Historical TCP port number assignments

Return to index.

Note that earliest assignments are exclusively 'odd' numbers because they're inherited from ARPANET NCP socket assignments, where sockets provided simplex connections – by convention, 'odd'-numbered sockets were for server-to-client data, while the corresponding 'even' sockets were used for client-to-server traffic – therefore each 'odd' assignment implicitly reserved the next higher 'even' socket as well. Explicit 'even' port assignments in the two-digit range tend to be much newer, well after the TCP/IP switchover.

Port 1 – tcpmux (TCP Port Service Multiplexer)

A simple multiplexing protocol for accessing different services by name, instead of by port number. The client sends an ASCII protocol name, the server connects it to the desired service. Seen implemented by some inetd versions. (Inetd already operates by connecting the TCP socket to the spawned service handler's stdin/stdout, so this feature can be easily added without requiring proxying.)

Defined in RFC 1078 (1988), deprecated in RFC 7805.

*connect*
C:SMTP
S:+
S:220 hades.arpa ESMTP Postfix

Before that, NCP socket 1 had been in use for the "Old Telnet" protocol (RFC 318, NIC 9348) until removal in RFC 870.

Port 3

Originally, NCP socket 3 was assigned by RFC 349 (1972) (removed in RFC 870) to the original "File Transfer" protocol as defined in RFC 354 and RFC 385 (later the document reference changed to the same NIC 7014 as Telnet and RJE). RFC 739 calls it "Old File Transfer" and assigns socket 21 for "New File Transfer" (which is the text-based FTP known until today).

Port 5 – rje (Remote Job Entry)

A protocol for submitting "punched card" batch jobs via TELNET.

Proposed in RFC 360 (1972), then RFC 407 (1972). Later the socket assignment in RFC 503 lists NIC 7014 as the protocol definition.

Probably the first protocol to use the numbered responses style now known from FTP/SMTP/HTTP. As with several other protocols from that era, RJE is at least in part designed to work with an interactive TELNET client.

*connect*
S:300 RJE server ready
S:000 Message of the day goes here
C:USER=roundabout
S:330 Enter password
C:PASS=aabbcc
S:230 Log-on completed
C:OUT=:E/.sysprinter
S:200 Last command received ok
C:OUT puncher = (S)HOSTB:NE/my.savepunch
S:200 Last command received ok
C:INPUT=HOSTB:E/my.jobinput
S:240 File transfer has started
S:260 Job FOO123 accepted for processing

According to "ARPANET History", the RJE protocol came too late and remained mostly unused, its place already taken by UCLA's interim NETRJS protocol (see below).

Port 7 – echo

Echoes everything it receives.

Originally suggested in RFC 347, first implemented in RFC 361 for NCP, then defined in RFC 862 as a "debugging and measurement tool" for the early ARPA Internet.

Port 9 – discard

Ignores everything it receives.

Originally suggested in RFC 348, first implemented in RFC 361 for NCP, defined in RFC 863 as a "debugging and measurement tool" for the early ARPA Internet.

Sometimes still used as a "harmless" destination for things such as Wake-on-LAN UDP messages.

Port 11 – users or systat (Active Users)

Responds with a list of currently logged-in users in ASCII, with the output generally expected to come from commands such as 'who' on Unix or 'SYSTAT' on TENEX (hence the IANA name for this port).

Originally mentioned in RFC 503 for NCP as "Systat or who-is-on function", together with netstat.

Later defined in RFC 866 as a "debugging and measurement tool" for the early ARPA Internet deployment. Generally superseded by Finger.

Port 13 – daytime

Responds with the current time in arbitrary human-readable ASCII format (possibly the output of 'date' on Unix, or similar). See also time.

Originally mentioned in RFC 503 for NCP as "Date-Time function". Later defined in RFC 867 as a "debugging and measurement tool" for the early ARPA Internet deployment. NIST still operates Daytime service at time.nist.gov, alongside Time and NTP.

Port 15 – netstat (Who is up)

Originally mentioned in RFC 503 for NCP as "Netstat or who-is-up function", together with systat. Later mentioned in RFC 870 "Assigned numbers" but without any document reference.

(Likely to have been the 'netstat' command equivalent to systat (port 11), i.e. responding with an ASCII list of currently active TCP sockets, though the assignment name implies it might actually have been a list of hosts attached to the network.)

