Port 389: LDAP
Port 389 is LDAP, the directory protocol behind Active Directory and many company login systems.
What runs on port 389
LDAP servers listen on TCP 389 to answer questions about users, groups and computers, and to check passwords. Microsoft Active Directory domain controllers are the most common LDAP servers; OpenLDAP is the common open-source one. Connectionless LDAP (CLDAP) uses UDP 389.
On a home network
Home devices basically never run LDAP servers. Some NAS boxes offer an LDAP server package for small offices, and office printers can query a directory for email addresses.
If port 389 is reachable from the internet
A directory server reachable from the internet leaks information about users and systems and invites password spraying. CLDAP on UDP 389 has been widely abused for DDoS amplification. There is almost never a good reason to expose 389; keep directory traffic inside the network or on a VPN.
How to check whether it is open on your network
If a scan of your public address shows 389, find the server behind the port forward, usually a NAS directory service or a Windows server, and close it.
To find out whether port 389 is open on something in your home, and whether the internet can reach it, the app scans your Wi-Fi from your phone and checks your public address from the outside. It says what it checked and what it could not. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.