Port Number Lookup
What runs on a port, what IANA says about it, and whether it should face the internet.
Searches a copy of the IANA port registry in your browser. Nothing is scanned or contacted.
Results
IANA registry
Common ports and whether to expose them
- Public service Normal to open to the internet when you deliberately run this service. Keep it patched.
- Limit access Meant for remote use, but allow only known addresses, a VPN or strong authentication.
- Internal only Should never be reachable from the internet.
- Avoid Insecure or obsolete: turn it off or replace it with the secure alternative.
| Port | Service | Exposure | Used for · risks |
|---|---|---|---|
| Web | |||
| TCP | HTTP | Public service | Unencrypted web traffic. Today it mostly redirects to HTTPS and answers ACME HTTP-01 certificate checks (RFC 8555). Anything sent over it can be read and changed in transit — redirect to HTTPS. |
| TCP/UDP | HTTPS | Public service | Encrypted web traffic (HTTP over TLS); UDP 443 carries HTTP/3 over QUIC (RFC 9114). The application behind it sets the risk: keep web servers, CMSs and their admin pages patched. |
| TCP | HTTP alternate | Limit access | Web proxies, application servers (Apache Tomcat’s default HTTP port) and development servers. Often an admin console or test server that was never meant to be public. |
| TCP | HTTPS alternate | Limit access | HTTPS for admin interfaces and application servers (registered in IANA as pcsync-https). Frequently the management page of a firewall, controller or appliance — allow only administrators. |
| TCP | Development web server | Limit access | Development servers, such as the default of Python’s http.server and Django’s runserver. Development servers often list files and have no authentication. |
| TCP | Jupyter / dev servers | Limit access | Jupyter Notebook and JupyterLab default to 8888; also proxies and test servers. An exposed notebook server can run any code on the machine. |
| TCP | Grafana / Node.js dev | Limit access | Grafana’s default port and many Node.js and React development servers. Dashboards and dev servers leak data if left open. |
| TCP | Flask / AirPlay | Limit access | Flask’s development server; Apple also lists TCP 5000 and 7000 for AirPlay (support article 103229), so a Mac’s AirPlay Receiver may already be using it. A development server is not built to face the internet. |
| Remote access | |||
| TCP | SSH | Limit access | Secure Shell: remote command line, SFTP and SCP file transfer, Git over SSH. Brute-forced constantly. Use keys instead of passwords, disable root login and password login, or allow only known addresses. |
| TCP | Telnet | Avoid | Unencrypted remote login, still found on old routers, switches and IoT devices. Passwords travel in clear text. The Mirai botnet (2016) spread by logging in over Telnet (ports 23 and 2323) with default passwords. Disable it and use SSH. |
| TCP/UDP | RDP | Limit access | Microsoft Remote Desktop (registered in IANA as ms-wbt-server). A favourite entry point for ransomware through brute force and stolen passwords; BlueKeep (CVE-2019-0708) allowed remote code execution on unpatched systems. Put it behind a VPN or a gateway with MFA. |
| TCP | VNC | Limit access | VNC remote desktop (the RFB protocol); 5901 and up for more displays. Many VNC servers accept weak or no passwords and do not encrypt. Tunnel it through SSH or a VPN. |
| TCP | WinRM (HTTP) | Internal only | Windows Remote Management and PowerShell remoting. Full remote administration of Windows machines: keep it on management networks. |
| TCP | WinRM (HTTPS) | Internal only | Windows Remote Management over TLS. Encrypted, but still full remote administration — management networks only. |
| TCP | X11 | Avoid | X Window System display server (6000 plus the display number). An open X server lets others capture the screen and keystrokes. Use SSH X forwarding instead. |
| TCP | Webmin | Limit access | Webmin’s default web admin interface (registered in IANA as ndmp, the Network Data Management Protocol). Gives full control of the server. CVE-2019-15107, a command injection in Webmin up to 1.920, is in CISA’s Known Exploited Vulnerabilities catalog. Allow only admin networks. |
| TCP | SMTP | Public service | Mail transfer between mail servers (the MX of a domain). Needed only on mail servers. Misconfigured open relays are abused for spam, and many providers block outgoing port 25 from home connections. |