Port 17 – qotd (Quote of the Day)

Responds with some random quote or another message in ASCII.

Originally mentioned in RFC 433 as unofficial "Oneliners" implemented by two BBN-TENEX hosts, then in RFC 739 as an official "Short Text Message" assignment. Later defined in RFC 865 as a "debugging and measurement tool" for the early ARPA Internet deployment.

Port 18 – msp (Message Send Protocol)

Defined in 1990 by RFC 1159 (thus post-ARPANET), was a protocol to send text messages like using the Unix write command but between hosts.

Port 19 – chargen (Character Generator)

Generates an infinite stream of ASCII characters.

Originally mentioned in RFC 361 alongside echo/discard for NCP, later in RFC 429; later defined in RFC 864 as a "debugging and measurement tool" for the early ARPA Internet deployment.

Port 20 – ftp-data

Assigned in RFC 820 for "File Transfer (Default Data)" as defined in RFC 765, accompanying "FTP (Control)" on port 21.

This is the server-side port (i.e. source port) used by FTP servers when establishing data connections to the client, in what's now called the "active" mode. A relic of the NCP era.

The original ARPANET protocol suite did not have duplex connections as standard, the way TCP does, nor even the ability to juggle several connections to the same port number (although this might have been an implementation limitation). Programs such as Telnet, upon connecting to the well-known port, used a separate "Initial Connection Protocol" (ICP) to negotiate a bidirectional link consisting of two simplex sockets on ephemeral ports. Because of that architecture it seems to have been natural for FTP to simply pick additional simplex sockets for data transfers.

Port 21 – FTP

Assigned in RFC 739 to the "New File Transfer Protocol".

Original ARPANET (NCP-based) drafts:

Port 23 – telnet

The oldest ARPANET protocol ever.

The original Telnet or "Logger" protocol was assigned socket 1 for NCP/ICP (RFC 349) and defined in RFC 318, with RFC 739 updating socket 1 to be "Old Telnet" and assigning socket 23 to "New Telnet".

Port 25 – smtp (Simple Mail Transfer Protocol)

Assigned in RFC 790 to the same SMTP as used today, originally defined in RFC 788.

Before that, NCP socket 25 was briefly (RFC 739; removed in RFC 776) assigned to a "Distributed Programming System" (see socket 33).

Port 27 – nsw-fe (NSW User System FE)

NCP: Socket 27 was assigned in RFC 739 to "NSW User System w/COMPASS FE", with the following document references:

See also socket 39, which was briefly assigned in RFC 750 to "NSW User System w/SRI FE". Later that was rescinded, and RFC 820 listed only port 27 (the COMPASS variant) as "NSW User System FE".

Port 29 – msg-icp (MSG-3 ICP)
Port 31 – msg-auth (MSG-3 Authentication)

NCP sockets 29 and 31 were assigned in RFC 739 with a reference to:

Port 33 – dsp (Display Support Protocol)

Assigned in RFC 960 to a "Display Support Protocol" by Mike Corrigan at DDN, without a protocol reference.


Before that, NCP socket 33 had been briefly (RFC 739, removed in RFC 790) assigned to "DPS ICP" in reference to "Distributed Programming System", referencing RFC 707 and RFC 708:

Port 35 – priv-print (Any Printer Server)

A general placeholder assignment for site-specific network printing protocols.

Originally, NCP socket 35 was mentioned in RFC 739 for "IO Station Spooler" (no document reference).

Port 37 – time

Responds with the current time as a 32-bit binary value (offset from 1900-01-01 00:00:00), sharing the same epoch and "year 2036" rollover problem with NTPv3.

Originally assigned in RFC 739 and defined in RFC 738/NIC 42218 (1977) as "the Time Server protocol currently implemented on ITS hosts". Later updated in RFC 868 as a general standard ARPANET protocol. Still occassionally used as a simpler alternative to NTP (NIST still provides Time and Daytime service at time.nist.gov).

Port 39 – rlp (Resource Location Protocol)

Assigned in RFC 900 to a "Resource Location Protocol" as defined in RFC 887:

Before that, NCP socket 39 was assigned in RFC 750 (removed in RFC 776) to "NSW User System w/SRI FE", sharing a reference with socket 27.

