Port 443: HTTPS
TCP/UDP 443 is the port for HTTP over TLS (and HTTP/3 over QUIC on UDP). The normal public port for web servers. Keep the certificate chain complete and TLS 1.2+ only.
| Service | HTTP over TLS (and HTTP/3 over QUIC on UDP) |
|---|---|
| Protocol | TCP/UDP |
| Exposure risk | Low: normally safe to expose |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 443 does
Encrypted web traffic: websites, APIs, and many VPNs and tunnels that hide inside it. HTTP/3 runs over QUIC on UDP 443, so firewalls should allow both TCP and UDP 443 for the best performance.
Should port 443 be open?
The normal public port for web servers. Keep the certificate chain complete and TLS 1.2+ only.
Find what's listening on port 443
- Linux:
sudo ss -tulpn | grep :443 - macOS:
sudo lsof -nP -i :443 - Windows:
netstat -ano | findstr :443, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 443/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=443/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 443" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 443
What is port 443 used for?
HTTP over TLS (and HTTP/3 over QUIC on UDP). Encrypted web traffic: websites, APIs, and many VPNs and tunnels that hide inside it. HTTP/3 runs over QUIC on UDP 443, so firewalls should allow both TCP and UDP 443 for the best performance.
Is port 443 TCP or UDP?
Both. HTTPS uses TCP and UDP on port 443.
Is it safe to open port 443?
Low: normally safe to expose. The normal public port for web servers. Keep the certificate chain complete and TLS 1.2+ only.
How do I check if port 443 is open?
Use the checker on this page: it connects to your host on TCP 443 from the internet. Locally, run
nc -vz host 443 (macOS/Linux) or Test-NetConnection host -Port 443 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :443 (Linux) or netstat -ano | findstr :443 (Windows).