Common Port Numbers List: Traditional Ports and Their Encrypted Alternatives

Understanding network ports is essential for cybersecurity, ethical hacking, and IT professionals. This blog explains the most commonly used old/traditional port numbers like 80, 21, 23, and their modern secure alternatives such as 443, 587, and 8443. We also cover their uses in protocols like LDAP, SNMP, SMTP, RDP, VPN, and VoIP. A detailed table compares each service's legacy and updated port numbers to help you configure firewalls, assess vulnerabilities, and prepare for certifications like CEH, OSCP, and CompTIA Security+.

Jun 23, 2025 - 09:36
Updated: 8 days ago
105.6k
Common Port Numbers List: Traditional Ports and Their Encrypted Alternatives

Quick answer: Ports are 16-bit numbers from 0 to 65535 that identify services. The "old versus new" idea is a myth: well-known ports such as 80, 22 and 25 did not change. What changed is that many services gained encrypted variants on other ports, such as HTTPS on 443, IMAPS on 993 and LDAPS on 636.

Key takeaways

  • Port numbers are assigned by IANA and do not get replaced. Secure versions of a service usually use a different, additional port.
  • Learn the pair: plain text and encrypted, for example 80 and 443, 143 and 993, 389 and 636.
  • Telnet (23), FTP (21) and POP3 (110) send data in clear text; use SSH, SFTP and encrypted mail ports instead.
  • Running a service on a non-standard port such as 2222 is a configuration choice, not a new standard, and is not real security.
  • Never expose SMB (445) or RDP (3389) directly to the internet.

Are there old and new port numbers?

No. The original version of this article suggested that older ports were replaced by "new" ones in 2026. That is not how ports work. The Internet Assigned Numbers Authority (IANA) keeps the official service name and port number registry. A port assigned to a service stays assigned. What does happen is that a service gains a secure version, which usually gets its own port, or runs over TLS on the same port using a command such as STARTTLS.

Ports run from 0 to 65535. 0 to 1023 are well-known ports, 1024 to 49151 are registered ports, and 49152 to 65535 are dynamic or private ports.

Common ports and secure alternatives

ServiceTraditional portSecure alternativeProtocolNote
HTTP / HTTPS80443TCP443 uses TLS. 8080 and 8443 are common alternates, not standards
FTP21 (control), 20 (data)SFTP on 22, FTPS on 990 (implicit)TCPFTP sends passwords in clear text
Telnet23SSH on 22TCPAvoid Telnet
SSH22SameTCPMoving it to 2222 only reduces log noise
SMTP25465 (SMTPS), 587 (submission with STARTTLS)TCP25 is for server to server mail
POP3110995TCPPrefer IMAP
IMAP143993TCP
DNS53853 (DNS over TLS)UDP and TCPDNS over HTTPS uses 443
DHCP67 server, 68 clientNoneUDPRogue DHCP risk
TFTP69NoneUDPNo authentication; internal use only
SNMP161, 162 (traps)SNMPv3 on the same ports; 10161 and 10162 for SNMP over TLS or DTLSUDPAvoid SNMPv1 and v2c community strings
LDAP389636 (LDAPS)TCP and UDPLDAP can use StartTLS on 389
SMB445SMB 3 encryption on the same portTCPDo not expose to the internet
NetBIOS137 to 139NoneUDP and TCPLegacy; disable where you can
RDP3389Same, often behind a VPN or gatewayTCP and UDPFrequent brute-force target
MySQL330633060 is the X Protocol, not a secure alternativeTCPUse TLS; do not expose
PostgreSQL5432Same, with TLS enabledTCP
MongoDB27017Same, with TLS and authenticationTCPNever expose without authentication

What about custom ports like 2222 or 3390?

Admins may move a service to another port, for example SSH to 2222 or RDP to 3390, to cut automated noise. This is configuration, not a new standard. Attackers scan all ports, so it is not a substitute for key-based login, MFA or a firewall. Use it, if at all, as a minor extra.

Security advice for students and admins

  • Close every port you do not need. List listening services with ss -tulpn on Linux.
  • Scan your own systems to see what is exposed. Use Nmap only on systems you own or have written permission to test.
  • Prefer encrypted protocols and turn off plain-text ones.
  • Restrict admin ports (SSH, RDP, databases) by IP, VPN or bastion host.
  • Monitor firewall logs for scans of many ports in a short time.

For more, see our lists of commonly used TCP and UDP ports and the top 20 network ports, and read the difference between TCP and UDP.

Common mistakes

  • Memorising numbers without knowing the service and risk.
  • Assuming a service on a high port is safe.
  • Mixing up SFTP (SSH-based) and FTPS (FTP over TLS).
  • Treating 8080 as an official HTTP port.

Next steps

Next steps: to practise scanning and securing services, see our Computer Network course, and read the top 20 ports guide.

Frequently Asked Questions

There is no official split. Well-known ports stay the same. Newer secure versions of services often use extra ports, such as 443 for HTTPS, 993 for IMAPS and 636 for LDAPS, while other ports like 8080 or 2222 are custom choices.

Port 443 carries HTTPS, which encrypts traffic with TLS, protecting passwords and data from eavesdropping and tampering. Port 80 carries plain HTTP. Most sites now redirect port 80 to 443.

LDAPS uses TCP port 636 with TLS from the start. LDAP on port 389 can also be secured with StartTLS. Use encryption for directory authentication.

It is rarely appropriate. Telnet on port 23 sends data, including passwords, in clear text. It appears on legacy devices, and security teams should replace it with SSH on port 22.

Port 21 is FTP control and sends credentials in clear text. Port 22 is SSH, which encrypts sessions and also carries SFTP and secure copy. Use port 22 services instead of FTP.

SMTPS uses port 465 with TLS from the start, and mail submission uses port 587 with STARTTLS. Port 25 is used for server-to-server mail and may be unencrypted unless configured.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.