Skip to main content

Port Checker

Check whether a TCP port on a public host accepts connections from outside your network, and tell a closed port from a filtered one.

This tool needs our server to process your file. It is sent over an encrypted connection, stored only while it is being processed, and deleted automatically within 60 minutes. We never read the contents or keep a copy.

This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.

About the Port Checker

Check whether a TCP port on a publicly reachable host accepts a connection from outside your own network. This is the question behind most "the service is running but nobody can reach it" problems — the port is listening on the machine and something between it and the internet is not letting anyone in.

The tool distinguishes three answers, and the distinction matters. Open means the connection was accepted, so something is listening. Closed means it was actively refused: the host is reachable and nothing is listening on that port. Filtered means no answer at all within three seconds, which usually means a firewall dropped the packet rather than refusing it. A tool that reports both of the last two as "closed" throws away the most useful piece of information you get.

Nothing is read from the connection. As soon as a port accepts, the socket is closed — this answers whether the port is open, not what is running behind it. Banner grabbing would turn a reachability check into fingerprinting, which is a different tool with different obligations.

Only public hosts can be checked. Private, loopback, link-local and reserved ranges are refused — and refused after resolution, so a host name that points into private space is rejected too. One port is checked per request; there is no range scanning, deliberately.

How to use the Port Checker

  1. Enter the host

    A domain name or a public IP address. Private and internal addresses are refused, including host names that resolve to them.

  2. Choose the port

    Pick a common service from the list or type any port from 1 to 65535. One port per check.

  3. Run the check

    One connection attempt, with a three-second timeout. The result reports the address actually used, since a name may resolve to several.

  4. Read the state

    Open means something is listening. Closed means the host refused. Filtered means nothing answered, which usually means a firewall is dropping the traffic.

Frequently asked questions

What is the difference between a closed port and a filtered one?

A closed port actively refuses the connection — the host is up and reachable, and nothing is listening there. A filtered port simply never answers, which is what a firewall configured to drop rather than reject looks like. If you are debugging a service that will not accept connections, filtered usually points at a firewall or security group while closed points at the service not running.

Why can I not check a port on my own computer?

Because the check runs from our server, not from your browser, so 127.0.0.1 and 192.168.x.x would mean our machine and our network — not yours. Those ranges are refused for that reason and for security: a tool that connects to arbitrary internal addresses on request is a server-side request forgery vulnerability with a friendly interface.

Why only one port at a time?

Because diagnosing a service needs one port and scanning a host needs thousands. Accepting ranges would make this a port scanner running from our address, which is a problem for us and potentially for you — many networks treat an inbound scan as an attack regardless of intent.

The port is open on my server but this says filtered. Why?

Something between the internet and your service is dropping the traffic. The usual candidates are a cloud security group or network ACL, a host firewall such as ufw or firewalld, a router without the port forwarded, or an ISP blocking the port — 25 and 445 are very commonly blocked. That the service is listening locally tells you nothing about what happens before the packet reaches it.

What do you log?

The tool records that a check happened, so we can spot abuse, and nothing about who asked or what was checked — no IP addresses, no host names, no ports. The check itself reads nothing from the connection and closes it immediately.