Destination Port
In short: The port on the target device to which a network connection is directed — determines which service accepts the request.
In more detail: Unlike the random source port, the destination port is usually well known, because it addresses the desired service (e.g. destination port 443 for an HTTPS call). A firewall often decides based on the destination port which traffic is let through.
In Depth
The destination port is the decisive factor that tells a server which service should handle an incoming request — on the same server, a web server on port 80/443, an SSH service on port 22 and a mail server on port 25 can run at the same time without interfering with each other, because each service only listens on “its” port. If a packet arrives with a destination port for which no service is actively listening, the operating system usually answers with an error message (e.g. destination unreachable/port unreachable) or ignores the packet, depending on the firewall configuration.
Firewalls often use the destination port as their primary filtering criterion: a typical rule might be “allow incoming traffic on port 443, block all other ports” — this considerably reduces a server’s attack surface, because only the services actually needed remain reachable from outside. This kind of filtering is simple to configure, but doesn’t replace deeper protection of the respective service itself, since an open port with a vulnerable application behind it still remains a security risk.
See also: Source port, Standard port