Ctrl + K
Network22 min read

Ports Every Developer Should Know

A practical reference to common TCP and UDP ports used by web servers, databases, development tools, networking protocols, email services, and infrastructure.

Published: 2026-10-05

A network port is a logical endpoint used to identify a particular service or application on a device. IP addresses identify hosts, while port numbers help identify which service should receive a network connection.

Developers encounter ports constantly. A web application may run on port 3000 during development, HTTPS normally uses port 443, SSH uses port 22, PostgreSQL commonly uses port 5432, and Redis commonly uses port 6379. Knowing the common ports makes it easier to configure applications, connect to servers, troubleshoot networking problems, and understand firewall rules.

This guide covers the ports developers are most likely to encounter, explains the difference between TCP and UDP ports, and shows how ports are used by web servers, databases, development environments, email systems, and other common services.

What Is a Network Port?

A network port is a number associated with a network service. Port numbers range from 0 to 65535 and are used with transport protocols such as TCP and UDP.

An IP address identifies the destination host, while the port identifies the destination service on that host. Together with a transport protocol, the address and port form an endpoint for network communication.

192.0.2.10:443

In this example, 192.0.2.10 is the IP address and 443 is the port. A TCP connection to this endpoint would normally be intended for an HTTPS service.

What Is a Port Used For?

A single server can run many network services at the same time. Without ports, a client would know which machine to contact but would not have a standardized way to identify the intended service.

ComponentExamplePurpose
IP address192.0.2.10Identifies the host.
ProtocolTCPDefines how the transport connection works.
Port443Identifies the service endpoint.

For example, a server can accept HTTPS connections on TCP port 443 while simultaneously accepting SSH connections on TCP port 22 and PostgreSQL connections on TCP port 5432.

TCP Ports vs UDP Ports

TCP and UDP both use port numbers, but they provide different transport mechanisms. TCP establishes a connection and provides reliable, ordered delivery. UDP is connectionless and has lower protocol overhead, but it does not provide TCP's built-in delivery guarantees.

CharacteristicTCPUDP
ConnectionConnection-orientedConnectionless
DeliveryReliable and orderedNo built-in delivery guarantee
Typical useHTTP, HTTPS, SSH, databasesDNS, DHCP, streaming and real-time protocols
HandshakeTCP connection establishmentNo TCP-style handshake

The same numeric port can exist independently for TCP and UDP. For example, DNS commonly uses UDP port 53 for ordinary queries, while TCP port 53 is also used for specific DNS operations and responses that require TCP.

Port Number Ranges

Port numbers are divided into ranges with different conventions.

RangeNameDescription
0–1023Well-known portsPorts traditionally associated with widely used standard services.
1024–49151Registered portsPorts associated with applications and services registered with IANA.
49152–65535Dynamic/private portsCommonly available for dynamic or private use, including ephemeral client ports.

These ranges describe conventions rather than strict technical restrictions on what software can do. Modern operating systems can run applications on many different ports when permissions and configuration allow it.

The Most Important Web Ports

PortProtocolCommon service
80TCPHTTP
443TCPHTTPS
8080TCPAlternative HTTP and development servers
8443TCPAlternative HTTPS

Port 80 — HTTP

TCP port 80 is the standard port associated with HTTP. Traditional HTTP URLs without an explicit port normally use port 80.

http://example.com:80

Modern public websites frequently redirect HTTP traffic to HTTPS, but port 80 remains important because browsers, reverse proxies, load balancers, certificate validation mechanisms, and legacy applications may still interact with HTTP endpoints.

Port 443 — HTTPS

TCP port 443 is the standard port associated with HTTPS. HTTPS combines HTTP with TLS to provide encryption and server authentication.

https://example.com:443

When a URL uses HTTPS without an explicit port, clients normally connect to TCP port 443. HTTP/3 is an important exception to the transport protocol: it uses QUIC over UDP, commonly on UDP port 443.

Port 8080 — Alternative HTTP

Port 8080 is widely used for HTTP applications that should not occupy port 80. Developers frequently encounter it with local development servers, application servers, proxies, and internal services.

http://localhost:8080

Port 8080 is a convention rather than a requirement. Any application can be configured to listen on another available port.

