What is a port number?

If an IP address finds the server, the port finds the right program on it. The common ports, and how to see which ones are open.

2–3 minutes
Blue network cable with an RJ45 plug on a white background

An IP address gets data to the right machine. A port number gets it to the right program on that machine. A single server can run a website, SSH and a database at once, each listening on its own port.

A port number identifies which program on a server should receive a connection. The IP address gets traffic to the right machine; the port gets it to the right service on that machine, such as 443 for HTTPS or 22 for SSH.

Think of the IP address as a building’s street address and the port as the flat number. One server can run a website, SSH, a database and email at the same time because each listens on its own port.

Common ports

PortUsed by
22SSH and SFTP
25Email between mail servers (SMTP)
53DNS
80HTTP
443HTTPS
465, 587Email sent from mail apps (SMTP submission)
993IMAP over TLS (reading email)
3306MySQL and MariaDB
5432PostgreSQL
6379Redis

Ports run from 0 to 65535. Browsers assume port 80 for http:// and 443 for https://, which is why you rarely see them in addresses. You can name a port explicitly: http://example.com:8080.

TCP and UDP

Each port number exists twice: once for TCP and once for UDP. TCP sets up a connection and guarantees data arrives complete and in order, which suits web pages, SSH and email. UDP sends without a connection or guarantees, which suits DNS lookups, video calls and games, where speed matters more than the odd lost packet. HTTP/3 also runs over UDP. Firewall rules name the protocol: 443/tcp and 443/udp are separate.

Ranges

RangeNameUsed for
0 to 1023Well-known portsStandard services; only root can listen on them
1024 to 49151Registered portsSpecific applications, such as 3306 for MySQL
49152 to 65535Dynamic portsTemporary ports your computer uses for its side of outgoing connections

When your browser connects to a server’s port 443, your own computer uses a random dynamic port for its end. That is why firewalls normally allow outgoing traffic and only restrict incoming.

Listening and open

A program listens on a port. A firewall decides whether outsiders may reach it. A database listening on 3306 should usually be reachable only from the server itself, not from the internet.

See what is listening

On a Linux server:

sudo ss -tlnp

This lists TCP ports that programs are listening on, with the program names. An address of 127.0.0.1 means local only; 0.0.0.0 or * means every network.

Changing a service’s port

Most services let you choose their port. Moving SSH from 22 to another number cuts down log noise from bots, though it is not real security on its own; SSH keys are. If you change a port, update the firewall first, and on AlmaLinux, Rocky and RHEL, tell SELinux too.

App servers such as Node.js often listen on ports like 3000 or 8080 because ports below 1024 need root. In production, put Nginx in front on 80 and 443 as a reverse proxy, rather than exposing the app’s port.

Test from outside

nc -zv 203.0.113.10 443

succeeded means the port is reachable. A timeout usually means a firewall; refused means nothing is listening. See ERR_CONNECTION_REFUSED.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.