Skip to main content

Port Details

Port
443
Transport
TCP / UDP
Service
HTTPS
IANA service name
https
Range
System port (0-1023)
Related ports

Security Exposure

HTTPS is meant to be reachable, so the risk sits in the web application behind it and in the TLS configuration. TLS 1.0 and 1.1 are formally deprecated and lack support for current cryptographic algorithms. A server that still negotiates deprecated TLS versions or weak cipher suites weakens the protection HTTPS is supposed to provide.

Hardening

  • +Disable TLS 1.0 and 1.1, require TLS 1.2, and prefer TLS 1.3 where clients support it.
  • +Send an HTTP Strict-Transport-Security header so browsers interact with the site only over secure connections (RFC 6797).
  • +Keep management and admin interfaces off the public 443 listener, or put them behind a VPN or identity-aware proxy.
  • +Patch the web server, reverse proxy and application frameworks on a fixed schedule.
  • +Renew certificates automatically and monitor expiry dates.

Monitoring

Collect web server and reverse proxy access logs, and track negotiated TLS versions so legacy clients are visible before older versions are switched off. Alert on new listeners on 443 that are not in the asset inventory.

Tools for Auditing and Monitoring HTTPS

ZAP

Open Source
Application Security Tools

Open-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.

LicenseApache-2.0
PlatformLinux, Windows, macOS

Nikto

Free / Commercial
Vulnerability Scanning

Web server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.

LicenseGPL-3.0-only (code); database files restricted to use with Nikto
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is port 443 TCP or UDP?→

Both. HTTPS over HTTP/1.1 and HTTP/2 uses TCP 443, and HTTP/3 runs over QUIC on UDP. RFC 9114 tells clients to fall back to TCP-based HTTP when UDP is blocked.

Which TLS versions should a server on port 443 accept?→

RFC 8996 deprecates TLS 1.0 and 1.1. RFC 9325 says implementations must support TLS 1.2, should support TLS 1.3, and must prefer TLS 1.3 when it is available.

What is the difference between port 80 and port 443?→

Port 80 carries plain HTTP. Port 443 is the default for https URIs, where HTTP runs inside TLS so traffic is encrypted and the server is authenticated by certificate.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 443 is not guaranteed to be HTTPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).