Port 8443 — Alternative HTTPS

TCP port 8443 is commonly used as an alternative HTTPS port, especially for development environments, administration interfaces, Java application servers, and internal services.

It does not have the same universal meaning as 443. If an application uses port 8443, the actual service behavior depends on its configuration.

SSH and Remote Administration Ports

PortProtocolCommon service
22TCPSSH
23TCPTelnet
3389TCP/UDPRemote Desktop Protocol

Port 22 — SSH

TCP port 22 is the standard port for SSH, which provides encrypted remote shell access and is also widely used for secure file transfer and tunneling.

ssh [email protected]

SSH servers can listen on other ports, but port 22 is the conventional default. Moving SSH to another port is sometimes used as an operational measure to reduce automated scanning noise, but changing the port does not replace proper authentication, access control, and firewall configuration.

Port 23 — Telnet

TCP port 23 is traditionally associated with Telnet. Telnet provides remote terminal access but does not provide the encryption expected from SSH.

⚠️ Telnet transmits sensitive information without the protections provided by SSH. It should generally not be used for secure remote administration over untrusted networks.

Port 3389 — Remote Desktop Protocol

Port 3389 is commonly associated with Microsoft's Remote Desktop Protocol. Depending on the implementation and configuration, RDP can use both TCP and UDP.

Exposing remote administration services directly to the public Internet requires careful security controls, including strong authentication, network restrictions, patching, and monitoring.

DNS Ports

PortProtocolCommon use
53UDPTypical DNS queries
53TCPDNS operations that require TCP
853TCPDNS over TLS
443TCP/UDPDNS over HTTPS or other HTTPS-based DNS services

Port 53 — DNS

Port 53 is used by the Domain Name System. DNS commonly uses UDP port 53 for ordinary queries because UDP has low overhead. TCP port 53 is also part of DNS and is used when TCP is required, including certain large responses and zone transfer operations.

DNS server: 192.0.2.53
UDP port: 53
TCP port: 53

DNSSEC does not introduce a separate transport port. DNSSEC data is exchanged through DNS using the normal DNS transport mechanisms.

Port 853 — DNS over TLS

TCP port 853 is commonly associated with DNS over TLS, which encrypts DNS traffic using TLS. This is different from ordinary DNS over port 53 because the DNS messages are carried through a TLS-encrypted connection.

Port 25 — SMTP

TCP port 25 is the traditional SMTP port used primarily for mail server-to-mail server delivery. It is not normally the port applications should use for authenticated email submission.

Many hosting providers and networks restrict outbound connections to port 25 to reduce spam abuse. Application email submission commonly uses other ports with authentication and TLS.

Port 587 — SMTP Submission

TCP port 587 is the standard port commonly used for message submission by email clients and applications. It is designed for authenticated submission rather than traditional server-to-server SMTP delivery.

Port 465 — SMTP over TLS

TCP port 465 is widely used for SMTP submission with TLS established from the beginning of the connection. It is commonly supported by modern mail services alongside port 587.

Port 110 — POP3

TCP port 110 is associated with POP3, a protocol for retrieving email. Its encrypted counterpart commonly uses TCP port 995.

Port 143 — IMAP

TCP port 143 is associated with IMAP, while TCP port 993 is commonly used for IMAP over TLS.

PortProtocolCommon use
25TCPSMTP server-to-server mail transfer
465TCPSMTP submission over TLS
587TCPSMTP message submission
110TCPPOP3
995TCPPOP3 over TLS
143TCPIMAP
993TCPIMAP over TLS

Database Ports Developers Should Know

PortProtocolDatabase or service
1433TCPMicrosoft SQL Server
1521TCPOracle Database
3306TCPMySQL and commonly MariaDB
5432TCPPostgreSQL
6379TCPRedis
27017TCPMongoDB

Port 3306 — MySQL

TCP port 3306 is the conventional default for MySQL and is also commonly used by MariaDB. Local development environments often expose a database on this port when the database runs directly on the host or through a container.

mysql://localhost:3306/app_database

Port 5432 — PostgreSQL

TCP port 5432 is the conventional PostgreSQL port. Developers frequently encounter it when connecting backend applications to local or containerized PostgreSQL instances.

postgresql://localhost:5432/app_database

Port 6379 — Redis

TCP port 6379 is the conventional Redis port. Redis is commonly used for caching, temporary data, queues, sessions, counters, and other fast in-memory workloads.

redis://localhost:6379

Port 27017 — MongoDB

TCP port 27017 is the conventional default port for MongoDB. It is frequently used in local development and private application networks.

