40% off with code HYPERLAUNCH

Claim offer
HyperMonitor
PortsGuide 01 of 04

How to check open ports on a Mac

Every app that accepts connections opens a port. Here’s how to see them all from Terminal, find the app behind a specific port, and tell which ones other devices can reach.

4 min read6 commands

Question 01

How do I see which ports are open on my Mac?

Open Terminal and run sudo lsof -iTCP -sTCP:LISTEN -n -P. It lists every TCP socket in the listening state, which means a process is waiting for incoming connections on that port. -iTCP limits the list to TCP sockets, -sTCP:LISTEN keeps only listening ones, -n skips slow hostname lookups and -P prints port numbers instead of service names. Each row shows the command name, its process ID (PID), the user it runs as and, in the NAME column, the address and port, such as *:5000 or 127.0.0.1:5432. Running it with sudo matters: without administrator rights, macOS only shows sockets that belong to your own user, so services running as root or as system users are missing. UDP has no listening state, so list UDP sockets separately with sudo lsof -iUDP -n -P. Expect to see a handful of Apple services on a normal Mac; that is not a problem in itself.

Terminal — zsh
# Every listening TCP port, with the process that owns itsudo lsof -iTCP -sTCP:LISTEN -n -P# Every UDP socketsudo lsof -iUDP -n -P

Question 02

How do I find what’s using a specific port, like 3000 or 8000?

Ask lsof about that one port: lsof -nP -iTCP:3000 -sTCP:LISTEN. Add sudo if nothing shows up, because the owner may be another user. The output gives you the command name and the PID. The command name is often just node, python3 or java, so look up the full command line with ps -p 1234 -o pid,user,command, replacing 1234 with the PID; that usually reveals which project or script started it. To free the port, quit the app or stop the server normally first. If it’s a stray process, kill 1234 asks it to exit, and kill -9 1234 forces it if it ignores that. Check the name before you kill anything: ending a system process can make macOS unstable, and some, like the AirPlay Receiver that holds ports 5000 and 7000 on recent macOS versions, are better turned off in System Settings than killed.

Terminal — zsh
# Who is listening on port 3000?lsof -nP -iTCP:3000 -sTCP:LISTEN# Full command line for a PIDps -p 1234 -o pid,user,command# Ask the process to quitkill 1234

Question 03

What’s the difference between 127.0.0.1, 0.0.0.0 and * in the output?

The address in front of the port tells you who can connect. 127.0.0.1 (or localhost, or [::1] for IPv6) is the loopback address: only software on this Mac can reach that port. *, 0.0.0.0 and [::] mean the process is listening on every network interface, so other devices on the same network can try to connect too, unless the macOS firewall or your router blocks them. A database or development server bound to * on café Wi-Fi is reachable by anyone on that Wi-Fi. A specific address, such as your Mac’s LAN IP, limits it to that one interface. For your own tools, the safe default is to bind to 127.0.0.1 unless you need another device to reach them. You can also turn on the built-in firewall in System Settings › Network › Firewall, which asks before unknown apps accept incoming connections.

Question 04

Can I use netstat or Activity Monitor instead?

Yes, with limits. netstat -an -p tcp | grep LISTEN lists listening addresses and ports quickly, but on macOS its default output doesn’t say which process owns each socket, so you still need lsof to match a port to an app. Activity Monitor can show ports for one process at a time: select the process, click the Info button in the toolbar, and open the Open Files and Ports tab. That works when you already suspect a specific app, but it doesn’t give you a single list of everything listening. For a full picture, lsof is the most complete built-in tool, as long as you run it with sudo so other users’ sockets are included. None of these tools tell you whether a listener is expected. For that, look at the process name, where its executable lives and who signed it, and check whether it is bound to localhost or to the whole network.

Terminal — zsh
# Listening TCP sockets, without process namesnetstat -an -p tcp | grep LISTEN