Port 3306: MySQL
TCP 3306 is the port for MySQL / MariaDB. Never on the internet. Bind to 127.0.0.1 or a private network, and use an SSH tunnel for remote admin.
| Service | MySQL / MariaDB |
|---|---|
| Protocol | TCP |
| Exposure risk | High: do not expose to the internet |
| Range | Registered (1024–49151) |
What port 3306 does
The default port for MySQL and MariaDB servers. Since MySQL 8.0, X Protocol also listens on 33060.
Should port 3306 be open?
Never on the internet. Bind to 127.0.0.1 or a private network, and use an SSH tunnel for remote admin.
Find what's listening on port 3306
- Linux:
sudo ss -tulpn | grep :3306 - macOS:
sudo lsof -nP -i :3306 - Windows:
netstat -ano | findstr :3306, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 3306/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=3306/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 3306" -Direction Inbound -Protocol TCP -LocalPort 3306 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 3306
What is port 3306 used for?
MySQL / MariaDB. The default port for MySQL and MariaDB servers. Since MySQL 8.0, X Protocol also listens on 33060.
Is port 3306 TCP or UDP?
TCP. MySQL uses TCP port 3306.
Is it safe to open port 3306?
High: do not expose to the internet. Never on the internet. Bind to 127.0.0.1 or a private network, and use an SSH tunnel for remote admin.
How do I check if port 3306 is open?
Use the checker on this page: it connects to your host on TCP 3306 from the internet. Locally, run
nc -vz host 3306 (macOS/Linux) or Test-NetConnection host -Port 3306 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :3306 (Linux) or netstat -ano | findstr :3306 (Windows).