Port 1433 — Microsoft SQL Server

TCP port 1433 is the conventional default port for Microsoft SQL Server. Named instances and custom configurations can use different ports.

Port 1521 — Oracle Database

TCP port 1521 is commonly associated with Oracle Database's listener service. The actual port can be changed by the database administrator.

Common Development Server Ports

PortCommon development use
3000Node.js, Next.js and other JavaScript development servers
4000Various application development servers
5000Flask and other application servers
5173Vite development server default
8000Python and various local HTTP servers
8080Alternative HTTP and application server
9000Various development tools and application servers

Development frameworks often choose conventional defaults, but these ports are not permanently assigned to those technologies. Developers can usually change the listening port through configuration or command-line options.

Port 3000

Port 3000 is extremely common in JavaScript and Node.js development. Next.js, React development setups, Express applications, and many custom Node.js projects can use it.

http://localhost:3000

If another process already occupies port 3000, the development server may fail to start or may need to be configured to use another port.

Port 5173

Port 5173 is the default development port commonly associated with Vite. It is often seen when developing React, Vue, Svelte, and other frontend applications using Vite.

Port 8000

Port 8000 is another popular development HTTP port. It is commonly encountered with Python development servers and local static file servers.

Container and Local Development Ports

Docker and similar container systems make port mapping especially important. A service can listen on one port inside a container while being exposed through a different port on the host.

localhost:8080 -> container port 3000

For example, an application could listen on port 3000 inside a container while Docker publishes that service on port 8080 on the host. The exact syntax depends on the container runtime and configuration.

Why Port Conflicts Happen

A TCP or UDP port can be occupied by a process that is already listening on the corresponding local address and protocol. If another application attempts to bind to the same endpoint, the operating system may reject the operation.

Error: listen EADDRINUSE: address already in use

This is especially common when a previous development server is still running in another terminal window.

How to Find Which Process Uses a Port

Operating systems provide commands for finding listening sockets and the processes associated with them. The exact command depends on the operating system.

# Linux
ss -ltnp | grep :3000

# macOS
lsof -nP -iTCP:3000 -sTCP:LISTEN

# Windows
netstat -ano | findstr :3000

On Windows, the PID shown by netstat can be correlated with the process using Task Manager or another process-management command. On Linux and macOS, tools such as ss and lsof can show the process directly when permissions allow it.

Common Ports for Infrastructure

PortProtocolCommon use
161UDPSNMP
162UDPSNMP traps
514UDP/TCPSyslog
1194UDP/TCPOpenVPN, depending on configuration
2049TCP/UDPNFS
2375TCPDocker Engine API without TLS
2376TCPDocker Engine API with TLS
6443TCPKubernetes API server

Port 6443 — Kubernetes API Server

TCP port 6443 is the commonly used default secure port for the Kubernetes API server. Kubernetes clients such as kubectl communicate with the API server through HTTPS.

The port can be changed, and Kubernetes networking frequently involves additional ports for node services, cluster networking, ingress, and application workloads.

Ports 2375 and 2376 — Docker Engine API

TCP port 2375 is conventionally associated with an unencrypted Docker Engine API, while port 2376 is commonly associated with a TLS-protected Docker Engine API.

⚠️ An exposed Docker daemon API can provide powerful control over the host. Do not expose an unauthenticated Docker API to an untrusted network.

Ports Used by Version Control and Git

Git itself does not have one universal network port. The port depends on the transport used to access a repository.

TransportTypical portExample
HTTPS443https://git.example.com/repository.git
SSH22[email protected]:repository.git
Git protocol9418git://git.example.com/repository.git

In practice, HTTPS and SSH are much more common for modern authenticated Git hosting than the unauthenticated Git protocol.

Ports for File Transfer

PortProtocolService
20TCPFTP data channel in traditional active FTP
21TCPFTP control channel
22TCPSFTP over SSH
69UDPTFTP
989TCPFTPS data
990TCPFTPS control

FTP has separate control and data behavior and can involve additional ports depending on whether active or passive mode is used. SFTP is different from FTP and runs as a subsystem over SSH, normally using TCP port 22.

Ports and Firewalls

Firewalls control whether network traffic is allowed to reach particular hosts and ports. A service can be running correctly but still be unreachable because a firewall blocks the corresponding traffic.

Application listening: TCP 443
Firewall rule: allow TCP 443
Client: connects to server:443

When troubleshooting a connection, check both sides: verify that the service is actually listening on the expected port and verify that network security rules allow the required traffic.

Listening Port vs Open Port

A service listening on a port does not automatically mean that the port is reachable from the Internet. The service may be bound only to localhost, blocked by a host firewall, protected by a cloud security group, or hidden behind another network layer.

SituationMeaning
Process listens on 127.0.0.1:3000The service is available only through the local machine.
Process listens on 0.0.0.0:3000The service may accept connections through available IPv4 interfaces, subject to firewall rules.
Firewall blocks TCP 3000External clients cannot reach the service through that port.
Service not listeningThere is no application accepting connections on that endpoint.

Why a Port Can Appear Closed

A connection attempt can fail for several reasons. The application may not be running, it may be listening on another port, it may be bound only to localhost, or a firewall or network security group may block the traffic.

A timeout and an immediate connection refusal can also provide different clues, although their exact interpretation depends on the network path and filtering behavior.

Port Scanning

Port scanning is the process of testing a host for services that respond on particular ports. Developers may use port scanning when troubleshooting their own infrastructure or validating firewall configuration.

⚠️ Only scan systems you own or have explicit permission to test. Unauthorized port scanning can violate organizational policies or applicable laws.

Port Numbers Are Conventions, Not Guarantees

Knowing that PostgreSQL normally uses port 5432 does not guarantee that every PostgreSQL server uses it. Administrators can configure services to listen on different ports.

The same principle applies to HTTP, SSH, databases, development servers, and nearly every other service. A port number is useful shorthand for a common configuration, not proof of what is actually running on a host.

Common Developer Ports at a Glance

PortProtocolCommon service
22TCPSSH
25TCPSMTP
53UDP/TCPDNS
80TCPHTTP
110TCPPOP3
143TCPIMAP
443TCP/UDPHTTPS and HTTP/3
465TCPSMTP over TLS
587TCPSMTP submission
993TCPIMAP over TLS
995TCPPOP3 over TLS
1433TCPMicrosoft SQL Server
1521TCPOracle Database
3000TCPCommon JavaScript development server
3306TCPMySQL
3389TCP/UDPRDP
5000TCPCommon application development server
5173TCPVite development server
5432TCPPostgreSQL
6379TCPRedis
6443TCPKubernetes API server
8080TCPAlternative HTTP
8443TCPAlternative HTTPS
27017TCPMongoDB

How to Troubleshoot a Port Connection

When an application cannot connect to a service, first identify the hostname and expected port. Verify that the service is configured to listen on that port and that the client is using the correct transport protocol.

Next, check whether the service is bound to the expected network interface. A service listening only on localhost cannot normally accept connections from another machine.

Finally, inspect host firewalls, cloud security groups, container port mappings, reverse proxies, and other network controls. If possible, test the endpoint from the same network location as the failing client because local and external connectivity can produce different results.

Useful Port-Testing Commands

Different operating systems provide different networking utilities. For example, curl is useful for HTTP services, while nc and similar tools can test whether a TCP connection can be established.

curl http://localhost:8080
nc -vz example.com 443

A successful TCP connection only confirms that something accepted the connection. It does not necessarily prove that the expected application protocol is configured correctly.

