🔎 Your own IP, or a server you prove you own · 18 common ports or one custom port

Open port checker

Find out whether a TCP port is open on your own public IP address. Check 18 common ports in one click, test a single port, or enter your own. To check a different server, you first prove you own it with a one-time token file. We try one connection per port from our server.

Check a port on your connection

Your detected public IP
Detecting…

Common ports

This checks 18 common ports only, not a full scan. Open ports on a home connection are usually caused by router port forwarding.

Custom port

🛡️
How this stays safe: by default the tool tests only the public IP your request came from, and you cannot type an address into that mode. The separate Check another server I own mode only works after you prove ownership by publishing a one-time token on that server, and it refuses private, reserved and internal addresses and this server. In both modes it is one port per request, a plain TCP connect with a timeout of about 3 seconds, no data sent and no banners read. Limits: 40 checks per 10 minutes per IP address, plus 3 verification attempts per 10 minutes. This is not a port scanner: there are no ranges and no full scans.

What an open port means

A port is a numbered door that network programs use: 443 for secure websites, 22 for SSH, 3389 for Windows Remote Desktop, and so on. A port is open when something is listening on it and accepts a connection. It is closed when your device replies that nothing is listening, and filtered when a firewall silently drops the attempt so no reply comes back. From the outside, a closed and a filtered port look similar, so this tool reports them together as “closed or filtered”.

How this checker works

When you press a port button, our server opens a single TCP connection to that port on the public IP address your browser connected from, and waits up to about three seconds. If the connection is accepted, we report the port as open and close it right away. We do not send any data or read any service banner. The Check common ports button simply repeats this for 18 common ports, one after another, with a short pause between them. Because the test comes from the internet side, it shows what outsiders can reach, which is not always the same as what works inside your home or office network.

Checking another server you own

You can also check a server that is not the connection you are using, such as a VPS, an office server or a website host, but only after you prove it is yours. Open the Check another server I own tab and follow four steps:

  1. Enter one hostname or one public IP address.
  2. Copy the one-time token we show and publish it as the only content of /.well-known/itcoh-verify.txt on that server, served over plain HTTP on port 80.
  3. Press Verify. We read the file back, with no redirects and a 4 second timeout, and the server is then verified for 30 minutes.
  4. Check the 18 common ports or any one custom port.

Private, loopback, link-local, reserved and multicast addresses are refused, and so is any hostname that resolves to one. A hostname is resolved once and that address is the only one used, so a DNS change cannot redirect the check. Verification is tied to your IP address, you can hold one verified server at a time, and verification and check limits apply. A DNS TXT record is not accepted, because it proves control of a domain name but not of the server at the address.

Common reasons a port is not reachable

Basic security advice

Frequently asked questions

What does it mean when a port is open?

An open port means a program on your device or router is listening and accepted a TCP connection from the internet. That is normal for services you meant to expose, such as a web server on 443, but every open port is a possible way in, so only keep open the ones you need.

Why does my port show as closed or filtered when the service is running?

Several things can sit in the way: the service may only listen on localhost, the Windows or Linux firewall may block it, your router may not forward the port to your device, or your internet provider may block the port (common for 25, 80 and 443 on home connections). Behind carrier-grade NAT you may also share a public IP with other customers, so forwarding cannot work.

Can I check the ports of another IP address or website?

Only a server you can prove you control. The default mode tests just the public IP your request came from. The Check another server I own tab lets you enter one hostname or one public IP address, publish a one-time token file at http://your-server/.well-known/itcoh-verify.txt, and after we read that file back, check the same ports on that server. You cannot check servers you do not control, private or internal addresses, or ranges of addresses.

Is it safe to leave ports like 3389 or 3306 open?

Usually not. Remote Desktop (3389), databases such as MySQL (3306) and PostgreSQL (5432), Telnet (23) and FTP (21) are frequent targets for automated attacks. Prefer a VPN or SSH tunnel, restrict access to known addresses, use strong authentication, and close the port if you do not need it.

Why is the number of checks limited?

Each check opens one TCP connection from our server. To prevent misuse, checking your own IP allows 40 checks every 10 minutes per IP address. For a server you own, each IP address also gets 3 verification attempts every 10 minutes, 40 port checks every 10 minutes, and one verified server at a time. Every check is one port per request with a timeout of about 3 seconds. There is no range scan or full port scan.

Can I check all my common ports at once?

Yes. The Check common ports button tests 18 common ports (21, 22, 23, 25, 53, 80, 110, 143, 443, 465, 587, 993, 995, 3306, 3389, 5432, 8080 and 8443) one after another and lists which are open, on your own IP or on a server you have verified. It is not a full scan of all 65,535 ports. If a port shows open on a home connection, it is usually because of router port forwarding, so check your router settings if you did not expect it.

How does ownership verification work?

Enter one hostname or public IP address and we give you a random token that is valid for 15 minutes. Publish it as the only content of http://your-server/.well-known/itcoh-verify.txt on port 80 and press Verify. Our server resolves the name once, fetches that file from the resolved address without following redirects, and reads at most 256 bytes. If the content matches, that server is verified for 30 minutes. Nothing is scanned before that.

Why do I have to verify before checking another server?

Connecting to ports on a machine you do not control can look like an attack and can get a hosting provider blocked. Placing a secret token on the server shows that you control it. We also refuse private, loopback, link-local, reserved and multicast addresses, any hostname that resolves to one of them, and our own server.

Can I verify with a DNS TXT record instead?

No. A DNS record only shows that you control a domain name, not the server at the IP address it points to, so only the HTTP file is accepted.

Verification keeps failing. What should I check?

The file must be reachable at exactly http://your-server/.well-known/itcoh-verify.txt over plain HTTP on port 80 and return status 200 with only the token in the body (a trailing newline is fine). Redirects are not followed, so a redirect from HTTP to HTTPS makes verification fail for that path. Make sure the web server serves the .well-known folder, that a firewall allows port 80, and that the token has not expired (15 minutes). You have 3 attempts per 10 minutes.