Port 443: HTTP over TLS
Port 443 is the default port for the https URI scheme, where HTTP runs over TLS on TCP. HTTP/3 runs over QUIC on UDP, and RFC 9114 has clients use the scheme's default port when a URI gives none, so HTTP/3 servers commonly listen on UDP 443 as well. Windows SMB over QUIC also uses UDP 443 by default.
Port Details
Security Exposure
HTTPS is meant to be reachable, so the risk sits in the web application behind it and in the TLS configuration. TLS 1.0 and 1.1 are formally deprecated and lack support for current cryptographic algorithms. A server that still negotiates deprecated TLS versions or weak cipher suites weakens the protection HTTPS is supposed to provide.
Hardening
- +Disable TLS 1.0 and 1.1, require TLS 1.2, and prefer TLS 1.3 where clients support it.
- +Send an HTTP Strict-Transport-Security header so browsers interact with the site only over secure connections (RFC 6797).
- +Keep management and admin interfaces off the public 443 listener, or put them behind a VPN or identity-aware proxy.
- +Patch the web server, reverse proxy and application frameworks on a fixed schedule.
- +Renew certificates automatically and monitor expiry dates.
Monitoring
Collect web server and reverse proxy access logs, and track negotiated TLS versions so legacy clients are visible before older versions are switched off. Alert on new listeners on 443 that are not in the asset inventory.
Tools for Auditing and Monitoring HTTPS
ZAP
Open SourceOpen-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.
Nikto
Free / CommercialWeb server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
Is port 443 TCP or UDP?→
Both. HTTPS over HTTP/1.1 and HTTP/2 uses TCP 443, and HTTP/3 runs over QUIC on UDP. RFC 9114 tells clients to fall back to TCP-based HTTP when UDP is blocked.
Which TLS versions should a server on port 443 accept?→
RFC 8996 deprecates TLS 1.0 and 1.1. RFC 9325 says implementations must support TLS 1.2, should support TLS 1.3, and must prefer TLS 1.3 when it is available.
What is the difference between port 80 and port 443?→
Port 80 carries plain HTTP. Port 443 is the default for https URIs, where HTTP runs inside TLS so traffic is encrypted and the server is authenticated by certificate.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 443 is not guaranteed to be HTTPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).