18 Common Network Ports
Eighteen common network ports and the protocols and services they expose.
Port numbers are a crude but useful map of network intent. They do not guarantee what service is running, yet they often provide the first clue when you are reading firewall rules, packet captures, or a failing connection string.
-
20. FTP data channel. A reminder that older protocols often split control and data across separate ports, which complicates firewalls and NAT.
-
21. FTP control channel. Still appears in legacy environments even though secure file transfer has largely moved to different protocols.
-
22. SSH. The standard remote shell and secure tunnelling port for Unix-like infrastructure, automation, and Git over SSH.
-
25. SMTP relay. Usually used between mail servers rather than by end-user clients, which often submit mail on a different port.
-
53. DNS. Both UDP and TCP matter here: UDP for most lookups, TCP for zone transfers and larger responses.
-
80. HTTP. Even when production traffic is redirected to TLS, port 80 often remains important for redirects and health probes.
-
110. POP3. A legacy mailbox retrieval protocol that still appears in older mail setups and migration projects.
-
123. NTP. Time synchronisation looks boring until clock skew breaks TLS, logs, or distributed coordination.
-
143. IMAP. More capable than POP3 because it treats mail as a synchronised server-side store rather than a simple download queue.
-
161. SNMP. Common in network monitoring and infrastructure management, and often a security concern when exposed carelessly.
-
389. LDAP. Central to directory services, authentication, and enterprise identity integration.
-
443. HTTPS. The default secure web port and the one most likely to hide several protocols behind TLS and modern reverse proxies.
-
465. Implicit TLS for SMTP. Historically messy, but still encountered in mail client configuration.
-
587. Mail submission. Usually the correct choice for authenticated client-to-server email sending.
-
993. IMAPS. IMAP wrapped in TLS, commonly used by mail clients that need secure mailbox access.
-
995. POP3S. The TLS-wrapped version of POP3, relevant mostly in older but still operational environments.
-
3306. MySQL and MariaDB. Useful to recognise quickly because exposing it publicly is rarely a good sign.
-
5432. PostgreSQL. One of the most common database ports in cloud and on-premise systems, and a frequent source of connection and firewall debugging.
Knowing ports does not replace protocol knowledge, but it speeds up triage. When you can identify likely intent from a socket, you get to the real debugging question faster: who should be speaking on that port, and why are they not agreeing?