This checks which ports on your internet connection answer from the outside. It runs from our server against the address your connection is using right now, so what you see is roughly what anyone else on the internet would see.
Port scanner
Checks which ports on your connection answer from the outside. Pick any port or range you want.
Before the first scan
This will test , , from our server on the internet.
Is this your own connection, at home or on a network you run? The address belongs to whoever runs the network you are on, and the result describes their firewall.
This address looks like it belongs to an organization rather than a home. A scan would test the organization's firewall and would show up in its firewall log. Only go ahead if you are the person responsible for this network.
This is a look at the ports you asked for, from one place on the internet, at one moment. It is not a security audit and it does not certify anything. A port that did not reply today can still be open tomorrow if something changes on your router.
What the results mean
There are four answers, and the difference between them matters more than the count does.
- Answered. Something accepted the connection. A service is listening on that port and it can be reached from the internet.
- Refused. Your network replied and turned the connection down. Nothing is listening there, and your own equipment said so.
- No reply. Nothing came back before we stopped waiting. Usually a firewall dropping the traffic before it reaches anything.
- Could not test. We never reached your network, so the row tells you nothing either way. We say that plainly instead of counting it as closed, because a port nobody tested is not a port anybody can vouch for.
Refused and no reply are both ordinary, and neither one leaves anything listening. If a result surprises you, why port checks fail goes through the cases that catch people out.
A port answered. Now what?
An answering port is not automatically a problem. It becomes one when you did not mean to open it.
Start with the port forwarding list on your router, because on a home connection that is where nearly every open port comes from. Read down it and check every entry is one you put there. If you do not recognise a rule, look the port up before you touch it, and if it turns out not to be yours, take it out.
If the forwarding list is empty and a port still answers, something on the network opened it without being asked, and that is worth tracking down rather than closing and forgetting about.
Firewalls that stop answering partway through
Some firewall gear watches for port scans and stops replying to the source once it decides it is being scanned. If that happens partway through a run, every port checked afterwards comes back as no reply whatever is really there, and the result reads as an all clear that nobody earned.
The old advice, on this site and plenty of others, was to switch that protection off before testing. We do not give that advice any more. Turning off a working defence to make a test look tidier is a poor trade, and it made no difference when we tried it. We switched scan protection on, restarted a current consumer router, and ran a full 1,024 ports: the results came back exactly as they had with the setting off. Five bursts fired back to back did the same.
So the scanner checks instead of asking you to change anything. At the end of a run it goes back to a few ports that answered early and asks them again. If they have gone quiet, it says so, because that is the pattern a firewall shutting the door would leave behind. If they still answer, your connection was talking to us the whole way through and the result stands on its own.
Testing a network that is not yours
The test always runs against the address your connection presents to the internet, and that address is not always yours. At work, at school, in a hotel or on shared wifi it belongs to the network, so the result describes their firewall rather than your computer. Do not run it there.
If you are responsible for a company network and you want it tested, that is a conversation with whoever runs it rather than a button on a website.
Going further
- Look up any port number in our database, which covers registered services, intrusion detection references and known malware activity for TCP and UDP ports.
- Check your public IP address, which is the address anyone probing you would actually reach. Worth a look if you use a VPN and expect to see a different one.
- How to check if port 80 is open, and what to do when port forwarding is not working and a rule looks right but the port still tests shut.
- Constant connection attempts in your firewall log, for making sense of all those blocked entries.
- Review your digital footprint to see what every website can read about your connection and browser.
Terms, privacy, and connections from our scanner
Using this tool means you accept our terms of service, including the rule that you test only connections you are responsible for. Our privacy statement covers what a scan records and how long we keep it.
If you arrived here because you saw a connection from our scanner in a firewall log, this page explains what it was and how to have a range excluded.
