Find Which Process Is Using a Port (Linux)

The fastest reliable answer on a modern Linux is one ss command — here's the exact invocation, plus why netstat output misleads people.

What you'll see

Root causes

Another process legitimately bound the port

Common double-booking: an old instance of the same app, or a second web server squatting on 80/443.

Docker's proxy process

dockerd/docker-proxy binds published ports — ps output shows 'docker-proxy', which confuses netstat readers.

Fix it

  1. The one-liner (process name, PID, everything)
    sudo ss -ltnp | grep -E ':443\b'
  2. Map the PID to its full command and working dir
    ps -fp <PID> && ls -l /proc/<PID>/cwd
  3. If it's docker-proxy, find which container owns it
    docker ps --format '{{.Names}} {{.Ports}}' | grep 443
  4. Gracefully stop it (or repoint your new service)
    sudo kill <PID>   # prefer systemctl stop <unit> when known

Field note

Use sudo with ss even as root — without it, process names for other users' sockets are hidden, which is exactly the case when you can't identify the holder. lsof -i :443 is the older equivalent if ss isn't available.

Common questions

What's the fastest way to see what's on a port?

ss -ltnp | grep :<port> (modern) or lsof -i :<port>. ss shows the process name/PID for sockets it owns; run with sudo to see processes owned by other users — the #1 reason people 'can't find' what's on the port.

Why does nothing show up on the port though the app says it's listening?

It's bound to a different interface (127.0.0.1 vs 0.0.0.0 — check ss for the bind address) or a different port (config mismatch). The bind address in ss output is the ground truth the app's config never shows you.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.

Get new fixes by email

One short email when new fixes and production templates drop. No spam, unsubscribe anytime.

Partner pick — sponsored

Vultr — our lab-environment pick for this stack

Spin up a cloud server in 60 seconds and reproduce this fix yourself — pay by the hour.

Get Vultr →
Also vetted

Sentry — Free tier: see the exact line of code that broke, before users report it.

Get Sentry →

We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush