Check a port on your connection
Common ports
This checks 18 common ports only, not a full scan. Open ports on a home connection are usually caused by router port forwarding.
Custom port
Check another server I own
Step 1 · Enter your server
One hostname or one IP only: no http://, no port, no path. The name is resolved once and only that address is used.
Step 2 · Publish the token
Target:
How do I create the file?
On the server, create the folder .well-known inside your website's web root and put a file called itcoh-verify.txt in it. The file must contain only the token. Example for a typical Linux web server (change the web root to yours):
The URL must answer with status 200 directly. Redirects, including HTTP to HTTPS, are not followed. If your site forces HTTPS, add an exception for this one path. You can delete the file after you are done.
Step 3 · Verify
Step 4 · Check ports
Common ports
This checks 18 common ports only, not a full scan.
Custom port
Common ports check
| Port | Service | Result |
|---|
Results
What an open port means
A port is a numbered door that network programs use: 443 for secure websites, 22 for SSH, 3389 for Windows Remote Desktop, and so on. A port is open when something is listening on it and accepts a connection. It is closed when your device replies that nothing is listening, and filtered when a firewall silently drops the attempt so no reply comes back. From the outside, a closed and a filtered port look similar, so this tool reports them together as “closed or filtered”.
How this checker works
When you press a port button, our server opens a single TCP connection to that port on the public IP address your browser connected from, and waits up to about three seconds. If the connection is accepted, we report the port as open and close it right away. We do not send any data or read any service banner. The Check common ports button simply repeats this for 18 common ports, one after another, with a short pause between them. Because the test comes from the internet side, it shows what outsiders can reach, which is not always the same as what works inside your home or office network.
Checking another server you own
You can also check a server that is not the connection you are using, such as a VPS, an office server or a website host, but only after you prove it is yours. Open the Check another server I own tab and follow four steps:
- Enter one hostname or one public IP address.
- Copy the one-time token we show and publish it as the only content of
/.well-known/itcoh-verify.txton that server, served over plain HTTP on port 80. - Press Verify. We read the file back, with no redirects and a 4 second timeout, and the server is then verified for 30 minutes.
- Check the 18 common ports or any one custom port.
Private, loopback, link-local, reserved and multicast addresses are refused, and so is any hostname that resolves to one. A hostname is resolved once and that address is the only one used, so a DNS change cannot redirect the check. Verification is tied to your IP address, you can hold one verified server at a time, and verification and check limits apply. A DNS TXT record is not accepted, because it proves control of a domain name but not of the server at the address.
Common reasons a port is not reachable
- No port forwarding: on a home network, your router must forward the port to the device running the service.
- Firewall rules: the operating system firewall or a cloud security group may block the port.
- Service not running or bound to localhost only: the program must listen on the network address, not just 127.0.0.1.
- Provider restrictions or CGNAT: some internet providers block ports like 25, 80 and 443, or put many customers behind one shared public IP.
- VPN or proxy: if you are on a VPN, the IP shown is the VPN exit address, not your home connection.
Basic security advice
- Only expose ports you actually need, and close the rest.
- Do not leave Remote Desktop (3389), databases (3306, 5432), Telnet (23) or FTP (21) open to the whole internet. Use a VPN, an SSH tunnel, or an IP allow-list.
- Keep software updated and use strong authentication such as keys or multi-factor login.
- After changing router or firewall rules, re-check the port to confirm the result.
Frequently asked questions
What does it mean when a port is open?
An open port means a program on your device or router is listening and accepted a TCP connection from the internet. That is normal for services you meant to expose, such as a web server on 443, but every open port is a possible way in, so only keep open the ones you need.
Why does my port show as closed or filtered when the service is running?
Several things can sit in the way: the service may only listen on localhost, the Windows or Linux firewall may block it, your router may not forward the port to your device, or your internet provider may block the port (common for 25, 80 and 443 on home connections). Behind carrier-grade NAT you may also share a public IP with other customers, so forwarding cannot work.
Can I check the ports of another IP address or website?
Only a server you can prove you control. The default mode tests just the public IP your request came from. The Check another server I own tab lets you enter one hostname or one public IP address, publish a one-time token file at http://your-server/.well-known/itcoh-verify.txt, and after we read that file back, check the same ports on that server. You cannot check servers you do not control, private or internal addresses, or ranges of addresses.
Is it safe to leave ports like 3389 or 3306 open?
Usually not. Remote Desktop (3389), databases such as MySQL (3306) and PostgreSQL (5432), Telnet (23) and FTP (21) are frequent targets for automated attacks. Prefer a VPN or SSH tunnel, restrict access to known addresses, use strong authentication, and close the port if you do not need it.
Why is the number of checks limited?
Each check opens one TCP connection from our server. To prevent misuse, checking your own IP allows 40 checks every 10 minutes per IP address. For a server you own, each IP address also gets 3 verification attempts every 10 minutes, 40 port checks every 10 minutes, and one verified server at a time. Every check is one port per request with a timeout of about 3 seconds. There is no range scan or full port scan.
Can I check all my common ports at once?
Yes. The Check common ports button tests 18 common ports (21, 22, 23, 25, 53, 80, 110, 143, 443, 465, 587, 993, 995, 3306, 3389, 5432, 8080 and 8443) one after another and lists which are open, on your own IP or on a server you have verified. It is not a full scan of all 65,535 ports. If a port shows open on a home connection, it is usually because of router port forwarding, so check your router settings if you did not expect it.
How does ownership verification work?
Enter one hostname or public IP address and we give you a random token that is valid for 15 minutes. Publish it as the only content of http://your-server/.well-known/itcoh-verify.txt on port 80 and press Verify. Our server resolves the name once, fetches that file from the resolved address without following redirects, and reads at most 256 bytes. If the content matches, that server is verified for 30 minutes. Nothing is scanned before that.
Why do I have to verify before checking another server?
Connecting to ports on a machine you do not control can look like an attack and can get a hosting provider blocked. Placing a secret token on the server shows that you control it. We also refuse private, loopback, link-local, reserved and multicast addresses, any hostname that resolves to one of them, and our own server.
Can I verify with a DNS TXT record instead?
No. A DNS record only shows that you control a domain name, not the server at the IP address it points to, so only the HTTP file is accepted.
Verification keeps failing. What should I check?
The file must be reachable at exactly http://your-server/.well-known/itcoh-verify.txt over plain HTTP on port 80 and return status 200 with only the token in the body (a trailing newline is fine). Redirects are not followed, so a redirect from HTTP to HTTPS makes verification fail for that path. Make sure the web server serves the .well-known folder, that a firewall allows port 80, and that the token has not expired (15 minutes). You have 3 attempts per 10 minutes.