An IP address gets data to the right computer. But that computer is running dozens of programs at once: a browser, a mail app, a database, a chat client, an update service. Something has to decide which program receives which piece of data. That something is the port number, and once you understand it, firewalls, port forwarding, “address already in use” errors and half of the security advice you have ever read start making sense.
The problem ports solve
Think about what happens when you open a website while a video call is running, a music app is streaming and your email is syncing in the background. All of that traffic arrives at your laptop through one network connection, addressed to one IP address. Yet the website data ends up in the browser, the call audio in the call app, and the emails in the mail client. They never get mixed up.
The IP address cannot do that job, because it only identifies the machine. You need a second number that identifies the program or service on that machine. That number is the port.
The one-paragraph version. A port is a 16-bit number, from 0 to 65535, that tells the receiving computer which program or service should get the incoming data. An IP address is the building, and the port is the apartment number. Web servers conventionally listen on 80 (HTTP) and 443 (HTTPS), and remote-login servers on 22 (SSH). A connection is identified by the pair of IP addresses plus the pair of port numbers, which is how thousands of conversations share one network card without colliding.
An everyday analogy: the apartment building
Imagine you send a parcel to “42 Mall Road.” The courier finds the building, which is what an IP address does. But 42 Mall Road is an apartment block with a hundred flats. Without a flat number the parcel sits in the lobby. Write “Flat 443” on it and the right resident receives it.
The analogy also explains why some flat numbers are famous. Everybody knows the front desk is Flat 1, so visitors do not have to ask. Ports work the same way. If every web server on Earth listens on 443 for secure traffic, your browser can reach any of them without being told the number.
Where ports live: the transport layer
Ports belong to the transport layer of networking, and the two protocols that use them are TCP and UDP.
- TCP sets up a connection first, guarantees delivery and keeps the data in order. Web pages, email and file transfers use it.
- UDP just fires packets without a handshake or guarantees. It suits things where speed matters more than perfection, such as DNS lookups, live video, voice calls and games.
TCP port 53 and UDP port 53 are different doors that happen to share a number. Each protocol has its own full set of 65,536 ports, which is why you will see written forms like 443/tcp and 443/udp. In fact, modern HTTP/3 uses UDP port 443, while ordinary HTTPS uses TCP port 443.
Why exactly 0 to 65535?
The port number is stored in 16 bits in the TCP and UDP headers. Sixteen bits give 216, or 65,536 possible values, counting from zero. That is the whole reason for the limit. Port 0 is reserved and is not used for ordinary traffic, so in practice you work with 1 to 65535.
The three port ranges
The internet’s numbering authority, IANA, divides the 65,536 numbers into three zones.
| Range | Name | Count | What lives here |
|---|---|---|---|
| 0 – 1023 | Well-known (system) ports | 1,024 | Core services: web, SSH, email, DNS. Assigned by IANA. |
| 1024 – 49151 | Registered ports | 48,128 | Applications and databases, such as MySQL on 3306 or PostgreSQL on 5432. |
| 49152 – 65535 | Dynamic (ephemeral) ports | 16,384 | Temporary numbers your device picks for outgoing connections. |
One caution: operating systems do not all follow the IANA suggestion for temporary ports. Modern Windows uses 49152 to 65535 by default. Linux commonly uses 32768 to 60999, and you can read the exact range in /proc/sys/net/ipv4/ip_local_port_range. That is a tuning detail worth knowing when you debug connection limits.
The ports every beginner should memorise
| Port | Service | What it does |
|---|---|---|
| 22 (TCP) | SSH | Encrypted remote login and file copying. |
| 25 (TCP) | SMTP | Mail transfer between mail servers. |
| 53 (UDP/TCP) | DNS | Turns names like example.com into IP addresses. |
| 80 (TCP) | HTTP | Unencrypted web traffic. |
| 443 (TCP, UDP) | HTTPS | Encrypted web traffic. UDP carries HTTP/3. |
| 587 (TCP) | SMTP submission | Where your mail app sends outgoing mail. |
| 993 (TCP) | IMAPS | Encrypted mailbox access. |
| 3306 (TCP) | MySQL | Default MySQL and MariaDB database port. |
| 3389 (TCP) | RDP | Windows Remote Desktop. |
| 5432 (TCP) | PostgreSQL | Default PostgreSQL database port. |
| 6379 (TCP) | Redis | Default Redis cache and data store port. |
These are conventions, not laws. Nothing in physics forces a web server to listen on 80. It is simply the agreed default, and the agreement is what lets browsers and servers find each other without negotiation.
