Port Scanner
Checks which ports are reachable on your own public IP address — the view an attacker gets when they look at your connection from the outside. Every open port is a door with something listening behind it; most home connections should have none at all.
Selected: common ports.
| Port | Service | Result | What it means |
|---|
Key takeaway: for a home connection, filtered on everything is the result you want. It means your router dropped the packets without replying — a scanner learns nothing, not even that you are there. Closed is fine too, but slightly chattier. Open means something answered, and you should know what.
Why it only scans your own address
Because the alternative is irresponsible. A scanner that accepts any target turns this site into a free tool for probing other people’s networks, with the connections arriving from our server rather than from whoever asked for them. That is an abuse complaint against us and, in many places, unauthorised access testing against them.
So there is no target field here. The endpoint reads the address your browser connected from and can
scan nothing else — not by policy, but because there is no way to tell it otherwise. If you need to scan a
network you are responsible for, use nmap from a machine on that network; it is the right tool
and it will tell you far more than this can.
Reading the three results
Filtered — the good one
Nothing came back at all. Your router or your provider dropped the packet silently, which is how a well-configured firewall behaves: an attacker scanning a range cannot even confirm something is there. Almost every port on a normal home connection should look like this.
Closed — harmless, slightly noisy
Something actively refused the connection. Nothing is listening on that port, so there is nothing to attack, but the refusal itself confirms a live host at your address. Not worth fixing on a home line.
Open — the one that matters
A service accepted the connection. That is not automatically bad — if you deliberately run a game server or a VPN endpoint, you want it open. It is bad when you did not know about it, because it means something is reachable from the entire internet and you are not the one deciding who talks to it.
What to do about a port you did not expect
Work out what opened it before closing anything. Most unexpected open ports on home connections come from three places: a UPnP request from a game, console or torrent client that silently asked the router to forward a port; a manual port-forward set up once and forgotten; or the router’s own remote-management interface being exposed to the internet rather than the local network.
Start in the router’s admin page. Turn off UPnP unless you actively need it, delete port-forwarding rules you cannot account for, and make sure remote administration is off. Then scan again — the change should show up here immediately, which is the useful part of running this twice.
The ones worth acting on today
3389 (RDP) and 5900 (VNC) expose a desktop to the internet. Exposed RDP is one of the most common ways ransomware gets in, and every one of these is found by automated scanning within hours. Use a VPN into your network instead of forwarding them.
445 (SMB) and 139 are Windows file sharing, which should never be reachable from outside your own network. Several of the worst worms in history spread through exactly this.
23 (Telnet) sends everything, passwords included, in plain text. On a home connection an open 23 usually means a device with factory firmware and default credentials — often a camera or DVR.
3306, 5432, 6379, 27017, 9200, 11211 are databases. A database on the public internet is a breach waiting to happen; Redis, MongoDB, Elasticsearch and Memcached have all had mass-compromise events from exactly this exposure, in several cases with no password required at all.
An unexplained open port can mean a misconfigured device, or malware that opened one deliberately. Scan the machines on your network before you assume it was a router setting — and if you need remote access to your own network, a VPN back into it is the right answer rather than forwarding a port to the internet.
Bitdefender PureVPNAffiliate links. We do not rank by commission — compare providers yourself.
What this cannot tell you
It scans your router, not your computer. Almost every home network puts one public address in front of many devices, so what you are testing is the box at the edge. A laptop with an open port is invisible here unless the router forwards that port to it — which is exactly why NAT is such an effective accidental firewall. How NAT protects you explains the mechanism.
If you are behind CGNAT, you are scanning your provider. Many mobile and some fixed-line connections share one public address across many customers, so the result describes the carrier’s equipment, not your home. Here is how to tell.
If you are on a VPN, you are scanning the VPN server. Turn it off before scanning, or the results describe a datacentre in another country. The VPN leak test will confirm which address you are currently using.
It checks a shortlist, not all 65,535 ports. These are the ports worth knowing about on a home connection. A service on an unusual high port will not appear, and an empty result is not proof that nothing is listening anywhere.
Frequently asked questions
Is it legal to scan ports?
Scanning your own connection is unambiguously fine — it is your address and you are the one answering. Scanning someone else’s without permission is a different question with different answers depending on where you live, and is the reason this tool will not do it.
All my ports are filtered. Am I safe?
From this angle, yes, and that is the normal, healthy result. It says nothing about the other directions an attack arrives from — phishing, a malicious download, a compromised device already inside the network, or anything that reaches out from your side. Closed doors are good; they are not the whole building.
Why does my result change between scans?
Either your address changed — many providers rotate them, see why that happens — or something on your network opened a port via UPnP in the meantime. A game or torrent client starting up is the usual explanation.
Should I close port 80 and 443?
Only if you are not intentionally hosting anything. If you run a web server, a NAS interface or a smart home hub reachable from outside, they are open on purpose — the thing to check is that whatever answers is patched and password-protected, not that the port is shut.
My router has a firewall. Why scan at all?
Because port forwarding rules, UPnP and remote management all punch holes through that firewall, usually without telling you. The firewall being on and the ports being closed are two different claims, and this checks the second one from the outside, which is the only vantage point that counts.
Related reading
- How to check open ports yourself
- What port forwarding does
- NAT firewalls explained
- What a firewall actually does
- Securing your home network
- CGNAT explained
- What someone can do with your IP
- How ransomware gets in