| TCP | SMTP submission (TLS) | Public service | Sending mail from apps and mail clients over implicit TLS (RFC 8314). Requires authentication; watch for password guessing against mail accounts. |
| TCP | SMTP submission | Public service | Sending mail from apps and mail clients with STARTTLS and authentication (RFC 6409). Requires authentication; watch for password guessing against mail accounts. |
| TCP | POP3 | Avoid | Downloading mail without encryption. Credentials and mail in clear text — use POP3S on 995. |
| TCP | POP3S | Public service | POP3 over TLS. Use strong passwords or app passwords; disable it if nobody uses POP. |
| TCP | IMAP | Avoid | Mail access, unencrypted unless STARTTLS is used. Prefer IMAPS on 993: RFC 8314 recommends implicit TLS. |
| TCP | IMAPS | Public service | IMAP over TLS — how mail apps read mailboxes. Use strong passwords or app passwords and MFA where possible. |
| DNS, time and network services | |||
| TCP/UDP | DNS | Public service | Domain Name System: authoritative name servers and resolvers. Large answers and zone transfers use TCP. Authoritative servers must be reachable; recursive resolvers should answer only your own users — open resolvers are abused for amplification DDoS. |
| TCP/UDP | DNS over TLS / QUIC | Public service | Encrypted DNS: DNS over TLS (RFC 7858) on TCP and DNS over QUIC (RFC 9250) on UDP. Same rule as DNS: run an open resolver only on purpose. |
| UDP | NTP | Limit access | Network Time Protocol: clock synchronisation. Old servers answering the “monlist” query (CVE-2013-5211) were used for huge amplification attacks. Run current software and serve only who needs it. |
| UDP | DHCP | Internal only | DHCP: server on 67, client on 68 — handing out IPv4 addresses. Local networks only; a rogue DHCP server can redirect a network’s traffic. |
| UDP | DHCPv6 | Internal only | DHCPv6: client on 546, servers and relays on 547. Local networks only; filter rogue DHCPv6 servers on switches. |
| UDP | TFTP | Internal only | Trivial FTP for network boot (PXE), IP phones and device firmware or configuration. No authentication at all: keep it on isolated provisioning networks. |
| UDP | SNMP | Internal only | SNMP queries to routers, switches, printers and servers. SNMPv1/v2c “community strings” (often public) are sent in clear text, and open agents are abused for amplification. Use SNMPv3 on a management network. |
| UDP | SNMP traps | Internal only | Alerts sent by devices to a monitoring system. Management networks only. |
| UDP | Syslog | Internal only | Log messages over UDP. (On TCP, 514 is rsh, a legacy clear-text remote shell.) Unencrypted and unauthenticated; across untrusted networks use syslog over TLS on 6514. |
| TCP | Syslog over TLS | Internal only | Encrypted log transport (RFC 5425). Accept only your own log sources. |
| TCP | BGP | Limit access | Border Gateway Protocol sessions between routers. Allow only configured peers, and protect sessions with TCP-AO or MD5 and TTL security (RFC 5082). |
| UDP | RIP | Internal only | RIP routing updates. Unauthenticated RIP can be spoofed to redirect traffic. |
| UDP | SSDP / UPnP | Internal only | UPnP device discovery: smart TVs, media servers, routers. Exposed SSDP is abused for reflection DDoS; turn off UPnP on internet-facing interfaces. |
| UDP | mDNS | Internal only | Multicast DNS — Bonjour, Avahi, AirPlay and Chromecast discovery (RFC 6762). Meant for the local link only; answering from the internet leaks device details and enables reflection. |
| TCP/UDP | LLMNR | Internal only | Link-Local Multicast Name Resolution in Windows. Spoofed answers (for example with the Responder tool) capture Windows password hashes; many networks disable LLMNR. |
| TCP/UDP | NetBIOS | Internal only | NetBIOS name (137/udp), datagram (138/udp) and session (139/tcp) services of older Windows networking. Never expose: it reveals machine names and shares and can lead to SMB attacks. |
| UDP | WS-Discovery | Internal only | Web Services Discovery used by Windows, printers and IP cameras. Exposed devices have been abused for reflection attacks. |
| File sharing and storage | |||
| TCP | FTP | Avoid | File Transfer Protocol: control on 21, data on 20 in active mode. Logins and files travel in clear text. Use SFTP (over SSH, port 22) or FTPS. |
| TCP | FTPS (implicit TLS) | Limit access | FTP over TLS: data on 989, control on 990. Encrypted, but FTP’s extra data connections complicate firewalls; SFTP is usually simpler. |
| TCP | Simple File Transfer Protocol | Avoid | An obsolete 1984 protocol (RFC 913). Not the SSH File Transfer Protocol: SFTP uses port 22. Should not be in use. |
