Port and Service Lookup

Search the port registry in both directions: type a number such as 443 or a service name such as postgresql, and the table shows every assignment that matches, the transport protocol it uses, the range it falls in and what the port is for. The data is a copy of the public registry carried inside this page, so the lookup works with no network connection at all and nothing you type leaves your browser. This page does not scan ports, and it cannot tell you which ports are open on any machine — it tells you what a number means.
Offline reference loaded. Nothing has been sent anywhere.
Type a number or a service name, or pick a sample above.
Well-known ports, 0 to 1023. These are assigned one at a time to specific protocols and are the only ports that mean the same thing everywhere: 22 is SSH, 80 is plain HTTP, 443 is HTTP over TLS. On a server they are normally reachable only by a process with administrative rights, which is exactly why a daemon that has no business listening there is worth a second look.

Registered ports, 1024 to 49151. These are registered the same way but any process may use them, so a number here tells you the registered use rather than the use in front of you: 8080 and 8443 are registered as alternates and are used just as often for something else entirely, and a development server can appear on any number in this range.

Dynamic or private ports, 49152 to 65535. These are deliberately left unassigned: an operating system picks one for the outgoing end of a connection, and it means nothing stable. A number in this range can only be read from the context of one conversation, which is why an offline reference cannot say anything useful about it.

Reading the table. The registry assigns ports to protocol and transport at the same time, and one number can carry several unrelated services: 514 is the remote shell on TCP and syslog on UDP, 465 carries both an older mail submission service and an IGMP variant. When a row lists more than one service name, look at the bracketed transport next to each name before deciding which one your traffic belongs to. A missing number is not an error: the registry simply has no assignment for it, and the page will still tell you which range it falls in.
How to use this list. Nothing here says a port is open — only that if the service behind it answers to anyone who can reach the machine, the risk is higher than the service's age suggests. Check these on machines you own, from the inside, with the tool that ships with the system:

Plaintext by design. 23 telnet 21 ftp 389 ldap 161 snmp — whatever a password or community string crosses the wire in the clear.
File sharing and remote control. 445 139 137 3389 5900 — these are meant for a local network and should never be reachable from the internet, which is why they are the classic entry point found by scanning.
Databases and caches. 3306 1433 5432 6379 27017 11211 — most of these were designed to sit behind an application, and several have no authentication at all in their default configuration.
Control interfaces. 2375 — an API that can start containers on the host, registered in plain text next to an encrypted sibling. Reaching it is equivalent to running commands on the machine.
A number borrowed by a popular service. 9200 — the registry records this as a mobile web service port, and the same number is widely used by a search engine product that is not in the registry. Rows like this are why the table shows the registered purpose and not a list of products.

What to do instead of guessing. On a machine you control, ask the operating system which process holds a port (ss -lntup on Linux, netstat -abno on Windows), and decide from the answer. A port being reachable is a configuration question, and the fix is to stop the service, bind it to the loopback address or put it behind a firewall — in that order.