Emergency server help: get in touch

cPanel and DirectAdmin Server Check

Check a cPanel, WHM, DirectAdmin or Plesk server from the outside: 16 standard hosting ports, panel and mail certificates, STARTTLS on 587, plain FTP and HTTP login ports, exposed databases and reverse DNS.

Status
Live
Last updated
October 3, 2026

Enter a server hostname or a domain hosted on it to see the server the way the internet does. The check connects to the standard cPanel, WHM, DirectAdmin, Plesk, mail, FTP and database ports, reads each greeting and TLS certificate, and flags anything that sends passwords in clear text or should not be public.

What the server check looks at

The ports are FTP 21, SSH 22, cPanel 2082 and 2083, WHM 2086 and 2087, webmail 2095 and 2096, DirectAdmin 2222, Plesk 8443, SMTP 465 and 587, IMAP 993, POP3 995, MySQL 3306 and PostgreSQL 5432. Each connection only reads the greeting and certificate and then closes; no login is attempted.

The certificate on every TLS port is checked for trust, name and expiry, port 587 is tested for STARTTLS, and the reverse DNS (PTR) of the IP is checked to resolve back, which mail servers rely on.

Ports that should not be public

The plain HTTP panel ports 2082, 2086 and 2095 send logins unencrypted; redirect them to the HTTPS ports or close them. Plain FTP on 21 does the same with passwords, so prefer SFTP or force TLS. MySQL and PostgreSQL should listen only on localhost or be limited to known IPs.

Closing ports with CSF

In /etc/csf/csf.conf remove the port from TCP_IN and run csf -r. For a database that a few remote systems need, keep it out of TCP_IN and allow those IPs in csf.allow with a port filter instead of opening it to everyone.

cPanel and DirectAdmin Server Check at a glance

cPanel and DirectAdmin Server Check summary card: Enter a server hostname or a domain hosted on it to see the server the way the internet does.
In short: Enter a server hostname or a domain hosted on it to see the server the way the internet does.
cPanel and DirectAdmin Server Check sections: What the server check looks at, Ports that should not be public and Closing ports with CSF
Covers: What the server check looks at, Ports that should not be public and Closing ports with CSF.
cPanel and DirectAdmin Server Check questions answered: Is this a port scan? Why does port 2083 show a certificate name mismatch?
Answers: Is this a port scan? Why does port 2083 show a certificate name mismatch?

Official documentation: cPanel and WHM documentation, DirectAdmin documentation.

Related guides: Harden Shared cPanel Server: Secure CageFS and ModSecurity Setup · CSF DirectAdmin Install: Tune CSF/LFD Safely (Post-1.689) · Lock Down WHM: 2FA, cPHulk and API Tokens for Secure Access.

Frequently asked questions

Is this a port scan?

No. It connects only to a fixed list of 16 standard hosting ports, reads what the service announces and disconnects. It does not try passwords or exploits.

Why does port 2083 show a certificate name mismatch?

cPanel service ports present the server hostname certificate unless the domain has its own service certificate. Test the server hostname to check the panel certificate properly.

What does no answer, firewalled, mean?

The firewall dropped the connection without replying, which is the normal result for a closed service behind CSF or firewalld.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.