🔌 Port Checker

Test whether common service ports are open on any host. Activates with the live server at launch.

What an open port really means

A port is a numbered door into a server, one per service: 443 for secure web traffic, 22 for SSH administration, 3306 for a MySQL database. This checker attempts a real connection to each common port on the host you enter, from our server, and reports open, or closed or filtered. Open is not automatically bad; a web server must have 80 and 443 open. Open is dangerous when the service behind it was never meant for the public: a database port reachable from the whole internet is one of the most common ways servers get breached, and it is usually an accident, not a decision.

Why "closed or filtered" is one answer, not two

From outside, a port that refuses connections and a port silently dropped by a firewall look almost identical, and distinguishing them reliably takes more than a single connection attempt. We report them together rather than pretend to a precision one check cannot honestly give. A timeout leans filtered, a fast refusal leans closed, and either way the service is not reachable, which is the fact you usually need.

Frequently asked questions

Which ports should never be open on a public server?

Database ports (3306 MySQL, 5432 PostgreSQL, 27017 MongoDB), RDP (3389) and network file services are the classic accidents. They belong behind a firewall or VPN. SSH (22) is often open by necessity; protect it with key-only login and fail2ban rather than leaving passwords enabled.

My port shows closed but the service is running. Why?

A firewall, a cloud security group, or your provider is blocking outside connections, or the service only listens on localhost. From the internet's point of view the port is closed, which for security is what matters; check from the server itself to see the local picture.

Why can my browser not just do this check?

Browsers are deliberately unable to open raw network connections, otherwise any web page could scan your home network. That is why this one tool runs on our server: the page sends the host name, the server opens the connections, and the results come back. Checks are one host at a time by design.

Is checking someone else's ports allowed?

Checking your own systems is routine administration. Scanning networks you do not own or have permission to test can breach laws and provider terms, which is why this tool is deliberately single-host and small-scale rather than a scanner.