Ports and Security

Every exposed service increases the number of network endpoints that need to be maintained and secured. Developers should avoid exposing development databases, administrative interfaces, debugging services, or internal APIs to networks where they are not required.

Security should not rely on obscurity of a port number. Moving a service from a well-known port to a random port can change the amount of automated scanning it receives, but it does not replace authentication, encryption, authorization, firewall rules, or software updates.

💡 For production systems, expose only the ports required by the architecture. Keep databases and internal services on private networks whenever possible instead of making them directly reachable from the public Internet.

How Ports Relate to URLs

A URL can contain an explicit port after the hostname. If no port is specified, the application protocol normally determines the default.

https://example.com:443
http://localhost:3000
postgresql://localhost:5432/app

The port is not part of the hostname itself. It is a separate component of the network endpoint used to establish the connection.

Common Mistakes With Ports

  • Assuming a service always uses its conventional default port.
  • Using a TCP port when the service expects UDP, or the reverse.
  • Forgetting to expose a container port to the host.
  • Opening a firewall port without checking which application is listening there.
  • Assuming that a listening service is automatically reachable from another machine.
  • Exposing databases directly to the public Internet when private networking would be sufficient.
  • Confusing SFTP on port 22 with FTP on port 21.
  • Assuming port 443 always means HTTP over TCP when HTTP/3 may use QUIC over UDP.
  • Changing a service port without updating application connection strings or firewall rules.
  • Testing a port from localhost and assuming the same result will occur from an external network.

Frequently Asked Questions

What ports should every developer know?

The most useful starting set includes 22 for SSH, 53 for DNS, 80 for HTTP, 443 for HTTPS, 25 and 587 for SMTP, 3306 for MySQL, 5432 for PostgreSQL, 6379 for Redis, 27017 for MongoDB, 3000 for common JavaScript development servers, 5173 for Vite, and 8080 for alternative HTTP services.

What is port 443 used for?

TCP port 443 is the standard port for HTTPS. HTTP/3 commonly uses UDP port 443 because HTTP/3 runs over QUIC rather than TCP.

What is port 80 used for?

TCP port 80 is the standard port for HTTP. Many public websites redirect HTTP traffic from port 80 to HTTPS on port 443.

What is port 22 used for?

TCP port 22 is the conventional port for SSH. SSH provides encrypted remote administration and is also used for services such as SFTP and Git over SSH.

What is the PostgreSQL port?

PostgreSQL commonly listens on TCP port 5432. However, administrators can configure it to use a different port.

What is the difference between TCP and UDP ports?

TCP provides connection-oriented, reliable and ordered delivery, while UDP is connectionless and does not provide TCP's built-in delivery guarantees. Both protocols have independent port spaces.

Can two applications use the same port?

Two applications generally cannot listen on the exact same IP address, transport protocol, and port combination at the same time. They can use the same numeric port if they bind to different local addresses or use different transport protocols, subject to operating-system rules.

Helpful Networking Tools

A Port Number Lookup tool is useful when you encounter an unfamiliar port and want to identify its commonly registered service. An HTTP Port Reference provides a focused reference for web-related ports, while a Ping Command Builder can help construct basic connectivity tests. An HTTP Request Builder is useful when the port belongs to an HTTP service, and an SSH Config Generator can simplify SSH connection configuration when working with remote servers.

Conclusion

Ports provide a standard way for network clients to identify services running on a host. Developers encounter them everywhere: web servers use 80 and 443, SSH commonly uses 22, DNS uses 53, email services use several ports, and databases such as MySQL, PostgreSQL, Redis, and MongoDB have familiar defaults.

The most important thing to remember is that port numbers are conventions rather than guarantees. A PostgreSQL server can run somewhere other than 5432, an SSH server can use a custom port, and a development application can listen wherever its configuration specifies.

When troubleshooting a connection, always consider the complete endpoint: hostname or IP address, transport protocol, port, service configuration, network binding, firewall rules, and any container or proxy layer between the client and server. Understanding those pieces turns port numbers from a memorization exercise into a practical networking tool.

Found an issue?

Found an error, outdated information, or something missing from this article? Let me know through the Contact page.

Your feedback helps improve our articles and keep them accurate and useful.