Scan any domain or IP for open TCP ports across 30 common services — web, mail, databases, remote access, and more. Fast, safe, and passive.
A port scanner probes a target host to determine which TCP or UDP ports are open and accepting connections. Every service running on a server — a web server, an SSH daemon, a database — listens on a specific port. By scanning the ports, you build a picture of what's running on the server and how exposed it is to the internet.
Port scanning is a fundamental step in any security assessment. Attackers use it to map out attack surfaces. Defenders use it to verify their firewall rules are working and to identify services that shouldn't be publicly reachable.
This tool performs a TCP connect scan. For each port in our scan list, we attempt to open a TCP connection using non-blocking sockets. If the connection succeeds within the timeout, the port is open. If it's refused, the port is closed. If there's no response, the port is filtered (usually by a firewall).
Unlike aggressive port scanners (like nmap with SYN scanning), our approach:
Standard HTTP and HTTPS. Non-standard ports (8000, 8080, 8443, 8888) often host development servers, admin panels, or API endpoints that should not be publicly exposed.
SMTP for sending, POP3 and IMAP for receiving. Normal if you run a mail server. Should use TLS versions (465/587 for SMTP, 993/995 for IMAP/POP3) and never expose plaintext versions to untrusted networks.
SSH, Telnet, RDP, and VNC. SSH on port 22 is common and reasonable. Telnet (23) sends credentials in plaintext and should never be used. RDP and VNC should be behind a VPN, never exposed to the public internet.
MSSQL, MySQL, PostgreSQL, Redis, Memcached, MongoDB, Elasticsearch. None of these should ever be publicly accessible. They have no business being reachable from outside your private network. Exposure of any of these is a critical finding.
FTP, NetBIOS, and SMB. FTP transmits credentials in plaintext. SMB and NetBIOS on the public internet are a major risk — they've been used in ransomware attacks (WannaCry, NotPetya) and should always be firewalled.
DNS on TCP, Docker API, and RabbitMQ Management. Docker API exposed publicly allows full container takeover. RabbitMQ Mgmt exposed publicly allows message queue manipulation. Both are critical.
Every few months there's a story about a company leaking millions of records because a MongoDB, Elasticsearch, or Redis instance was left open to the internet. This happens constantly — automated bots scan for these ports continuously and exploit them within minutes of exposure.
Modern databases like Redis, Memcached, and MongoDB often ship with authentication disabled by default. If you spin one up on a cloud server and don't have a firewall in front, it's public within minutes and compromised within hours.
If this scanner reports any database port as open, treat it as an emergency. Restrict it immediately.
Each open port gets a risk classification:
Port scanning is a gray area legally. In most jurisdictions it's not explicitly illegal, but unauthorized scanning of systems you don't own can:
Only scan hosts you own or have explicit written permission to scan. If you're evaluating a potential client or vendor, ask first. The consent checkbox exists for a reason.
Get quick access to your security scans directly from your device.
Tap the Share icon below, then select "Add to Home Screen".