| TCP | SMB | Internal only | Windows file and printer sharing and Active Directory (registered in IANA as microsoft-ds). Never expose: EternalBlue (MS17-010) let WannaCry and NotPetya spread through SMB in 2017. |
| TCP/UDP | NFS | Internal only | Network File System shares. Exports trust client addresses; keep NFS on storage networks. |
| TCP/UDP | rpcbind | Internal only | Sun RPC port mapper, needed by NFSv3 and other RPC services. It lists the RPC services of a host and has been abused for reflection attacks. |
| TCP | AFP | Internal only | Apple Filing Protocol, legacy Apple file sharing (current macOS shares over SMB). Legacy protocol: local networks only. |
| TCP | rsync | Internal only | The rsync daemon for file synchronisation. Modules without authentication have leaked entire file systems. Run rsync over SSH instead. |
| TCP | iSCSI | Internal only | iSCSI block storage. Storage traffic belongs on an isolated storage network. |
| TCP | Git protocol | Limit access | The git:// daemon: unauthenticated and unencrypted, read-only by default. Fine for public read-only mirrors; use HTTPS or SSH for anything private. |
| Databases and queues | |||
| TCP | Microsoft SQL Server | Internal only | Microsoft SQL Server database engine (default instance). Exposed servers are brute-forced constantly; reach the database through the application or a VPN. |
| UDP | SQL Server Browser | Internal only | SQL Server Browser / Resolution Service. The SQL Slammer worm (2003) spread through UDP 1434. |
| TCP | MySQL / MariaDB | Internal only | MySQL and MariaDB databases (their default port). Exposed databases are brute-forced and dumped. Bind to localhost or a private network. |
| TCP | PostgreSQL | Internal only | PostgreSQL relational database (its default port). Allow only application servers; use TLS and scram-sha-256 passwords. |
| TCP | Oracle Database | Internal only | Oracle Database listener (registered in IANA as ncube-lm). Internal only. |
| TCP | MongoDB | Internal only | MongoDB document database (its default port). In January 2017 attackers wiped thousands of MongoDB databases that were open without a password and demanded ransom. Enable authentication and keep it private. |
| TCP | Redis | Internal only | Redis key-value store and cache (its default port). Older Redis versions had no password by default; attackers use exposed instances to read data and plant SSH keys or cron jobs. |
| TCP/UDP | Memcached | Internal only | Memcached object cache. Exposed UDP memcached powered record amplification attacks in 2018, including 1.35 Tbps against GitHub; memcached 1.5.6 turned UDP off by default. |
| TCP | Elasticsearch / OpenSearch | Internal only | Elasticsearch and OpenSearch REST API (registered in IANA as wap-wsp). Unprotected clusters are behind many large data leaks. |
| TCP | Elasticsearch transport | Internal only | Elasticsearch node-to-node traffic. Cluster traffic: internal only. |
| TCP | CouchDB | Internal only | Apache CouchDB HTTP API. Create an admin account and keep it private. |
| TCP | Cassandra | Internal only | Apache Cassandra native protocol (CQL). Not an IANA assignment. Internal only; enable authentication. |
| TCP | InfluxDB | Internal only | InfluxDB HTTP API (registered in IANA as d-s-n). Internal only; require tokens. |
| TCP | ZooKeeper | Internal only | Apache ZooKeeper client port (registered in IANA as eforward). Holds cluster configuration and secrets of Kafka and similar systems. |
| TCP | Apache Kafka | Internal only | Kafka brokers (registered in IANA as XmlIpcRegSvc). Internal only, with TLS and authentication between clients and brokers. |
| TCP | AMQP / RabbitMQ | Internal only | AMQP message brokers such as RabbitMQ. Remove default guest accounts; internal only. |
| TCP | RabbitMQ management | Internal only | RabbitMQ management web UI and API. Not an IANA assignment. Administrative access to the broker: internal only. |
| TCP | ActiveMQ | Internal only | Apache ActiveMQ OpenWire protocol (dynamic range, not an IANA assignment). CVE-2023-46604 allows remote code execution on exposed brokers; CISA lists it as exploited, including in ransomware campaigns. |
| TCP | Erlang EPMD | Internal only | Erlang Port Mapper Daemon, used by RabbitMQ and CouchDB clusters. Together with the Erlang distribution port and a guessable cookie it allows remote code execution. |
| Directory and authentication | |||
