An IP address gets data to the right machine. A port number gets it to the right program on that machine. A single server can run a website, SSH and a database at once, each listening on its own port.
A port number identifies which program on a server should receive a connection. The IP address gets traffic to the right machine; the port gets it to the right service on that machine, such as 443 for HTTPS or 22 for SSH.
Think of the IP address as a building’s street address and the port as the flat number. One server can run a website, SSH, a database and email at the same time because each listens on its own port.
Common ports
| Port | Used by |
|---|---|
| 22 | SSH and SFTP |
| 25 | Email between mail servers (SMTP) |
| 53 | DNS |
| 80 | HTTP |
| 443 | HTTPS |
| 465, 587 | Email sent from mail apps (SMTP submission) |
| 993 | IMAP over TLS (reading email) |
| 3306 | MySQL and MariaDB |
| 5432 | PostgreSQL |
| 6379 | Redis |
Ports run from 0 to 65535. Browsers assume port 80 for http:// and 443 for https://, which is why you rarely see them in addresses. You can name a port explicitly: http://example.com:8080.
TCP and UDP
Each port number exists twice: once for TCP and once for UDP. TCP sets up a connection and guarantees data arrives complete and in order, which suits web pages, SSH and email. UDP sends without a connection or guarantees, which suits DNS lookups, video calls and games, where speed matters more than the odd lost packet. HTTP/3 also runs over UDP. Firewall rules name the protocol: 443/tcp and 443/udp are separate.
Ranges
| Range | Name | Used for |
|---|---|---|
| 0 to 1023 | Well-known ports | Standard services; only root can listen on them |
| 1024 to 49151 | Registered ports | Specific applications, such as 3306 for MySQL |
| 49152 to 65535 | Dynamic ports | Temporary ports your computer uses for its side of outgoing connections |
When your browser connects to a server’s port 443, your own computer uses a random dynamic port for its end. That is why firewalls normally allow outgoing traffic and only restrict incoming.
Listening and open
A program listens on a port. A firewall decides whether outsiders may reach it. A database listening on 3306 should usually be reachable only from the server itself, not from the internet.
See what is listening
On a Linux server:
sudo ss -tlnp
This lists TCP ports that programs are listening on, with the program names. An address of 127.0.0.1 means local only; 0.0.0.0 or * means every network.
Changing a service’s port
Most services let you choose their port. Moving SSH from 22 to another number cuts down log noise from bots, though it is not real security on its own; SSH keys are. If you change a port, update the firewall first, and on AlmaLinux, Rocky and RHEL, tell SELinux too.
App servers such as Node.js often listen on ports like 3000 or 8080 because ports below 1024 need root. In production, put Nginx in front on 80 and 443 as a reverse proxy, rather than exposing the app’s port.
Test from outside
nc -zv 203.0.113.10 443
succeeded means the port is reachable. A timeout usually means a firewall; refused means nothing is listening. See ERR_CONNECTION_REFUSED.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



