Common Port Numbers List: Traditional Ports and Their Encrypted Alternatives
Understanding network ports is essential for cybersecurity, ethical hacking, and IT professionals. This blog explains the most commonly used old/traditional port numbers like 80, 21, 23, and their modern secure alternatives such as 443, 587, and 8443. We also cover their uses in protocols like LDAP, SNMP, SMTP, RDP, VPN, and VoIP. A detailed table compares each service's legacy and updated port numbers to help you configure firewalls, assess vulnerabilities, and prepare for certifications like CEH, OSCP, and CompTIA Security+.
Quick answer: Ports are 16-bit numbers from 0 to 65535 that identify services. The "old versus new" idea is a myth: well-known ports such as 80, 22 and 25 did not change. What changed is that many services gained encrypted variants on other ports, such as HTTPS on 443, IMAPS on 993 and LDAPS on 636.
Key takeaways
- Port numbers are assigned by IANA and do not get replaced. Secure versions of a service usually use a different, additional port.
- Learn the pair: plain text and encrypted, for example 80 and 443, 143 and 993, 389 and 636.
- Telnet (23), FTP (21) and POP3 (110) send data in clear text; use SSH, SFTP and encrypted mail ports instead.
- Running a service on a non-standard port such as 2222 is a configuration choice, not a new standard, and is not real security.
- Never expose SMB (445) or RDP (3389) directly to the internet.
Are there old and new port numbers?
No. The original version of this article suggested that older ports were replaced by "new" ones in 2026. That is not how ports work. The Internet Assigned Numbers Authority (IANA) keeps the official service name and port number registry. A port assigned to a service stays assigned. What does happen is that a service gains a secure version, which usually gets its own port, or runs over TLS on the same port using a command such as STARTTLS.
Ports run from 0 to 65535. 0 to 1023 are well-known ports, 1024 to 49151 are registered ports, and 49152 to 65535 are dynamic or private ports.
Common ports and secure alternatives
| Service | Traditional port | Secure alternative | Protocol | Note |
|---|---|---|---|---|
| HTTP / HTTPS | 80 | 443 | TCP | 443 uses TLS. 8080 and 8443 are common alternates, not standards |
| FTP | 21 (control), 20 (data) | SFTP on 22, FTPS on 990 (implicit) | TCP | FTP sends passwords in clear text |
| Telnet | 23 | SSH on 22 | TCP | Avoid Telnet |
| SSH | 22 | Same | TCP | Moving it to 2222 only reduces log noise |
| SMTP | 25 | 465 (SMTPS), 587 (submission with STARTTLS) | TCP | 25 is for server to server mail |
| POP3 | 110 | 995 | TCP | Prefer IMAP |
| IMAP | 143 | 993 | TCP | |
| DNS | 53 | 853 (DNS over TLS) | UDP and TCP | DNS over HTTPS uses 443 |
| DHCP | 67 server, 68 client | None | UDP | Rogue DHCP risk |
| TFTP | 69 | None | UDP | No authentication; internal use only |
| SNMP | 161, 162 (traps) | SNMPv3 on the same ports; 10161 and 10162 for SNMP over TLS or DTLS | UDP | Avoid SNMPv1 and v2c community strings |
| LDAP | 389 | 636 (LDAPS) | TCP and UDP | LDAP can use StartTLS on 389 |
| SMB | 445 | SMB 3 encryption on the same port | TCP | Do not expose to the internet |
| NetBIOS | 137 to 139 | None | UDP and TCP | Legacy; disable where you can |
| RDP | 3389 | Same, often behind a VPN or gateway | TCP and UDP | Frequent brute-force target |
| MySQL | 3306 | 33060 is the X Protocol, not a secure alternative | TCP | Use TLS; do not expose |
| PostgreSQL | 5432 | Same, with TLS enabled | TCP | |
| MongoDB | 27017 | Same, with TLS and authentication | TCP | Never expose without authentication |
What about custom ports like 2222 or 3390?
Admins may move a service to another port, for example SSH to 2222 or RDP to 3390, to cut automated noise. This is configuration, not a new standard. Attackers scan all ports, so it is not a substitute for key-based login, MFA or a firewall. Use it, if at all, as a minor extra.
Security advice for students and admins
- Close every port you do not need. List listening services with
ss -tulpnon Linux. - Scan your own systems to see what is exposed. Use Nmap only on systems you own or have written permission to test.
- Prefer encrypted protocols and turn off plain-text ones.
- Restrict admin ports (SSH, RDP, databases) by IP, VPN or bastion host.
- Monitor firewall logs for scans of many ports in a short time.
For more, see our lists of commonly used TCP and UDP ports and the top 20 network ports, and read the difference between TCP and UDP.
Common mistakes
- Memorising numbers without knowing the service and risk.
- Assuming a service on a high port is safe.
- Mixing up SFTP (SSH-based) and FTPS (FTP over TLS).
- Treating 8080 as an official HTTP port.
Next steps
Next steps: to practise scanning and securing services, see our Computer Network course, and read the top 20 ports guide.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0