HTTP & HTTPS — Complete Guide

Protocols, Ports, Status Codes & HTTP Methods

A quick reference for interviews & web development

1. What is a Protocol?

A protocol is a set of agreed rules that defines how two devices (or programs) communicate over a network. Just like humans need a common language to talk, computers need protocols to exchange data so both sides understand the format, order, and meaning of messages.

Simple way to explain it: "A protocol is like grammar rules for computer conversations — both sides must follow the same rules, otherwise the message makes no sense."

Examples:

2. What is a Port?

A port is a numbered doorway (0–65535) on a computer that identifies a specific service or application. While an IP address finds the machine on a network, the port finds the correct program/service on that machine. Ports let one server run many services at the same time (a website, a mail server, a database) on a single IP address.

Simple way to explain it: "IP address = building address, Port = apartment/office number inside that building."

Example URL with a port: http://example.com:8080/page  → here 8080 is the port.

Common Port Numbers

PortProtocol / ServiceUsed For
20 / 21FTPFile Transfer (data / control)
22SSH / SFTPSecure remote login & secure file transfer
23TelnetUnencrypted remote login (legacy, insecure)
25SMTPSending email
53DNSDomain name resolution
67 / 68DHCPAutomatic IP address assignment
80HTTPWeb browsing (unencrypted)
110POP3Receiving (downloading) email
143IMAPReceiving/syncing email on server
443HTTPSWeb browsing (encrypted, secure)
465 / 587SMTPS / SMTP (submission)Sending email securely
3306MySQLMySQL database connections
3389RDPWindows Remote Desktop
5432PostgreSQLPostgreSQL database connections
6379RedisRedis cache / in-memory DB
8080 / 8443HTTP altCommon alternate web/app server ports
27017MongoDBMongoDB database connections

Port ranges: 0–1023 = Well-known (reserved for standard services)  |  1024–49151 = Registered (common apps)  |  49152–65535 = Dynamic/Ephemeral (temporary, client-side).

3. What is HTTP?

HTTP (HyperText Transfer Protocol) is the foundation of data communication on the World Wide Web. It is a request–response protocol: the client (usually a browser) sends a request, and the server sends back a response (a web page, JSON, an image, etc.).

How a simple HTTP flow works

1. You type http://example.com in the browser 2. Browser resolves example.com → 93.184.216.34 (DNS, port 53) 3. Browser opens a TCP connection to 93.184.216.34 on port 80 4. Browser sends the HTTP request: GET /index.html HTTP/1.1 Host: example.com 5. Server responds: HTTP/1.1 200 OK Content-Type: text/html <html>...page content...</html> 6. Browser renders the page. Connection may be reused or closed.

4. What is HTTPS?

HTTPS (HTTP Secure) is HTTP running over an encrypted connection (usually TLS — Transport Layer Security) on port 443. The data between browser and server is scrambled, so even if someone intercepts it, they cannot read or modify it.

HTTP vs HTTPS

FeatureHTTPHTTPS
Full formHyperText Transfer ProtocolHTTP Secure (HTTP over TLS/SSL)
Default port80443
EncryptionNone — plain textYes — TLS encrypted
SecurityData can be read/modified in transitConfidentiality + integrity + server identity
CertificateNot requiredRequires an SSL/TLS certificate (from a CA)
Use casePublic, non-sensitive content (rare today)Logins, payments, personal data — the modern default

How HTTPS protects you (3 guarantees): Encryption (nobody can read the data), Integrity (data cannot be modified undetected), Authentication (the certificate proves you are talking to the real website, not an impostor).