Why 80, 443 and 22 matter so much
Port 80: the original web
When you type http://example.com, your browser quietly adds :80. This is plain, unencrypted HTTP. Anyone on the path, such as the coffee shop Wi-Fi owner, can read or modify what travels over it. Today port 80 mostly survives to redirect visitors to the secure version.
Port 443: the secure web
When you type https://example.com, the browser adds :443. The same HTTP conversation happens, but wrapped in TLS encryption. This is the port that matters most for any site you run. Search engines, browsers and users all expect it. If you want to run a site that ranks and earns trust, port 443 must be open, and the certificate behind it must be valid.
Port 22: the administrator’s door
SSH is how people manage servers from afar. It is also, unfortunately, one of the most attacked doors on the internet. If you have ever put a server online and checked its logs an hour later, you have seen strangers hammering port 22 with guessed passwords. We will come back to what to do about that.
You can use any port in a URL by writing it after a colon. https://example.com:8443 tells the browser to use 8443 instead of 443. Developers do this constantly, and the reason is a ritual every programmer knows: local test servers run on ports like 3000, 5000, 8000 or 8080, so that they do not clash with the real web ports.
The key idea: a connection is four numbers
Here is the part that clears up the most confusion. When your browser connects to a web server, it uses a port on both sides. The server side is the well-known one (443). Your side is a temporary number the operating system picks from the dynamic range.
A TCP connection is uniquely identified by four values: your IP address, your port, the server’s IP address and the server’s port. Change any one of them and it is a different connection. That is how you can open ten tabs to the same website, all talking to the same server on the same port 443, without the answers colliding. Each tab uses a different source port on your side.
See it for yourself in about twenty lines of Python
I like proving things in code rather than asking you to believe them. The script below starts a small server, connects to it three times, and prints which ports each side used. Then it tries to start a second server on the same port.
import socket, threading
# 1. A server listens on one port. We let the OS pick a free one (port 0).
server = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
server.bind(("127.0.0.1", 0))
server.listen()
host, port = server.getsockname()
print("server listening on port", port)
# 2. Three clients connect to that single server port.
def serve():
for _ in range(3):
conn, addr = server.accept()
conn.close()
threading.Thread(target=serve, daemon=True).start()
for n in range(3):
c = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
c.connect((host, port))
print(f"client {n+1}: my port {c.getsockname()[1]} -> server port {c.getpeername()[1]}")
c.close()
# 3. A second server cannot grab the same port.
dup = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
dup.bind((host, port))
except OSError as e:
print("second bind failed:", e.strerror)
This is the output from one run on my machine. Your numbers will differ, because the operating system picks them:
server listening on port 54875
client 1: my port 47676 -> server port 54875
client 2: my port 47684 -> server port 54875
client 3: my port 47700 -> server port 54875
second bind failed: Address already in use
Three things are worth noticing. First, the server uses one port, 54875 in this run, for all three clients. Second, each client received a different temporary port of its own. Third, the attempt to bind a second server to the same address and port failed with “Address already in use.” Only one program can listen on a given port at a time, which explains an error that confuses beginners every single week.
The error you will meet one day. “Address already in use” or “port 3000 is already allocated” almost always means a previous copy of your program is still running, or another application owns that port. Find the owner with the commands later in this article, stop it, and try again.
The same idea in five real settings
Click a tab to see ports at work in different places. No reload, nothing to install.
Browsing the web
You type a web address and press enter. You never type a port, yet one is used on every request.
What happens with ports. With no port in the address, the browser assumes 80 for http and 443 for https. A site on port 80 usually just redirects you to 443. Newer browsers may also try HTTP/3, which uses UDP port 443, and fall back to TCP if that fails. If you ever see a site at :8443 or :8080, the owner chose a non-default port.
Logging in to a server
A developer manages a rented server from home. They connect with a secure shell, and their password-guessing visitors do the same.
What happens with ports. SSH listens on 22 by default, so every scanner on the internet knocks there. Sensible practice is key-based login, no root login, and a firewall rule that allows 22 only from known addresses. To use another port, you write ssh -p 2222 user@host. It lowers log noise but is not a security measure.
Sending and reading email
Your phone’s mail app needs to send a message and fetch new ones.
