---
title: What Port Does TLS Use? | SendHQ
description: TLS has no single port. Learn how application protocols choose ports, how implicit TLS differs from STARTTLS, and which SMTP port to configure.
canonical: https://sendhq.cc/terms/what-port-does-tls-use
last-updated: 2026-08-26
---
# What Port Does TLS Use?

TLS does not use one universal port. TLS protects many application protocols, and each secured service uses its own assigned port or upgrades an existing connection with a command such as STARTTLS. Common examples are HTTPS on 443, SMTP submission with implicit TLS on 465, IMAP over TLS on 993, and POP3 over TLS on 995.

## TLS has no universal port

TLS is an application-protocol-independent security layer, so the correct port comes from the service running above it, not from TLS itself. HTTPS commonly uses TCP port 443, while secured mail access uses different ports. Saying that a server supports TLS is therefore incomplete configuration information. A client also needs the hostname, application protocol, port, and expected TLS mode.

## Implicit TLS and STARTTLS use ports differently

With implicit TLS, the TLS handshake starts immediately after the TCP connection opens. Email examples include SMTP submission on port 465, IMAP over TLS on 993, and POP3 over TLS on 995. With STARTTLS, the client first connects using the application protocol and then requests an upgrade to TLS. The client and server must agree on the same mode; choosing port 465 while configuring STARTTLS often causes a handshake or timeout error.

## Which TLS port should SMTP clients use

For authenticated message submission, use the exact port and security mode documented by the email provider. Port 587 commonly uses SMTP submission followed by STARTTLS, while port 465 uses implicit TLS from the first byte. Port 25 is primarily used for server-to-server SMTP relay and may use STARTTLS opportunistically. Port 2525 is a provider-specific alternative, not the universal TLS or SMTP port.

## How to diagnose a TLS port failure

Confirm the provider hostname, port, and encryption mode before changing credentials or certificates. Test basic TCP reachability, then inspect whether the server expects an immediate TLS handshake or an application command before STARTTLS. A timeout usually points to routing, firewall, or port blocking; an immediate protocol error often indicates a mismatch between implicit TLS and STARTTLS. Certificate validation and authentication happen after the connection mode is correct.

## Questions teams ask

**Is port 443 the TLS port?**

Port 443 is the standard port for HTTPS, which carries HTTP over TLS. It is not a universal port for every protocol protected by TLS.

**Should SMTP use port 465 or 587?**

Use the provider's documented setting: port 465 normally expects implicit TLS, while port 587 normally starts SMTP and then upgrades with STARTTLS.

**Does STARTTLS require a separate TLS port?**

No. STARTTLS upgrades an existing application-protocol connection on its configured port after the server advertises support and the client requests TLS.

**Why does a TLS connection fail on the correct port?**

The port can be reachable while the TLS mode is wrong. Check whether the endpoint expects implicit TLS or STARTTLS, then verify the hostname and certificate.

## Primary sources

- [RFC 8446: The Transport Layer Security Protocol Version 1.3](https://www.rfc-editor.org/rfc/rfc8446.html) — RFC Editor
- [RFC 8314: Cleartext Considered Obsolete](https://www.rfc-editor.org/rfc/rfc8314.html) — RFC Editor
- [RFC 3207: SMTP Service Extension for Secure SMTP over TLS](https://www.rfc-editor.org/rfc/rfc3207.html) — RFC Editor

## Continue learning

[smtp port](https://sendhq.cc/guides/smtp-port.md) [mail protocol smtp](https://sendhq.cc/guides/mail-protocol-smtp.md) [smtp relay service](https://sendhq.cc/guides/smtp-relay-service.md) [office 365 smtp details](https://sendhq.cc/guides/office-365-smtp-details.md) [google smtp relay service](https://sendhq.cc/guides/google-smtp-relay-service.md)
