)Windows Remote ManagementInternal only
5986TCPWinRM (HTTPS)Windows Remote Management over TLSInternal only
6379TCPRedisIn-memory data storeNo auth by default — critical if exposed
6443TCPKubernetes APIKubernetes control planeRestrict tightly
8000TCPHTTP alternateCommon development web portOften left exposed
8080TCPHTTP alternateProxies, Tomcat, JenkinsOften left exposed
8443TCPHTTPS alternateAlternative TLS web portEncrypted
8883TCPMQTT over TLSSecure IoT messagingEncrypted
9000TCPPHP-FPM / SonarQubeFastCGI process managerInternal
9090TCPPrometheusMetrics serverAuthenticate it
9200TCPElasticsearchSearch and analytics APINo auth by default — critical if exposed
11211TCP/UDPMemcachedDistributed cacheMajor DDoS amplification vector
27017TCPMongoDBMongoDB databaseNever expose publicly

About this reference

A searchable list of well-known and commonly abused TCP and UDP ports, what service runs on each, and a plain security note on whether it is safe to expose that port to the internet.

This page is static data served straight from the edge, so it loads instantly and works without JavaScript. Filtering happens in your browser — nothing you type is sent anywhere.