Port 41 – graphics

Originally assigned in RFC 739 and RFC 750 (the former missing the actual assignment) with a reference to:

Port 42 – name (Name Server)

First assigned in RFC 758 (the first TCP/IP-era "Assigned Numbers" document, thus also the first 'even' port number) with a reference to IEN-116:

Port 43 – nicname (WhoIs)

First assigned in RFC 758 without a reference. Defined in RFC 812 specifically for interacting with the (then ARPANET-wide) DDN WHOIS database at the SRI-NIC machine, hence the official name 'NICNAME'. Still used today with the whois command to query various routing and domain registries, although slowly being superseded by the HTTP-based RDAP.

One-shot query/response protocol (client sends one line consisting of a query; server responds with arbitrary text).

*connect*
C:AS206633
S:aut-num: AS206633
S:as-name: BROKEN-SYMLINK
S:[...]
Port 44 – mpm-flags (MPM FLAGS Protocol)

RFC 870 assigns this to "MPM FLAGS Protocol", without a reference but most likely related to the Message Processing Module on ports 45-46.

Port 45 – mpm (Message Processing Module)

NCP socket 45 and/or TCP port 45 were assigned in RFC 758 to "Internet Message Processing Module", referencing:

With RFC 820, port 45 was adjusted to "MPM (receive)" with port 46 added as a "send" port.

Port 46 – mpm-send

RFC 820 assigns TCP port 46 to "MPM (default send)", as companion to MPM port 45.

Port 47 – ni-ftp (Network Independent File Transfer Protocol)

Assigned in RFC 762 for "NI FTP":

Later, this became the JANET "Blue Book" protocol.

IANA removed this assignment on 2017-05-18.

Port 49 – login (Login Host Protocol) aka TACACS

A protocol used by TIPs and TACs (which were ARPANET's "login hosts") to centrally authenticate users, as well to authorize the ARPANET connections they make.

Originally assigned in RFC 870 as "Login Host Protocol" without a protocol reference, although it was apparently specified in "TAC Access Control System Protocols, Second Edition" (1985) [BBN Tech Memo CC-0045] which doesn't appear to be publicly available.

Eventually a variant was published as RFC 1492 several decades later (due to the protocol having been adopted by Cisco terminal servers).


Before that, RFC 762 had assigned port 49 to "RAND Network Graphics Conference" (removed in RFC 820):

Port 51 – la-maint (IMP Logical Address Maintenance)

Assigned in RFC 870 for a protocol defined in:


Before that, RFC 762 had assigned port 51 to "Simple Internet Mail" without a document reference, and RFC 790 briefly had it as "Message Generator Control" (referencing IEN 172), removed in the subsequent RFC 820.

Port 53 – domain (Domain Name System)

Assigned in RFC 870 for the very same DNS as used today.


Before that, RFC 762 had briefly assigned port 53 to "AUTODIN II FTP":

Port 55 – isi-gl (ISI Graphics Language)

Assigned in RFC 770 to "ISI Graphics Language":

Port 57 – priv-term

RFC 870 had assigned this to "Any Private Terminal Access".

Cisco IOS makes a connection on port 57 when the tunnel command is used.


Before that, briefly assigned in RFC 770 (removed in RFC 820) to "Mail Transfer", a precursor to SMTP:

See also RFC 771 "Mail Transition Plan".

Port 59 – priv-file

RFC 870 had assigned this to "Any Private File Service". See also RFC 1037.

Before that, briefly assigned in RFC 790 to "New MIT Host Status", then in RFC 820 to "Augment File Mover", both without a protocol specification.

Port 61 – ni-mail (Network Independent Mail)

RFC 820 had assigned it to "NIMAIL", related to NI FTP (port 47):

This was, I believe, the JANET "Blue Book" mail protocol.

IANA removed this assignment on 2017-05-18.

Port 63

Before that, RFC 900 had assigned it to "VIA Systems - FTP".

Port 65 – tacacs-ds

RFC 943 assigns this to "TACACS-Database Service", with a reference to:


Before that, NCP socket 65 was briefly (in RFC 433; removed in RFC 820) assigned to "Speech Data Base @ ll-tx-2", with SUR 37 as the reference document. Later RFC 739 updates the reference to:

Port 67 – bootps
Port 68 – bootpc

Ports 67–68 became assigned to the "Bootstrap Protocol" in RFC 960. This superseded RARP, and gradually evolved into what we now know as DHCP.


