lsof on Mac: Find a Process by Port
lsof (“list open files”) treats network sockets as files, which makes it the standard way to map a port to a process on macOS.
Core commands
| Goal | Command |
|---|---|
| Who listens on TCP 3000? | lsof -nP -iTCP:3000 -sTCP:LISTEN |
| All TCP listeners | lsof -nP -iTCP -sTCP:LISTEN |
| UDP on port 5353 | lsof -nP -iUDP:5353 |
| IPv6 only | lsof -nP -i6TCP -sTCP:LISTEN |
| One process’s sockets | lsof -nP -a -p 18432 -i |
| Only PIDs | lsof -ti tcp:3000 |
| Everyone’s sockets | sudo lsof -nP -iTCP -sTCP:LISTEN |
Reading the output
COMMAND PID USER FD TYPE DEVICE NODE NAME
node 18432 mohit 23u IPv4 0x1f2 TCP *:3000 (LISTEN)
NAME:*:3000is all interfaces,127.0.0.1:3000localhost only.FD: file descriptor;umeans opened read/write.COMMANDis truncated to 9 characters unless you pass+c 0.
Machine-readable output
lsof -nP +c 0 -iTCP -sTCP:LISTEN -FpcLn
-F prints one field per line (p pid, c command, L user, n name), which is far more robust to parse than columns. PortPeek uses this format internally.
Gotchas
- Without
-n -Plsof resolves names and can be slow. - Plain
-i :3000also matches outgoing connections to port 3000. - No
sudo, no other users’ processes.
Prefer a UI? PortPeek wraps this in a searchable menu-bar list.
PortPeek gives you the same visibility from your Mac menu bar. See what's using your ports. Kill it in one click. It is a free, open-source utility inside MacPeek.