HTTP & HTTPS — Complete Guide
Protocols, Ports, Status Codes & HTTP Methods
A quick reference for interviews & web development
1. What is a Protocol?
A protocol is a set of agreed rules that defines how two devices (or programs) communicate over a network. Just like humans need a common language to talk, computers need protocols to exchange data so both sides understand the format, order, and meaning of messages.
Examples:
- HTTP/HTTPS — browsing websites (transferring web pages)
- TCP — reliable delivery of data between machines
- IP — addressing and routing packets across networks
- FTP — transferring files
- SMTP / POP3 / IMAP — sending & receiving email
- DNS — translating domain names to IP addresses
2. What is a Port?
A port is a numbered doorway (0–65535) on a computer that identifies a specific service or application. While an IP address finds the machine on a network, the port finds the correct program/service on that machine. Ports let one server run many services at the same time (a website, a mail server, a database) on a single IP address.
Example URL with a port: http://example.com:8080/page → here 8080 is the port.
Common Port Numbers
| Port | Protocol / Service | Used For |
|---|---|---|
| 20 / 21 | FTP | File Transfer (data / control) |
| 22 | SSH / SFTP | Secure remote login & secure file transfer |
| 23 | Telnet | Unencrypted remote login (legacy, insecure) |
| 25 | SMTP | Sending email |
| 53 | DNS | Domain name resolution |
| 67 / 68 | DHCP | Automatic IP address assignment |
| 80 | HTTP | Web browsing (unencrypted) |
| 110 | POP3 | Receiving (downloading) email |
| 143 | IMAP | Receiving/syncing email on server |
| 443 | HTTPS | Web browsing (encrypted, secure) |
| 465 / 587 | SMTPS / SMTP (submission) | Sending email securely |
| 3306 | MySQL | MySQL database connections |
| 3389 | RDP | Windows Remote Desktop |
| 5432 | PostgreSQL | PostgreSQL database connections |
| 6379 | Redis | Redis cache / in-memory DB |
| 8080 / 8443 | HTTP alt | Common alternate web/app server ports |
| 27017 | MongoDB | MongoDB database connections |
Port ranges: 0–1023 = Well-known (reserved for standard services) | 1024–49151 = Registered (common apps) | 49152–65535 = Dynamic/Ephemeral (temporary, client-side).
3. What is HTTP?
HTTP (HyperText Transfer Protocol) is the foundation of data communication on the World Wide Web. It is a request–response protocol: the client (usually a browser) sends a request, and the server sends back a response (a web page, JSON, an image, etc.).
- It is an application-layer protocol that typically runs over TCP (port 80).
- It is stateless — the server does not remember previous requests; each request is independent. (Sessions/cookies are used to simulate state.)
- It is plain text (unencrypted) — anyone intercepting the traffic can read it, which is why HTTPS was created.
How a simple HTTP flow works
4. What is HTTPS?
HTTPS (HTTP Secure) is HTTP running over an encrypted connection (usually TLS — Transport Layer Security) on port 443. The data between browser and server is scrambled, so even if someone intercepts it, they cannot read or modify it.
HTTP vs HTTPS
| Feature | HTTP | HTTPS |
|---|---|---|
| Full form | HyperText Transfer Protocol | HTTP Secure (HTTP over TLS/SSL) |
| Default port | 80 | 443 |
| Encryption | None — plain text | Yes — TLS encrypted |
| Security | Data can be read/modified in transit | Confidentiality + integrity + server identity |
| Certificate | Not required | Requires an SSL/TLS certificate (from a CA) |
| Use case | Public, non-sensitive content (rare today) | Logins, payments, personal data — the modern default |
How HTTPS protects you (3 guarantees): Encryption (nobody can read the data), Integrity (data cannot be modified undetected), Authentication (the certificate proves you are talking to the real website, not an impostor).