| TCP/UDP | Kerberos | Internal only | Kerberos authentication, the core of Active Directory logins. Never expose domain controllers; inside networks, attacks such as Kerberoasting target it. |
| TCP/UDP | LDAP | Internal only | LDAP directory queries, including Active Directory. Connectionless LDAP (CLDAP, UDP 389) exposed to the internet is abused for amplification DDoS. |
| TCP | LDAPS | Internal only | LDAP over TLS. Internal only. |
| TCP | AD Global Catalog | Internal only | Active Directory global catalog (3269 with TLS). Internal only. |
| TCP/UDP | Kerberos password change | Internal only | kpasswd: changing Kerberos passwords. Internal only. |
| TCP | Microsoft RPC | Internal only | Microsoft RPC endpoint mapper (DCOM, WMI, Active Directory). Never expose; the Blaster worm (2003) spread through it. |
| UDP | RADIUS | Internal only | RADIUS authentication (1812) and accounting (1813) for Wi-Fi, VPN and network device logins. Blast-RADIUS (CVE-2024-3596) showed that RADIUS over UDP can be forged by an attacker on the path. Use it only on trusted networks or over TLS (RadSec). |
| TCP | TACACS+ | Internal only | TACACS+ logins and command authorisation on network devices. Management networks only. |
| VPNs, proxies and tunnels | |||
| UDP | IKE (IPsec) | Public service | IPsec VPN key exchange (ISAKMP/IKE). Open on VPN gateways only — and patch them promptly: VPN appliances are a frequent target. |
| UDP | IPsec NAT traversal | Public service | IPsec through NAT (ESP in UDP). Open on VPN gateways only. |
| TCP/UDP | OpenVPN | Public service | OpenVPN’s registered port. Use certificates and keep the server updated. |
| UDP | WireGuard | Public service | WireGuard’s conventional listen port. It lies in the dynamic range, so it is not an IANA assignment. WireGuard does not answer packets without a valid key, so an open port reveals little. |
| UDP | L2TP | Avoid | Layer 2 Tunnelling Protocol, normally combined with IPsec. Legacy VPN; prefer IKEv2, WireGuard or OpenVPN. |
| TCP | PPTP | Avoid | Point-to-Point Tunnelling Protocol VPN. Its MS-CHAPv2 authentication is broken. Do not use PPTP. |
| TCP | SOCKS proxy | Limit access | SOCKS proxies. An open proxy lets anyone send traffic from your address. |
| TCP | Squid proxy | Limit access | Squid web proxy’s default port (registered in IANA as ndl-aas). An open proxy is abused within hours; allow only your own networks. |
| TCP | Tor SOCKS | Internal only | The Tor client’s local SOCKS port (registered in IANA as versiera). Should listen on localhost only. |
| TCP/UDP | STUN / TURN | Public service | STUN and TURN for WebRTC, VoIP and video calls (5349 with TLS or DTLS). Restrict TURN relays to authenticated users and block relaying to internal addresses. |
| Voice, chat and IoT messaging | |||
| TCP/UDP | SIP | Limit access | SIP signalling for VoIP phones and trunks (5061 with TLS). Scanned constantly for toll fraud: allow only your provider’s addresses and use strong passwords. |
| TCP | XMPP | Public service | XMPP (Jabber) chat: clients on 5222, server-to-server on 5269. Require TLS and disable open registration unless wanted. |
| TCP | MQTT | Internal only | MQTT messaging for IoT devices, without TLS. Exposed brokers often allow anonymous access to device data and commands. Use 8883 with authentication. |
| TCP | MQTT over TLS | Limit access | MQTT with TLS. Require client authentication. |
| TCP | IRC | Limit access | Internet Relay Chat (6697 with TLS). Long used for botnet command and control — unexpected IRC traffic from a server is a warning sign. |
| UDP | CoAP | Internal only | Constrained Application Protocol for IoT devices. Exposed CoAP devices can be abused for reflection attacks. |
| Containers and orchestration | |||
| TCP | Docker API (no TLS) | Avoid | Docker Engine API without encryption or authentication. Whoever reaches it controls the host — exposed Docker APIs are routinely hijacked for crypto-mining. Never expose it. |
| TCP | Docker API (TLS) | Limit access | Docker Engine API with TLS client certificates. Equivalent to root on the host: restrict to administrators. |
| TCP | Docker Swarm | Internal only | Docker Swarm cluster management. Cluster traffic: internal only. |
| TCP | Kubernetes API | Limit access | Kubernetes API server (registered in IANA as sun-sr-https). Allow only administrators and CI; keep anonymous access disabled. |
| TCP | Kubelet API | Internal only | The kubelet on every Kubernetes node. Not an IANA assignment. With anonymous access enabled it lets anyone run commands in containers. |
| TCP | etcd | Internal only | etcd client (2379) and peer (2380) ports; Kubernetes keeps its state and secrets there. Access to etcd is access to every secret in the cluster. |
| TCP | Consul | Internal only | HashiCorp Consul HTTP API and UI (registered in IANA as fmtp). Enable ACLs; internal only. |
| Monitoring and management | |||
| TCP | Prometheus | Internal only | Prometheus server (registered in IANA as websm). Metrics reveal infrastructure details: internal only. |
| TCP | Printing / node exporter | Internal only | Raw printing to network printers (JetDirect / PDL data stream) and the Prometheus node exporter. Printers accept jobs and commands from anyone who reaches them. |
| TCP | Kibana | Internal only | Kibana dashboards for Elasticsearch (registered in IANA as esmagent). Shows everything in the cluster: internal only or behind single sign-on. |
| TCP | MikroTik Winbox | Limit access | MikroTik router management with Winbox. Not an IANA assignment. CVE-2018-14847 let unauthenticated attackers read any file on the router through Winbox and has been exploited in the wild (CISA KEV). Allow only management addresses. |
| TCP | TR-069 (CWMP) | Internal only | Internet providers managing customers’ home routers remotely. In 2016 a Mirai variant attacking this port knocked about 900,000 Deutsche Telekom routers offline. Reachable only from the provider. |
| TCP/UDP | IPP / CUPS | Internal only | Internet Printing Protocol and the CUPS print system. In 2024 flaws in cups-browsed on UDP 631 (CVE-2024-47176 and related) enabled remote code execution. Block 631 from the internet. |
| TCP | LPD | Internal only | Line Printer Daemon printing. Legacy printing: internal only. |
| Industrial and building control, cameras | |||
| TCP | Modbus/TCP | Internal only | Modbus industrial control (PLCs, meters, drives). No authentication at all: anyone who reaches it can read and write controller values. Never expose control systems. |
| TCP | Siemens S7 (ISO-TSAP) | Internal only | Siemens S7 PLC communication over ISO-TSAP. Control systems belong on isolated networks. |
| TCP | DNP3 | Internal only | DNP3 for electricity and water utilities. Control systems belong on isolated networks. |
| TCP/UDP | EtherNet/IP | Internal only | EtherNet/IP (CIP) industrial devices. Control systems belong on isolated networks. |
| UDP | BACnet | Internal only | BACnet building automation: heating, ventilation, lighting, access control. Exposed building controllers can be read and switched remotely. |
| TCP | RTSP | Internal only | Video streams from IP cameras and recorders. Exposed cameras often accept default passwords; view them through a VPN or the vendor’s cloud. |
| Games and peer-to-peer | |||
| TCP | Minecraft | Public service | Minecraft Java Edition servers. Not an IANA assignment. Keep the server software and plugins updated. |
| TCP/UDP | Steam / Source | Public service | Steam and Source-engine game servers such as Counter-Strike. Not an IANA assignment. Open it only while you host a server. |
| TCP/UDP | Xbox network | Public service | Xbox online multiplayer. Usually opened automatically by UPnP on home routers. |
| TCP/UDP | BitTorrent | Limit access | BitTorrent’s traditional ports; modern clients pick random ports. Unexpected BitTorrent traffic on a work network usually breaks policy. |
| Other | |||
| TCP | Metasploit listener | Avoid | The default listening port of Metasploit payloads (registered in IANA as krb524). Unexpected traffic on 4444 is a classic sign of a reverse shell. |
About the Port Number Lookup
Type a port number, a range or a service name to see what the IANA Service Name and Transport Protocol Port Number Registry — the official list behind “port 443 is HTTPS” — says about it, for TCP, UDP, SCTP and DCCP. The search runs on a copy of the registry in your browser (it is loaded the first time you search and then works offline), including registered ranges, reserved and unassigned ports, references and the unauthorized uses IANA has recorded.
For more than 100 commonly seen ports there are practical notes: what actually uses the port today (which is not always what IANA registered), whether it is normal to open it to the internet, and the attacks it is known for. The tool never scans or contacts anything — it is a reference.
How to use it
- Type a port (
3389), a port with a protocol (udp 53or443/tcp), a range (8000-8100) or a service name (ssh,postgresql,remote desktop). - Untick protocols you are not interested in to narrow the list.
