Search 93+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Dev Tool

Port Scanner

Check which ports are open on any public IP address or domain. Scans 21 common ports instantly.

⚡ Scan Open Ports

⚠ Only scan hosts you own or have permission to test. Scans 21 common TCP ports with 1.5s timeout each.

Ports We Check

21 FTP
22 SSH
23 Telnet
25 SMTP
53 DNS
80 HTTP
110 POP3
143 IMAP
443 HTTPS
465 SMTPS
587 SMTP Submit
993 IMAPS
995 POP3S
1433 MSSQL
3306 MySQL
3389 RDP
5432 PostgreSQL
6379 Redis
8080 HTTP-Alt
8443 HTTPS-Alt
27017 MongoDB

Frequently Asked Questions

What is a port scanner used for?
A port scanner checks which TCP ports are open and accepting connections on a given host. It is used by network administrators to audit firewall rules, by security professionals to identify exposed services, and by developers to verify that server applications are listening on the correct ports.
Which ports should I check first?
The most important ports to check are 22 (SSH), 80 (HTTP), 443 (HTTPS), 3306 (MySQL), 5432 (PostgreSQL), 3389 (RDP), and 21 (FTP). These are common targets for attackers and should either be firewalled or secured with strong authentication if open.
Is port scanning legal?
Port scanning your own servers is always legal. Scanning third-party servers without permission may violate computer crime laws in many jurisdictions. Only scan hosts you own or have explicit written permission to test.
What does an open port mean?
An open port means a service is actively listening for connections on that port. Open ports on public servers are not necessarily dangerous — a web server needs port 80 and 443 open. Concern arises when unexpected ports like 3306 (MySQL) or 27017 (MongoDB) are open to the public internet.
Why are some ports showing as closed when they should be open?
Firewalls and security groups block connection attempts without sending a response. Our scanner uses TCP connect with a 1.5s timeout — firewalled ports appear closed even if a service is running behind them.
🛡️
Open ports expose your server to attackers. Secure your connection with a VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

How to read a port scan

Every network service listens on a numbered port: web servers on 80 and 443, SSH on 22, mail on 25 and 587, databases on ports such as 3306. A port scan tries to connect to a list of these ports and records which ones answer. It is the quickest way to see a server the way an attacker on the internet sees it. Only public addresses can be scanned here; private and internal ranges are refused.

What the results mean

  • Open means a program accepted the connection. On a web server, 80 and 443 should be open. Anything else that is open is a service you are exposing to the whole internet, so make sure you meant to.
  • Closed or no response means nothing accepted the connection. A firewall that silently drops traffic is usually the safest setup for ports you do not use.

Ports that should rarely be open to everyone

  • 22 (SSH) is attacked by automated password guessing around the clock. Use key-based login, disable password login, and limit which IP addresses can connect if you can.
  • 3306 (MySQL), 5432 (PostgreSQL), 6379 (Redis) and 27017 (MongoDB) belong on localhost or a private network. Exposed databases are one of the most common causes of data leaks.
  • 21 (FTP) and 23 (Telnet) send passwords in plain text. Replace them with SFTP and SSH.
  • 3389 (Remote Desktop) is a frequent ransomware entry point. Keep it behind a VPN.

Why your results may differ from ours

Firewalls and hosting providers often filter traffic by where it comes from, so a port can look open from your office and closed from our server, or the other way round. If your domain sits behind a proxy such as Cloudflare, the scan shows the proxy's ports rather than your real server's. Scan the origin IP address directly to check the server itself.

Scan responsibly

Only scan systems you own or have permission to test. A single check of common ports is routine, but repeated or wide scanning of other people's networks can breach your provider's terms of service or local law.

Related Tools

📊
HTTP Status Checker
Check status codes for any URL
📡
HTTP Headers Check
Inspect HTTP response headers
🛡️
HTTP Security Headers
Grade a site on security headers
🔒
SSL Checker
Check a certificate and expiry
🌍
IP Lookup
Geolocate any IP address
🔎
DNS Lookup
Query any DNS record type
Done!