Before that, NCP socket 67 was assigned in RFC 433 (removed in RFC 900) to "Datacomputer @ CCA". Later RFC 739 provides a reference:

Port 69 – tftp

NCP socket 69 was first mentioned in RFC 433 as "CPYNET" implemented by some hosts, later (RFC 503) getting an official assignment, without any protocol reference.

Eventually RFC 770 had a double assignment for "CPYNET" as well as "Trivial File Transfer" as defined in:

Port 71-74 – netrjs

Another remote job entry protocol similar to RJE, used specifically at UCLA Campus Computing Network for submitting jobs to an IBM 360. According to "ARPANET History", NETRJS was first defined by UCLA as an interim protocol because the official RJE protocol hadn't been available yet.

Defined in RFC 88, later RFC 189, eventually formalized in RFC 360 (which originates the 3-digit status codes seen in FTP/SMTP/HTTP), then RFC 740 - at the time only for ARPANET ICP, not yet for TCP/IP. See also RFC 307, RFC 325 for usage examples.

Current IANA database (as of RFC 820) reserves four adjacent ports without much explanation, but the original NCP-era RFC 503 (first appearance) had specifically assigned socket 71 to be used for EBCDIC and socket 73 for ASCII, with the 'even' companion sockets 72 and 74 being implicitly reserved for duplex transmission as was standard for NCP.

Port 75 – priv-dial

RFC 870 had assigned this to "Any Private Dial-out Service".


Before that, NCP socket 75 was briefly (in RFC 503) assigned to "NETRJS [TTY]" alongside the EBCDIC and ASCII variants. Later RFC 755 updated socket 73 as "NETRJS (ASCII-68)" and socket 75 as "NETRJS (ASCII-63)".

Port 77

Assigned in RFC 739 to "any private RJE server".

Port 79 – finger (Name/Finger)

An ASCII protocol for querying online user information, allowing to query either a free-form list of all logged-in users (similar to 'systat' or Unix 'who'), or detailed information about a specific user (including their contact information, where they are logged in from, and the "plan" file).

Originally assigned in RFC 739 and defined in RFC 742 (which includes several output examples). Unlike e.g. SYSTAT (port 11), the Finger protocol was quite widespread among various operating systems until the 2000s; a Finger client is included with Windows to this day.

This site has a Finger service, as well as a web-based gateway.

Port 81 – hosts2-ns (HOSTS2 Name Server)

Assigned in RFC 820 without much explanation.

"An interesting story. The name attached to this port in the IANA list, Earl Killian, says he shouldn't be. He says "I don't know what 81 is, or whether it is still in use." Since Mr. Killian doesn't know what HOSTS2 is/was, and with Postel gone, I wonder if there's anyone left in the world who knows what 81 was/is for and who actually requested it."

Registered by Earl Killian <EAK@S1-C.ARPA>, <EAK@MORDOR.S1.GOV> of Lawrence Livermore National Labs. Removed by IANA on 2007-09-06.

Before that, NCP socket 81 was assigned to "Network BSYS" in RFC 739, again without any protocol reference.

Port 82 – xfer (XFER Utility)

"Another interesting story. The name attached to this port in the IANA list, Thomas M. Smith of Lockheed Martin, says "Sorry... there is no publicly available information regarding the details of the XFER Utility and its use of tcp and udp port #82. XFER employs a proprietary protocol which has not been disclosed."

Port 83, 85 – mit-ml-dev

RFC 750 listed NCP sockets 83 and 85 as "MIT ML Device" under the Host-Specific Functions category, without any specification reference (later a reference to David Moon as registrant was added).

Port 87 – priv-term-l (Any Private Terminal Link)

RFC 770 assigned this to "any terminal link".

Port 89 – su-mit-tg (SU/MIT Telnet Gateway)

RFC 770 assigned this to "SU/MIT Telnet Gateway" under the Host-Specific Functions category; later RFC 776 added a reference to Mark Crispin at Stanford but no document specification.

Port 91 – mit-dov (MIT Dover Spooler)

RFC 776 assigned this to "MIT Dover Spooler" under the Host-Specific Functions category, with a reference to Eliot Moss at MIT but no specification document.

Port 93 – dcp

RFC 820 assigned this to "Device Control Protocol", with the only reference being Dan Tappan (BBN) as the registrant.

