Port 636: LDAPS
Port 636 is LDAP over TLS, the encrypted form of directory lookups and logins.
What runs on port 636
LDAPS wraps LDAP in TLS on TCP 636 so usernames and passwords checked against a directory are not sent in the clear. Active Directory domain controllers offer it when they have a certificate. The alternative is STARTTLS on 389.
On a home network
Home devices rarely use it. NAS boxes offering a directory server and small-office Windows servers may listen on 636.
If port 636 is reachable from the internet
Encryption protects the connection but not the directory. A reachable 636 still lets attackers try passwords and probe the directory, so it should be limited to the internal network or a VPN.
How to check whether it is open on your network
If an outside scan shows 636, trace the port forward to the server behind it and close it unless you intentionally provide a public directory.
To find out whether port 636 is open on something in your home, and whether the internet can reach it, the app scans your Wi-Fi from your phone and checks your public address from the outside. It says what it checked and what it could not. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.