Open port check
Pick a port and our server tries to connect to it on the address you’re visiting from. You’ll learn whether the port is open, closed or silent, and what each answer says about your router.
An address has 65,535 doors
Your internet connection has one public address, a bit like the street address of a building. A port is a numbered door in that building. A program that wants to receive connections stands behind one of the doors and waits. A web server waits behind 443, a Minecraft server behind 25565, Windows Remote Desktop behind 3389.
At home, the building has a doorman, and that’s your router. Connections you start yourself go out, and their replies come back in with no setup at all. A connection that starts from outside is another story. The router has no idea which of your devices it’s meant for, so it throws it away. That default is why a home network is hard to attack. It’s also why your friend can’t join the game server running on your computer.
A port forward is a standing instruction to the doorman, something like “anything that arrives for door 25565 goes to the computer at 192.168.1.20”. This page knocks from the outside to tell you whether that instruction works.
Three possible answers
We make one TCP connection attempt and watch what comes back. Nothing is sent through the connection, and we close it right away.
| Result | What happened on the wire | What it means |
|---|---|---|
| Open | The connection was accepted. | A program is listening and every firewall on the way lets the traffic through. |
| Closed | A refusal came back within milliseconds. | The path is clear but there’s no program behind the door. Start the program or correct its port number. |
| No answer | Four seconds of silence. | A firewall or the router dropped the attempt. For a port nobody opened, that’s the normal, safe state. |
When a forward isn’t working, the difference between “closed” and “no answer” is your best clue. A refusal proves the router passed the connection along, so whatever is still wrong is on the device. Silence points at the router rule, or at the provider.
Why you can only test your own address
You won’t find an address field on this page. The test always targets the address your request came from, one port at a time.
Trying ports on a machine is the first step of most break-ins. That’s why nearly every hosting contract forbids scanning addresses you don’t manage, and why it’s illegal in some countries. A public page that scans any address on request would let anyone take that step while hiding behind our server. Checking your own door is fine, since you already hold the key.
With a VPN or a corporate proxy switched on, “your address” is the address of the VPN server. Turn it off before testing a home port forward.
When the port stays silent
Go through these in order, from the outside in.
- Shared address at the provider. Open the router’s status page and read its WAN address. If it differs from the address shown above, or starts with
100.64to100.127,10.or192.168., your provider puts many customers behind one address (carrier-grade NAT). No rule in your router will help. Ask for a public address, or use IPv6 or a tunnel service. - The forwarding rule. External port, internal port, protocol TCP, and the local address of the right device. Give that device a fixed local address, or the rule will point at nothing after the next restart.
- Two routers in a row. If a provider box sits in front of your own router, you need the forward on both, or the first one set to bridge mode.
- The firewall of the device. Windows, macOS and most Linux systems block incoming connections until you allow the program.
- The program. It has to be running, on that port, and listening on all interfaces (
0.0.0.0) instead of only127.0.0.1.
Some providers block a few ports for every home customer, most often 25 (mail), 80 and 445. If one port stays silent while its neighbors open, that’s probably what you’re seeing.
An open port gets visitors
Automated scanners sweep the whole IPv4 internet several times a day. They find a newly opened port within hours, and the first password guesses follow. Open only what you use and keep the program behind it updated. Never expose a database, Windows file sharing (445), Telnet (23) or Remote Desktop (3389) directly. Reach those through a VPN.
This page tests TCP only. UDP services such as WireGuard or most voice chat can’t be checked from outside, because an open UDP port with nothing to say looks exactly like a closed one.
Questions people ask
How do I know if my port forwarding is working?
Start the program that should receive the connections, then test its port here. “Open” means the forward works from end to end. “Closed” means the router forwards correctly but the program isn’t listening. “No answer” means the router or a firewall is still dropping the traffic.
Why does the port show as closed when my server is running?
It’s usually a program listening only on 127.0.0.1, a different port number in its settings, a device firewall, or a VPN that makes the test hit another address. Test from the same network the server is on, with the VPN off.
Can I check a port on another IP address or website?
No. The page only tests the address you’re connecting from. Scanning machines you don’t manage is abusive, so there’s no address field. To see whether a public website answers, use Is it down?.
Is it dangerous to have open ports?
A port is only as safe as the program behind it. A patched web server on 443 is fine. Remote Desktop, a database or a camera with a default password will be found and attacked quickly. Close what you don’t use.
What is carrier-grade NAT and how does it block port forwarding?
Your provider shares one public address among many customers, so incoming connections stop at its equipment and never get to your router. You can tell by a WAN address in your router that differs from your public address. Only the provider, IPv6 or a tunnel service can get you around it.
Can this test UDP ports?
No. UDP has no connection handshake, so a silent port may be open or closed. Test UDP services with their own client from another network, a phone on mobile data for example.