Port 80: HTTP
TCP 80 is the port for Hypertext Transfer Protocol. Fine for public web servers, ideally only serving a 301 redirect to HTTPS plus /.well-known/acme-challenge/.
| Service | Hypertext Transfer Protocol |
|---|---|
| Protocol | TCP |
| Exposure risk | Low: normally safe to expose |
| Secure alternative | HTTPS (port 443) |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 80 does
Unencrypted web traffic. Today its main job is to redirect visitors to HTTPS on 443 and to answer ACME HTTP-01 challenges when Let's Encrypt issues certificates.
Should port 80 be open?
Fine for public web servers, ideally only serving a 301 redirect to HTTPS plus /.well-known/acme-challenge/. Where you can, use HTTPS (port 443) instead.
Find what's listening on port 80
- Linux:
sudo ss -tulpn | grep :80 - macOS:
sudo lsof -nP -i :80 - Windows:
netstat -ano | findstr :80, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 80/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=80/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 80" -Direction Inbound -Protocol TCP -LocalPort 80 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 80
What is port 80 used for?
Hypertext Transfer Protocol. Unencrypted web traffic. Today its main job is to redirect visitors to HTTPS on 443 and to answer ACME HTTP-01 challenges when Let's Encrypt issues certificates.
Is port 80 TCP or UDP?
TCP. HTTP uses TCP port 80.
Is it safe to open port 80?
Low: normally safe to expose. Fine for public web servers, ideally only serving a 301 redirect to HTTPS plus /.well-known/acme-challenge/. Secure alternative: HTTPS (port 443).
How do I check if port 80 is open?
Use the checker on this page: it connects to your host on TCP 80 from the internet. Locally, run
nc -vz host 80 (macOS/Linux) or Test-NetConnection host -Port 80 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :80 (Linux) or netstat -ano | findstr :80 (Windows).