5. HTTP Status Codes
A status code is a 3-digit number the server returns with every response, telling the client whether the request succeeded or failed, and why. They are grouped into 5 classes:
| Class | Meaning |
|---|---|
| 1xx | Informational (request received, keep going) |
| 2xx | Success |
| 3xx | Redirection (further action needed) |
| 4xx | Client Error (the request was wrong) |
| 5xx | Server Error (the server failed to handle a valid request) |
Important status codes in detail
| Code | Name | Meaning & Example |
|---|---|---|
| 200 | OK | Success. The request worked and the response contains the data. Example: page loaded, API returned JSON. |
| 301 | Moved Permanently | The resource has permanently moved to a new URL. Browsers and search engines update to the new address. Example: http://site.com → https://www.site.com redirect. |
| 302 | Found (Temporary) | The resource is temporarily at a different URL; the old URL should still be used in future. Example: redirect to a maintenance page or temporary promo URL. |
| 401 | Unauthorized | You are not authenticated — no valid login/credentials/token. Usually fixed by logging in. Example: calling an API without a valid JWT token. |
| 403 | Forbidden | Server knows who you are, but you don't have permission to access this resource. Logging in again won't help. Example: a normal user trying to open an admin page. |
| 404 | Not Found | The resource doesn't exist at this URL (or the server won't reveal it). Example: typo in a URL, deleted page, wrong API route. |
| 501 | Not Implemented | The server doesn't support the functionality needed to fulfil the request (e.g., an unknown/unimplemented HTTP method). Example: server that never implemented PATCH receives a PATCH request. |
| 502 | Bad Gateway | A gateway/proxy (e.g., Nginx, Cloudflare) received an invalid response from the upstream/backend server. Example: your app server crashed behind a load balancer. |
| 503 | Service Unavailable | The server is temporarily unable to handle the request — overloaded or down for maintenance. Usually temporary; may include a Retry-After header. Example: traffic spike, deployment in progress. |
| 504 | Gateway Timeout | The gateway/proxy waited too long for the upstream server and gave up (timeout). Example: backend took 60+ seconds to respond while the proxy timed out after 30s. |
6. HTTP Methods
HTTP methods (also called verbs) tell the server what action to perform on a resource. Think of them as CRUD operations on data.
| Method | Purpose | Details |
|---|---|---|
| GET | Read / fetch data | Requests a resource; must not change server data (safe). Parameters go in the URL, can be bookmarked/cached. Example: GET /users/5 → fetch user #5. |
| POST | Create / submit data | Sends data in the request body to create something or trigger an action; not cacheable, not idempotent (repeating may create duplicates). Example: POST /users with new user details in body. |
| PUT | Update / replace fully | Replaces the entire resource with the data sent; idempotent (calling it 1× or 10× gives the same result). Example: PUT /users/5 replaces all fields of user #5. |
| DELETE | Delete a resource | Removes the specified resource; idempotent (deleting twice → still gone). Example: DELETE /users/5. |
| HEAD | GET without the body | Same as GET but the response has headers only, no body. Used to check if a resource exists, its size, or last-modified date — cheap and fast. Example: HEAD /files/big.zip → check size before downloading. |
Other methods you may hear about
- PATCH — partial update (change only some fields, unlike PUT's full replace).
- OPTIONS — ask the server which methods are allowed (used in CORS pre-flight).
Typical REST API mapping (CRUD)
7. One-Page Cheat Sheet
| Topic | Key Point |
|---|---|
| Protocol | Set of rules for communication between computers (HTTP, TCP/IP, FTP, SMTP, DNS…) |
| Port | Numbered door (0–65535) on a machine identifying a service; IP finds the machine, port finds the service |
| HTTP | Request–response protocol for the web, port 80, stateless, unencrypted |
| HTTPS | HTTP + TLS encryption, port 443, needs SSL certificate — secure, authenticated, tamper-proof |
| 200 | OK — success |
| 301 / 302 | Redirect — permanent / temporary |
| 401 / 403 / 404 | No login / no permission / not found |
| 501 / 502 / 503 / 504 | Not implemented / bad gateway / service unavailable / gateway timeout |
| GET / POST | Read data / create data |
| PUT / DELETE | Full update / delete (both idempotent) |
| HEAD | GET with headers only — check existence/metadata |
www.kushlearn.in · HTTP & HTTPS Complete Guide · For learning & interview reference