Common Ports Lookup
Look up what normally listens on a TCP or UDP port, and why it matters if it is exposed.
Enter a port number on the left.
How it works
A port number is a label on a door, not a verdict about what is behind it. This page tells you what conventionally listens on one and what is worth knowing if it turns up reachable — which are two different facts, kept apart on purpose.
An open port is not a vulnerability
Worth being precise about, because findings get written from this distinction. Whether a port should be open depends on what answers it and who can reach it. What is reportable is an unauthenticated or obsolete service reachable from an untrusted network — a database with no password, Telnet on an internet-facing host, a BMC on 623 that is full hardware control to anyone who finds it. The exposure rating here speaks to that reachability question. It never claims the service itself is flawed.
Three ranges, and only two are assigned
0–1023 are system ports, assigned by IANA; binding one traditionally needs root on Unix-like systems. 1024–49151 are registered on request. 49152–65535 are ephemeral and never assigned to anything — the operating system hands them out as the source port of outbound connections and reuses them constantly. A connection from port 51423 tells you only that some client opened a socket.
Some entries are here for what they mean, not what they are
Port 4444 has no meaningful assignment. It is listed because it is Metasploit's default listener, so it runs through a great many public exploit write-ups and through the traffic of everyone who followed one without changing the default. That is a fact about what you will see in a log, and it is labelled as such rather than dressed up as an assignment.
Example
445 is SMB over TCP — the port EternalBlue and WannaCry spread over, and one that should never be
reachable from the internet. 3389 is RDP, the most common initial-access route for ransomware. Search
amplification instead of a number and you get the UDP services abused for reflected DDoS: DNS, NTP,
memcached, the SQL Server browser.
Frequently asked questions
Does a port being open mean it is a vulnerability?
No, and the distinction matters when you are writing a finding up. A port is a door; whether it should be open depends on what is behind it and who can reach it. What is reportable is an unauthenticated or legacy service reachable from an untrusted network — an exposed database with no password, or Telnet on an internet-facing host. The exposure rating here is about that reachability question, not a claim that the service is flawed.
Why are ports above 49151 not assigned to anything?
Because that range is deliberately never assigned. Those are ephemeral ports, which an operating system hands out as the source port for outbound connections and reuses constantly. A connection from port 51423 tells you only that some client opened a socket.
Why is port 4444 listed when it has no real assignment?
Because recognising it is useful even though the assignment is not. It is the default listener port in Metasploit, so it appears throughout public exploit write-ups and in traffic from anyone who followed one without changing the default. That is a fact about what you will see in logs, not an assignment.
Related tools
HTTP Status Code Lookup
What a status code means, which RFC defines it, and what to do next.
LocalPrivate & Public IP Classifier
Tell whether an address is routable, private, loopback or otherwise reserved.
LocalCIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
LocalWHOIS Lookup
Registrar, registration and expiry dates, status codes and name servers for any domain.
Sends dataPort Checker
Check whether one well-known port on a host answers — open, closed, or timed out.
Sends dataDNS Lookup
Query A, AAAA, MX, TXT, NS, CNAME, SOA and CAA records for any domain.
Sends dataFrom the intelligence desk
- News Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn
- News CISA confirms exploitation of SharePoint and MikroTik RouterOS flaws
- News CISA flags six exploited flaws in VPN, SD-WAN and commerce platforms
- Vulnerability 2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102)