5. HTTP Status Codes

A status code is a 3-digit number the server returns with every response, telling the client whether the request succeeded or failed, and why. They are grouped into 5 classes:

ClassMeaning
1xxInformational (request received, keep going)
2xxSuccess
3xxRedirection (further action needed)
4xxClient Error (the request was wrong)
5xxServer Error (the server failed to handle a valid request)

Important status codes in detail

CodeNameMeaning & Example
200OK Success. The request worked and the response contains the data. Example: page loaded, API returned JSON.
301Moved Permanently The resource has permanently moved to a new URL. Browsers and search engines update to the new address. Example: http://site.com → https://www.site.com redirect.
302Found (Temporary) The resource is temporarily at a different URL; the old URL should still be used in future. Example: redirect to a maintenance page or temporary promo URL.
401Unauthorized You are not authenticated — no valid login/credentials/token. Usually fixed by logging in. Example: calling an API without a valid JWT token.
403Forbidden Server knows who you are, but you don't have permission to access this resource. Logging in again won't help. Example: a normal user trying to open an admin page.
404Not Found The resource doesn't exist at this URL (or the server won't reveal it). Example: typo in a URL, deleted page, wrong API route.
501Not Implemented The server doesn't support the functionality needed to fulfil the request (e.g., an unknown/unimplemented HTTP method). Example: server that never implemented PATCH receives a PATCH request.
502Bad Gateway A gateway/proxy (e.g., Nginx, Cloudflare) received an invalid response from the upstream/backend server. Example: your app server crashed behind a load balancer.
503Service Unavailable The server is temporarily unable to handle the request — overloaded or down for maintenance. Usually temporary; may include a Retry-After header. Example: traffic spike, deployment in progress.
504Gateway Timeout The gateway/proxy waited too long for the upstream server and gave up (timeout). Example: backend took 60+ seconds to respond while the proxy timed out after 30s.
Quick memory tricks: 401 = "Who are you?" (no identity)  |  403 = "I know you, but no." (no permission)  |  404 = "Wrong address."  |  301 = permanent move  |  302 = temporary detour  |  502/504 = middleman problems (proxy ↔ backend)  |  503 = server busy/down.

6. HTTP Methods

HTTP methods (also called verbs) tell the server what action to perform on a resource. Think of them as CRUD operations on data.

MethodPurposeDetails
GETRead / fetch data Requests a resource; must not change server data (safe). Parameters go in the URL, can be bookmarked/cached. Example: GET /users/5 → fetch user #5.
POSTCreate / submit data Sends data in the request body to create something or trigger an action; not cacheable, not idempotent (repeating may create duplicates). Example: POST /users with new user details in body.
PUTUpdate / replace fully Replaces the entire resource with the data sent; idempotent (calling it 1× or 10× gives the same result). Example: PUT /users/5 replaces all fields of user #5.
DELETEDelete a resource Removes the specified resource; idempotent (deleting twice → still gone). Example: DELETE /users/5.
HEADGET without the body Same as GET but the response has headers only, no body. Used to check if a resource exists, its size, or last-modified date — cheap and fast. Example: HEAD /files/big.zip → check size before downloading.

Other methods you may hear about

Idempotent means "same result no matter how many times you repeat it." GET, PUT, DELETE, HEAD are idempotent; POST is not.

Typical REST API mapping (CRUD)

GET /users → list all users (Read) POST /users → create a new user (Create) GET /users/5 → get user #5 (Read) PUT /users/5 → replace user #5 (Update) PATCH /users/5 → partially update user #5 (Update) DELETE /users/5 → delete user #5 (Delete)

7. One-Page Cheat Sheet

TopicKey Point
ProtocolSet of rules for communication between computers (HTTP, TCP/IP, FTP, SMTP, DNS…)
PortNumbered door (0–65535) on a machine identifying a service; IP finds the machine, port finds the service
HTTPRequest–response protocol for the web, port 80, stateless, unencrypted
HTTPSHTTP + TLS encryption, port 443, needs SSL certificate — secure, authenticated, tamper-proof
200OK — success
301 / 302Redirect — permanent / temporary
401 / 403 / 404No login / no permission / not found
501 / 502 / 503 / 504Not implemented / bad gateway / service unavailable / gateway timeout
GET / POSTRead data / create data
PUT / DELETEFull update / delete (both idempotent)
HEADGET with headers only — check existence/metadata

www.kushlearn.in · HTTP & HTTPS Complete Guide · For learning & interview reference