Port 95 – supdup

A remote logon protocol similar in purpose to Telnet, but used primarily by MIT ITS systems.

First mentioned in RFC 739 with a reference to:

Currently implemented by PuTTY.

Port 97 – swift-rvf

RFC 923 assigns this to "Swift Remote Vitural File Protocol", with the only reference being Mark A. Rosenstein at MIT.


Before that, RFC 750 listed NCP socket 97 as "Datacomputer Status" under the Host-Specific Functions category, related to the "Datacomputer at CCA" socket 67. Eventually removed in RFC 900.

Port 98 – tacnews (TAC News)

Assigned in RFC 960, with the only reference being Francine Perillo at SRI.

Most likely used by ARPANET TACs (aka TIPs) to retrieve news by calling telnet sri-nic tacnews when the @NEWS command was invoked.

Port 99 – metagram (Metagram Relay)

Assigned in RFC 820 to "Metagram Relay", with only Geoff Goodfellow at SRI (Geoff@DARCOM-KA) as the registrant.

Port 101 – hostname (NIC Host Name Server)

Assigned in RFC 820 to "NIC Host Name Server", referencing RFC 811:

This was an interim protocol for distributing HOSTS.TXT tables before the network switched to dynamic lookup protocols such as DNS.

Port 102 – iso-tsap

Assigned in RFC 990.

Port 103

RFC 820 had temporarily assigned this to "CSNET Mailbox Name Server (Telnet)", with the same reference as port 105; this was removed in RFC 870, leaving only the "Program" variant on port 105.

Later port 103 was assigned to "X.400" in RFC 990, together with "X.400 Send" on port 104.

Port 105 – cso or csnet-ns

RFC 2378 "The CCSO Nameserver (Ph) Architecture". Called so because it comes from the Computing and Communications Services Office (i.e. CCSO) of University of Illinois at Urbana-Champaign.

RFC 820 had originally assigned this to "CSNET Mailbox Name Server (Program)", referencing:

Port 107 – rtelnet

Assigned in RFC 820 to "Remote Telnet Service", with reference to RFC 818:

Port 109 – pop2 (Post Office Protocol)

Assigned in RFC 900 for the first version of the POP protocol, becoming version 2 in RFC 943.

Port 111 – sunrpc

RFC 923 assigns this to "SUN Remote Procedure Call", and it's the same portmapper or rpcbind service that you might know from NFSv3 (although in earlier times it was used for a great many more protocols).

Port 113 – auth (Authentication Service)

RFC 923 assigns this to an "Authentication Service" as defined in RFC 912.

This is more commonly known as the identd protocol, and is still encountered as part of IRC.

Port 115 – sftp (Simple File Transfer Protocol)

Assigned in RFC 943 to a "Simple File Transfer Protocol" that references:

Not to be confused with the now more common SFTP that is the "SSH File Transfer Protocol" (port 22), nor with FTPS.

Port 117 – uucp-path (UUCP Path Service)

Assigned in RFC 923 to the "UUCP Path Service" protocol defined in RFC 915:

Port 119 – nntp

Originally assigned in RFC 943 to a "USENET News Transfer Protocol".

Port 121 – erpc (HYDRA Expedited Remote Procedure Call)

Assigned in RFC 960 to:

Port 123 – ntp (Network Time Protocol)

Assigned in RFC 960 to the same NTP that is still widely in use:

Port 125 – locus-map (Locus PC-Interface Net Map Server)
Port 127 – locus-con (Locus PC-Interface Conn Server)

Both assigned in RFC 960 to:

Port 129 – pwdgen (Password Generator Protocol)

Assigned in RFC 990 to:

Port 130 – cisco-fna (CISCO FNATIVE)
Port 131 – cisco-tna (CISCO TNATIVE)
Port 132 – cisco-sys (CISCO SYSMAINT)

Assigned in RFC 990 without explanation.

Port 243 – sur-meas

Assigned in RFC 433 for "Survey Data [Kampe @ NMC]". Later RFC 739 updates the reference to:

At the time, it was in the "Experimental Functions" section, accompanied by a similar "NCP Measurement" socket 241 (RFC 388).

Port 245 – link

Assigned in RFC 433 to "LINK [Bressler @ BBN]". Later a reference added to: