OmniTools Logo
OmniTools
All Tools/Network & Privacy/Common Network Ports & Security Reference
Network & PrivacyPOPULARNEW

Free Common Ports & Network Protocol Lookup Tool Online

Search a bundled IANA port reference by number or service, then review transport assignments and practical security guidance. This is not a port scanner.

🔒Inputs are processed on your device. Works offline after loading.

223 matching ports · 223 bundled entries · IANA snapshot 2026-10-03

1 · tcpmux

TCP/UDP

TCP Port Service Multiplexer

IANA names: tcpmux

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

7 · echo

TCP/UDP

Echo

IANA names: echo

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

9 · discard

TCP/UDP

Discard

IANA names: discard

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

13 · daytime

TCP/UDP

Daytime

IANA names: daytime

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

17 · qotd

TCP/UDP

Quote of the Day

IANA names: qotd

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

19 · chargen

TCP/UDP

Character Generator

IANA names: chargen

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

20 · ftp-data

TCP/UDP

File Transfer [Default Data]

IANA names: ftp-data

Security guidance: FTP data can be cleartext. Prefer encrypted transfer and restrict data channels.

21 · ftp

TCP/UDP

File Transfer Protocol [Control]

IANA names: ftp

Security guidance: FTP login and transfers may be cleartext. Prefer SFTP or properly configured FTPS.

22 · SSH

TCP/UDP

The Secure Shell (SSH) Protocol

IANA names: ssh

Security guidance: Use strong authentication, patch SSH, and restrict management sources.

23 · Telnet

TCP/UDP

Telnet

IANA names: telnet

Security guidance: Telnet is cleartext. Replace remote administration with SSH (22).

25 · SMTP

TCP/UDP

Simple Mail Transfer

IANA names: smtp

Security guidance: Restrict mail relay and require suitable transport security; do not run an open relay.

37 · time

TCP/UDP

Time

IANA names: time

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

42 · name / nameserver

TCP/UDP

Host Name Server

IANA names: name, nameserver

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

43 · nicname

TCP/UDP

Who Is

IANA names: nicname

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

49 · tacacs

TCP/UDP

Login Host Protocol (TACACS)

IANA names: tacacs

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

53 · DNS

TCP/UDP

Domain Name Server

IANA names: domain

Security guidance: Restrict recursive DNS to authorized clients to reduce amplification abuse.

67 · bootps

TCP/UDP

Bootstrap Protocol Server

IANA names: bootps

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

68 · bootpc

TCP/UDP

Bootstrap Protocol Client

IANA names: bootpc

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

69 · tftp

TCP/UDP

Trivial File Transfer

IANA names: tftp

Security guidance: TFTP lacks built-in authentication and encryption; isolate provisioning networks.

70 · gopher

TCP/UDP

Gopher

IANA names: gopher

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

79 · finger

TCP/UDP

Finger

IANA names: finger

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

80 · HTTP

TCP/UDP

World Wide Web HTTP

IANA names: http, www, www-http

Security guidance: HTTP is unencrypted. Redirect sensitive web traffic to HTTPS.

88 · kerberos

TCP/UDP

Kerberos

IANA names: kerberos

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

102 · iso-tsap

TCP/UDP

ISO-TSAP Class 0

IANA names: iso-tsap

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

109 · pop2

TCP/UDP

Post Office Protocol - Version 2

IANA names: pop2

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

110 · pop3

TCP/UDP

Post Office Protocol - Version 3

IANA names: pop3

Security guidance: Require TLS-protected mail authentication instead of cleartext POP3.

111 · sunrpc

TCP/UDP

SUN Remote Procedure Call

IANA names: sunrpc

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

113 · ident / auth

TCP/UDP

IANA names: ident, auth

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

119 · nntp

TCP/UDP

Network News Transfer Protocol

IANA names: nntp

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

123 · ntp

TCP/UDP

Network Time Protocol

IANA names: ntp

Security guidance: Restrict NTP control functions and keep implementations patched.

135 · epmap

TCP/UDP

DCE endpoint resolution

IANA names: epmap

Security guidance: Do not expose Windows RPC broadly; limit access to trusted networks.

137 · netbios-ns

TCP/UDP

NETBIOS Name Service

IANA names: netbios-ns

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

138 · netbios-dgm

TCP/UDP

NETBIOS Datagram Service

IANA names: netbios-dgm

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

139 · netbios-ssn

TCP/UDP

NETBIOS Session Service

IANA names: netbios-ssn

Security guidance: Restrict legacy NetBIOS services to trusted segments.

143 · imap

TCP

Internet Message Access Protocol

IANA names: imap

Security guidance: Require IMAP encryption; prefer IMAPS or enforced STARTTLS.

161 · snmp

TCP/UDP

SNMP

IANA names: snmp

Security guidance: Use SNMPv3 authentication and privacy; restrict management access.

162 · snmptrap

TCP/UDP

SNMPTRAP

IANA names: snmptrap

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

163 · cmip-man

TCP/UDP

CMIP/TCP Manager

IANA names: cmip-man

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

164 · cmip-agent

TCP/UDP

CMIP/TCP Agent

IANA names: cmip-agent

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

174 · mailq

TCP/UDP

MAILQ

IANA names: mailq

Security guidance: A port assignment does not identify the running service or prove safety. Restrict access, verify authentication and encryption, and patch the actual application.

A registry assignment is not a port scan or vulnerability finding. TCP/UDP means both transports appear in the registry, not that every deployment uses both. Service aliases can differ by transport.

Port Ranges Explained: Well-Known vs. Registered vs. Dynamic Ports

Transport-layer ports help distinguish services sharing an IP address. IANA port numbers are divided into well-known ports 0-1023, registered or user ports 1024-49151, and dynamic private ports 49152-65535. A number is interpreted together with its transport protocol: TCP 53 and UDP 53 are separate assignments. Applications can also be configured on nonstandard numbers. This reference searches a curated static dictionary rather than connecting to a host, so a match cannot tell you whether anything is listening on your network.

TCP provides an ordered byte stream with connection management and retransmission, while UDP provides datagrams without those stream guarantees. Neither transport alone determines whether application content is encrypted. Protocols such as TLS and QUIC supply security at other layers. The TCP/UDP badge means the bundled IANA records include both transports, not that a particular product supports both or uses them identically. Read the service names and actual configuration before translating a reference entry into firewall rules.

Top 20 Critical Ports and Their Security Risks

Port exposure should follow the service’s purpose and trust boundaries. HTTP on 80 is ordinarily cleartext, while HTTPS on 443 uses TLS but can still host vulnerable application code. Telnet on 23 should not carry remote-administration credentials across untrusted networks. Database services such as MySQL, PostgreSQL, Redis, and MongoDB generally need restricted access rather than broad public exposure. Remote desktop should use controlled access, strong authentication, and current patches. The table below is a starting point for review, not a vulnerability scan.

Encrypted vs unencrypted protocols cannot always be distinguished from a number alone: some services negotiate STARTTLS, use a tunnel, or run on an alternate port. Port vulnerabilities depend on software versions, configuration, authentication, and the reachable network path. Keep only necessary listeners enabled, limit source addresses where appropriate, and verify both IPv4 and IPv6 firewall policy. The bundled snapshot can become outdated, and security notes are general operational guidance. Check the authoritative service documentation before changing production access or assuming that an unfamiliar port is malicious.

Top 20 Critical Ports and Their Security Risks

Top 20 Critical Ports and Their Security Risks
PortProtocolDefault ServiceSecurity Best Practice
21TCPFTPPrefer encrypted file transfer
22TCPSSHRestrict sources and use strong authentication
23TCPTelnetReplace cleartext administration
25TCPSMTPPrevent open relays
53TCP/UDPDNSRestrict recursive service
67/68UDPDHCPRestrict to intended local links
80TCPHTTPRedirect sensitive traffic to HTTPS
110TCPPOP3Require transport encryption
123UDPNTPRestrict control queries
135TCPRPCKeep management internal
139TCPNetBIOSLimit legacy exposure
143TCPIMAPEnforce TLS
161UDPSNMPUse SNMPv3 and access controls
389TCPLDAPProtect directory access
443TCP/UDPHTTPS / QUICPatch application and validate TLS
445TCPSMBRestrict trusted networks
3306TCPMySQLRestrict database clients
3389TCP/UDPRDPUse controlled access and MFA
5432TCPPostgreSQLReview authentication rules
6379TCPRedisRequire ACLs and restricted access

Technical references

How to use Common Network Ports & Security Reference

  1. 1. Enter the input

    Enter a port number or service name such as SSH, HTTPS, MySQL, or RDP. Numeric searches match the exact port.

  2. 2. Inspect the local result

    Choose Web, Database, Mail, or Remote Access to browse a focused group. Filters clear the previous query to show their complete preset.

  3. 3. Apply the result carefully

    Read the transport, assigned service names, and security guidance. Verify the real application and authorized access requirements before changing firewall rules.

Key features and technical specifications

Local processing

Inputs stay in browser memory; no query or certificate is sent to a processing service.

Explicit limits

Results describe supplied data and bundled references, not live network measurements.

Use this result with its limits in mind

These tools transform supplied data locally. They do not scan devices, verify ownership, or confirm that a network service is secure.

Prepare configuration notes

Copy normalized values and check their meaning before applying a production change.

Learn protocol representations

Compare the examples and reference table with the interactive result.

Frequently asked questions

What is the difference between TCP and UDP ports?

The same numeric port belongs to distinct TCP and UDP namespaces. TCP offers a reliable ordered stream; UDP sends individual datagrams. An application may use one or both. A firewall allowance for one transport does not automatically allow the other.

Which ports should never be exposed to the public internet?

There is no universal safe list based only on numbers. Avoid public access to unauthenticated management interfaces, cleartext remote administration, and databases intended for internal use. Review the actual application, authentication, source restrictions, and deployment architecture before opening a service.

Does port 443 mean a connection is safe?

No. It commonly indicates HTTPS, but any application can listen on a chosen port. Even a valid TLS connection can serve malicious or vulnerable content. Verify the hostname, certificate validation, application behavior, and authorization instead of relying on the number alone.

Why does my port search return no result?

This dictionary contains a curated selection rather than every IANA assignment or locally chosen service. An empty result does not mean the port is available, closed, or harmless. Inspect your device’s listening processes and consult the full registry when needed.

Does this tool scan my network or send the query away?

No. Number, name, and quick-filter searches run over bundled client-side JSON. No socket is opened to test a listener and the search text is not uploaded. Use an authorized diagnostic tool separately if you need actual reachability information.