What happens with ports. Mail uses several ports because it has several jobs. Your app submits outgoing mail on 587 (or 465 with immediate TLS). Mail servers pass messages between each other on 25. For reading, IMAP over TLS uses 993 and POP3 over TLS uses 995. Many hosting providers block outgoing port 25 from ordinary customers to cut spam, so a mail setup that works on a laptop may fail on a cloud server.
Databases
A web app stores its data in a database on the same server, or on a neighbouring one.
What happens with ports. Databases listen on their own registered ports, and the app connects to them. The golden rule is to bind them to a private address and block them in the firewall, so only the application server can reach them. Unprotected database ports on the public internet are found and attacked within hours, which is why every serious guide says to keep them closed.
Gaming and home servers
You host a game server on your PC so friends can join from their homes.
What happens with ports. A common Java Minecraft server listens on 25565. Your friends connect to your public IP on that port, but your router drops the unsolicited traffic until you forward public port 25565 to the PC’s private address. Then allow the same port in the PC’s own firewall. Providers that put many homes behind shared addresses can block this entirely, in which case a hosted server or a relay service is the workaround.
How your router uses ports: NAT in plain English
Your home has one public IP address from your internet provider, yet a dozen devices share it. How do replies find the right device? The router performs NAT, network address translation, and ports are the trick that makes it work.
Suppose your phone (192.168.1.20) opens a connection to a web server from its local port 51000. The router rewrites the outgoing packet so it appears to come from the router’s own public address, using its own chosen port, say 40001. It remembers the pairing in a table. When the reply returns to port 40001, it looks it up and forwards the data to the phone at 192.168.1.20 port 51000. Your laptop doing the same thing would get a different public port.
| Device (private) | Private port | Router (public) port | Destination |
|---|---|---|---|
| 192.168.1.20 phone | 51000 | 40001 | example.com:443 |
| 192.168.1.31 laptop | 51000 | 40002 | example.com:443 |
| 192.168.1.44 TV | 49500 | 40003 | video.example.net:443 |
The numbers in the table are illustrative, since real routers pick their own. Notice that the phone and laptop both used private port 51000 and nothing broke. The router separates them by assigning different public ports.
Port forwarding: the reverse trick
NAT works naturally for connections that start inside your home. Connections that start outside have a problem: the router has no table entry, so it drops them. If you want a friend to join a game server running on your PC, you create a port forwarding rule: “anything arriving on public port 25565 goes to 192.168.1.50, port 25565.” That is exactly what the home-router tab above shows.
Firewalls: deciding which doors are open
A firewall is largely a list of rules about ports. A typical server firewall says: allow incoming 443, allow incoming 22 only from my office, and drop everything else. Because a program can only receive connections if something is listening, closing a port you do not need means that if the software behind it has a flaw, the flaw is unreachable.
When you scan a machine for open ports, there are usually three results:
- Open. A program is listening and accepted the connection.
- Closed. The machine is reachable, but nothing listens there, and it politely refuses.
- Filtered. A firewall dropped the attempt, so you get no answer at all.
The practical rule I teach every junior: every open port is a promise to answer strangers. Keep that list as short as you can.
Commands to see ports on your own machine
| Goal | Command | Notes |
|---|---|---|
| List listening ports (Linux) | ss -tulpn | Shows protocol, port and the program. Needs sudo to see other users’ programs. |
| List listening ports (Windows) | netstat -ano | The last column is the process ID. Match it in Task Manager. |
| Who owns port 3000? (macOS, Linux) | lsof -i :3000 | Prints the program and its process ID. |
| Test a remote port (Windows PowerShell) | Test-NetConnection host -Port 443 | Reports whether the TCP connection succeeded. |
| Test a remote port (Linux, macOS) | nc -zv host 443 | Needs netcat installed. |
Tool options vary slightly between systems and versions, so treat these as reliable starting points. Only scan machines you own or have permission to test. Scanning other people’s networks can break rules or laws.
Limits you can actually hit: running out of ports
Because each outgoing connection needs a temporary port, a single client talking to a single server address and port has a ceiling. With Windows’ default dynamic range of 49152 to 65535, that is 16,384 simultaneous connections. With Linux’s common default of 32768 to 60999, it is 28,232. After that, new connections fail until old ones close.
Most users never see this. Busy servers and load balancers do, and the same arithmetic hits NAT gateways that funnel thousands of devices through one public address. When people say a service “ran out of ephemeral ports,” this is what they mean. The usual fixes are reusing connections (keep-alive and connection pooling), widening the range, or adding more addresses.