- Read the note at the top for common ports — what uses the port and whether it should be reachable from the internet.
- Check the IANA entries below it: the registered service name, description, reference and notes.
- Browse the Common ports table by category, or press a port in it to look it up.
Examples
3389
IANA: ms-wbt-server (TCP, UDP) — MS WBT Server Note: Microsoft Remote Desktop · Limit access — put it behind a VPN or a gateway with MFA
postgresql
5432 · TCP · UDP · postgresql — PostgreSQL Database
51820
Dynamic port (49152–65535): no IANA entry Note: WireGuard’s conventional listen port
Common uses
- Finding out what an unfamiliar port in a firewall log, netstat output or scan report is used for.
- Choosing which ports to open on a server — and which to keep closed — when writing firewall rules or cloud security groups.
- Picking a free port number for a new service without colliding with a registered one.
- Looking up the port of a protocol while configuring a client, proxy or SRV record.
The three port ranges
TCP, UDP, SCTP and DCCP each have 65,536 port numbers, divided by RFC 6335 into:
- System (well-known) ports, 0–1023: assigned by IANA only through IETF review or IESG approval. On Linux, binding to one needs root or the
CAP_NET_BIND_SERVICEcapability by default (Linux kernel ip-sysctl documentation). - User (registered) ports, 1024–49151: assigned by IANA on request, so applications can use a fixed number.
- Dynamic (private or ephemeral) ports, 49152–65535: never assigned. Software may use them freely, and operating systems pick the source port of outgoing connections from an ephemeral range: Linux uses 32768–60999 by default (ip_local_port_range), and Windows has used 49152–65535 since Windows Vista (Microsoft). RFC 6056 recommends choosing from the whole 1024–65535 range, for better randomisation.
An assignment is a convention, not a rule: any program can listen on any free port, and malware often uses well-known ports to blend in.
Reading an IANA entry
- Service name: the registered short name, also used in DNS SRV records (
_sip._tcp) — you can search for those too. - Protocols: a service is often registered on TCP and UDP even when it uses only one of them.
- Reference: the RFC or contact that requested the assignment; RFCs are linked.
- Notes and unauthorized use: IANA records de-assignments, aliases and reports of software using a port it was not assigned.
The snapshot was downloaded from the IANA registry.
Should this port be open to the internet?
The notes use four labels: Public service (normal to expose if you deliberately run it — web, mail, DNS, VPN endpoints), Limit access (built for remote use, but restrict who can connect — SSH, RDP, admin consoles), Internal only (databases, file sharing, directory services, industrial controllers) and Avoid (insecure or obsolete protocols such as Telnet, FTP and PPTP).
A safe default for any internet-facing firewall is to block everything inbound and open only the ports of services you actually publish. To check what is reachable on your own systems, run a port scanner such as Nmap against them from outside your network — only on systems you are authorised to test.
Limitations
- A reference, not a scanner: it cannot tell you whether a port is open on any machine.
- Registry data is a snapshot; assignments made since are missing.
- The notes describe typical use and risk, simplified. Your own software may use a port differently.
- The full registry (about 150 KB compressed) is downloaded the first time you search.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
What is the difference between TCP and UDP ports?
They are separate number spaces: TCP port 53 and UDP port 53 are different endpoints. TCP sets up a connection and guarantees delivery and order; UDP sends independent datagrams without either, which suits DNS lookups, streaming, games and QUIC. Many services are registered on both even if they use one.
Which ports should be open on a web server?
Usually only TCP 443 (and UDP 443 if you serve HTTP/3), plus TCP 80 to redirect visitors to HTTPS and to answer certificate checks. Restrict SSH (22) to your own addresses or a VPN, and keep database and admin ports closed to the internet.
What is an ephemeral port?
The temporary source port your computer picks for an outgoing connection, such as the port your browser uses while talking to a website on 443. They come from a dynamic range — 32768–60999 on Linux and 49152–65535 on Windows by default — and are released when the connection ends.
Can this tool check whether a port is open?
No. It never sends anything to any server; it only looks up what a port is registered for. To test your own server, use a port scanner from outside your network, or check the firewall and the listening services (for example with ss -ltnu or netstat).
Why does IANA list a port for something I have never heard of?
Many popular programs use ports registered to someone else — Oracle Database on 1521 (registered as ncube-lm) or Elasticsearch on 9200 (registered as wap-wsp), for example. The notes show the common use next to the official registration.