Connections from our port scanner

If you are reading this because you saw a connection from scanner.auditmypc.com in a firewall log, this page explains what it was.

What it is

AuditMyPC runs a free port scanner. Somebody opens our page, reads the warning, and clicks a button. We then try to open a TCP connection to a short list of ports on their own address to see which ones answer, and we show them the result. The connection you saw is that test.

It only ever goes back to whoever asked

This is the part that matters if you are worried. We only ever scan the address the request came from. Nobody can type in your address, or anyone else’s, and have us scan it for them. The address is read off the connection itself, and the permission slip our page hands the scanner is signed for that one address and expires in about two minutes. There is no field to put a different address in, and no header we will believe instead of the connection.

So if you saw us, one of two things happened: somebody on your network ran the test, or your network recently handed that address to somebody who did.

Schools, companies and campuses

If you run a network that many people share, one of them ran the test from inside it. The address they tested is the one your network presents to the internet, so the result described your firewall rather than their computer. Our page warns against exactly that, and before the first scan it asks the person whether the connection is their own or a network they run. We keep their answer with the record of the scan.

Send us the address and the time, in UTC if you can, and we will tell you what our record shows, usually the same day. If you would like the range excluded, say so in the same message and it will be done. You are welcome to report the connection to our hosting provider instead. Their process forwards it to us, so writing to us directly is the quicker route, and it ends with your range excluded if that is what you want.

How to recognise it

  • It comes from 64.177.14.241, which is scanner.auditmypc.com in both forward and reverse DNS. Browse to that name or that address and it explains itself.
  • It is a plain TCP handshake and nothing else. We open the connection and close it. Nothing is sent, no banner is read, and nothing about the software behind the port is examined.
  • At most 1,024 ports in one run, and one address can ask about at most 4,096 ports in any ten minutes before we start refusing.
  • It stops on its own. There is no follow-up, no repeat schedule, and nothing about your network is remembered for next time.

What we keep

One line per scan: the address, when the scan started and ended, how many ports were asked about, a count of how the results came back, and the answer the person gave to the question before the scan. One line for anything we refused without connecting. We do not record which individual ports answered, and we never look at what is behind them. The record is kept for about six weeks. It exists so we can answer the question that brought you here, which is usually some version of “did you connect to us at half past two, and why”.

Have your network left alone

If you would rather we never scanned an address in your range, send the range in CIDR form to monetizers@gmail.com and we will add it to the exclusion list. If your network has IPv6 addresses as well, send that prefix too; an IPv4 range on its own does not cover them. You do not need to explain why, and we will not argue about it.

Excluded ranges are refused before any connection is opened, so somebody on an excluded network is told plainly that we cannot test them rather than being left with a test that quietly does nothing.

Government and military networks

We do not test an address whose name says it belongs to a government or military network unless whoever runs that network has asked us to. Anyone on such an address who tries is told so before anything is scanned, and told how to ask.

If you run one and want it tested, write to monetizers@gmail.com from your organization’s own email address. Tell us the address range and your role. We check that the range is registered to your organization, confirm your role through your organization’s own website or directory, and reply with the date the permission runs to, a year as a rule. There is no charge. Anyone on the range who runs a test is still asked to confirm that they run the network and are allowed to test it, and that answer is kept with the record.

Something worse than a log entry

If you think this service is being misused, or you have found a security problem with it, the contact in our security.txt reaches us and we would rather hear about it than not.

© 2002-2026 AuditMyPC.com