Security myths about ports
Myth: changing the SSH port makes it secure
Moving SSH from 22 to something obscure reduces noise in your logs because the lazy scanners that probe only port 22 stop finding you. It does not stop a determined scanner, which checks all ports in minutes. Real protection comes from key-based login instead of passwords, disabling root login, keeping software updated, and restricting who may connect at all. Treat a port change as tidiness, not security.
Myth: a closed port means the machine is invisible
A closed port still reveals that the machine exists. Only a firewall that silently drops traffic hides that, and even then the machine can leak information in other ways.
Myth: databases are safe on their default port because nobody knows the number
Everybody knows the number. MySQL on 3306, PostgreSQL on 5432, Redis on 6379 and MongoDB on 27017 are scanned constantly. A database should normally listen only on a private interface, with the firewall blocking public access.
Common mistakes beginners make
- Confusing the port with the protocol. Port 443 is conventionally HTTPS, but a program can run anything on any port. The convention is not enforced.
- Forgetting TCP versus UDP. Opening TCP 53 in a firewall does nothing for DNS queries that use UDP 53.
- Opening a port without checking what listens behind it. You have just exposed that program to the whole internet.
- Forwarding a port on the router but not opening it on the PC firewall. The traffic arrives and is dropped by the last gate.
- Assuming a number above 1023 needs no thought. Registered ports can be just as dangerous as well-known ones when they hold a database.
- Running a second copy of a server and ignoring “Address already in use.” Something already owns that port.
Test yourself
Tap a question to reveal the answer. The correct option is marked.
How many bits is a TCP or UDP port number, and what is the highest port?
- 8 bits, 255
- 32 bits, 4,294,967,295
- 16 bits, 65535
- 12 bits, 4095
Sixteen bits give 65,536 values, 0 through 65535.
You type https://example.com with no port. Which port does your browser use?
- 80
- 443
- 22
- 8080
The https scheme defaults to 443. Plain http defaults to 80.
Ten browser tabs open connections to the same server on port 443. How does the server tell them apart?
- By the website address
- By the tab title
- It cannot, so they share one connection
- By the different source ports on the visitor’s side
A connection is identified by both IP addresses and both ports. Each tab uses its own temporary source port.
Your program fails with “Address already in use” on port 3000. What is the most likely cause?
- Another program, maybe an earlier copy of yours, is already listening on 3000
- Port 3000 is reserved by IANA
- Your internet is down
- TCP does not allow ports above 1023
Only one program can listen on a given address and port. Find the owner with lsof, ss or netstat.
Which statement about changing the SSH port from 22 is true?
- It makes SSH impossible to attack
- It reduces log noise from lazy scanners but is not real security
- It is required by law
- It disables password logins
A full port scan finds any port in minutes. Real protection is key-based login, updates and firewall rules.
Frequently asked questions
What is a port number in simple words?
A number that tells a computer which program should receive incoming data. The IP address finds the machine, and the port finds the program on it.
What is the difference between port 80 and port 443?
Port 80 is the default for plain HTTP, which is unencrypted. Port 443 is the default for HTTPS, which wraps the same web traffic in TLS encryption. Modern sites use 443 and redirect 80 to it.
Is a port a physical thing?
No. It is just a number in the TCP or UDP header that the operating system uses to route data to the right program. It is not a hardware socket, even though a network cable plug is also sometimes called a port.
Can I use any port I want for my own program?
Yes, within limits. Avoid the well-known range below 1024 for personal projects, since on many systems those need extra privileges, and check that the port is not already used. Ports from about 1024 up are the usual choice for custom apps.
Are open ports dangerous?
An open port is a program accepting connections from the network. It is only as risky as the program behind it and who can reach it. Keep open only what you need, patch the software, and restrict access with a firewall.
What is the difference between TCP and UDP ports?
They are two separate sets of 65,536 numbers. TCP 53 and UDP 53 are different doors. TCP is reliable and ordered, UDP is faster with no guarantees, and some services, like DNS, use both.
Key takeaways
- A port is a number from 0 to 65535 that tells a computer which program should receive incoming data. An IP address is the building, a port is the apartment.
- Ports 80 (HTTP), 443 (HTTPS) and 22 (SSH) are conventions that let clients find services without negotiating.
- A connection is identified by four values: both IP addresses and both port numbers. That is how many tabs share one server port.
- Only one program can listen on a given port at a time, which causes “Address already in use.”
- Routers use ports to let many devices share one public address, and port forwarding opens a door from outside.
- Every open port is a promise to answer strangers. Keep the list short, and never rely on an obscure port number as security.
