Port 5432 — PostgreSQL
TCP registered
What runs on port 5432
The default PostgreSQL port.
Security considerations
Keep it on a private network. Configure `pg_hba.conf` deliberately — a permissive `host all all 0.0.0.0/0 md5` line is a common and serious mistake.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :5432
sudo ss -lntp | grep :5432
# Windows
netstat -ano | findstr :5432
Get-NetTCPConnection -LocalPort 5432
# is it reachable from outside?
nc -zv example.com 5432
curl -v telnet://example.com:5432
Freeing the port
# find the process, then stop it
sudo lsof -ti :5432 | xargs kill # Linux / macOS
netstat -ano | findstr :5432 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
No. Port 5432 should never be reachable from a public address. Bind it to localhost or a private network, and reach it through a VPN or bastion host if remote access is genuinely needed. Internet-wide scanners find newly exposed instances of this service within minutes.
Quick reference
| Port | 5432 |
| Protocol | TCP |
| Service | PostgreSQL |
| Range | Registered (1024–49151) — any user process may bind |
Frequently asked questions
What is port 5432 used for?
The default PostgreSQL port.
Is it safe to open port 5432?
Keep it on a private network. Configure `pg_hba.conf` deliberately — a permissive `host all all 0.0.0.0/0 md5` line is a common and serious mistake.
How do I check if port 5432 is open?
Locally, sudo lsof -i :5432 on macOS or Linux, or netstat -ano | findstr :5432 on Windows. From outside, nc -zv host 5432 tells you whether anything answers.
Why do I get "address already in use" on port 5432?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :5432 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.