Emergency server help: get in touch

Open Port Checker: Test TCP Ports on Any Public Server

Check whether TCP ports are open on a public server: up to 10 ports per test, presets for web, mail and control panels, open, closed or filtered results and the SMTP greeting.

Last updated
October 6, 2026

Short answer: Enter a hostname or public IP and up to 10 TCP ports, and our server tries to connect to each one. A port is OPEN when something accepts the connection, CLOSED when the host refuses it, and FILTERED when nothing answers within 5 seconds, which usually means a firewall is dropping the traffic. The test runs from our server’s location, so a firewall that only allows certain IPs or countries can give your visitors a different answer.

We tested this tool on 6 October 2026 by running its code in a test harness on our lab server (AlmaLinux 9.8, PHP 8.2): ports 22, 80 and 81 on scanme.nmap.org (open, open, closed), 443 and 81 on 8.8.8.8 (open, filtered after 5 seconds), the SMTP greeting on smtp.gmail.com port 587, and the IPv6 path. We also confirmed that 27 forbidden targets are refused before any connection is made, including 127.0.0.1, 10.0.0.1, ::1, 169.254.169.254, 100.64.0.1, IPv4-mapped and 6to4 addresses, and hostnames such as localtest.me that resolve to private addresses. The nc and ss commands below were run on the same server; the firewall and PowerShell commands are checked against the official documentation linked below.

How to use the open port checker

  1. Enter the hostname or public IP address of the server, for example mail.example.com or 203.0.113.10. You can also type host:port.
  2. Type the ports to test, separated by commas, for example 22, 443, 2083, or pick a preset such as Mail or Control panels. A preset and typed ports are combined, up to 10 ports per check.
  3. For mail servers, leave Also read the SMTP greeting on to see the 220 banner on ports 25 and 587.
  4. Choose IPv4 or IPv6 if the host has both and you want to test a specific one. Auto tests the first IPv4 address.
  5. Click Check ports. All ports are tested at the same time and the whole check finishes within 15 seconds.

The presets cover the ports hosting admins ask about most:

PresetPortsTypical service
Web80, 443, 8443HTTP, HTTPS, alternative HTTPS (Plesk uses 8443)
Mail25, 110, 143, 465, 587, 993, 995SMTP, POP3, IMAP, submission and their TLS versions
Control panels2083, 2087, 2222, 8443cPanel, WHM, DirectAdmin, Plesk
Remote access21, 22, 3389FTP, SSH/SFTP, Remote Desktop
DNS, database, SIP53, 3306, 5060DNS over TCP, MySQL/MariaDB, SIP over TCP

Reading the results

StateWhat happenedWhat it usually means
OPENThe TCP handshake completed.A service is listening and the firewall allows our server. It does not prove the service itself works.
CLOSEDThe host answered with a reset (connection refused).Nothing listens on that port, the service is bound to 127.0.0.1 only, or a firewall rule rejects instead of dropping.
FILTEREDNo answer within 5 seconds.A firewall drops the packets, the host is down, or a cloud security group does not allow the port.
NOT TESTEDWe did not try.Our hosting provider blocks outbound port 25, so the tool cannot test it from our server.
ERROROur server could not start the connection.Most often an IPv6 target while our server has no IPv6 route. Test the IPv4 address instead.

On ports 25 and 587 the details column also shows the server greeting, for example 220 mail.example.com ESMTP. We read at most 512 bytes, send QUIT and disconnect. No other port gets any data from us: the tool only opens and closes the connection. For STARTTLS, certificate and EHLO details use the SMTP test.

Only TCP is tested. DNS on port 53 and SIP on port 5060 mostly use UDP, and a connect test cannot tell you whether a UDP port is open. An OPEN result on TCP 53 or 5060 says nothing about UDP.

Why the result can differ for you

The connection comes from our server, not from your computer. If your firewall only allows some IP addresses or countries, our result is correct for our address and may be wrong for yours. Common causes on hosting servers are a CSF allow or deny list, cPanel Host Access Control, a cloud provider security group, and fail2ban or LFD blocks that are still active. The reverse also happens: a port can be open for our server but blocked for your office if your ISP filters outbound traffic, which is common for port 25 on home and mobile connections.

To compare, test from your own machine. On Linux or macOS with netcat (on our lab server this printed Connected to x.x.x.x:22):

nc -zv -w 3 example.com 22

In PowerShell on Windows, TcpTestSucceeded : True means the port is open from that computer:

Test-NetConnection -ComputerName example.com -Port 443

Common problems and fixes

The port shows FILTERED but the service is running

Check that the service listens on the public address and not only on localhost. On the server, list listening TCP sockets with their process:

ss -tlnp | grep ':2083'

An address of 127.0.0.1:port in the output means only local connections are accepted; change the service’s bind or listen setting. If it listens on 0.0.0.0 or [::], open the port in the firewall. With firewalld:

firewall-cmd --permanent --add-port=2083/tcp
firewall-cmd --reload

With CSF, add the port to TCP_IN in /etc/csf/csf.conf and restart CSF. On a cloud server also check the provider’s security group or network firewall, which sits in front of the server’s own firewall.

The port shows CLOSED

The host is reachable but nothing accepted the connection. Start the service, check its logs for a failed start, and make sure it uses the port you expect: SSH moved to a custom port, a panel on a non-default port, or a mail server with submission disabled are common reasons.

Port 25 is not tested or always times out

Many cloud and hosting providers block outbound port 25 to stop spam, including from our server. Test 587 or 465 here, or test port 25 from a server whose provider allows it. If port 25 on your mail server is closed for everyone, other mail servers cannot deliver to you; check the MX records with the MX lookup.

Database, RDP and panel ports are OPEN to everyone

Ports such as 3306, 3389, 2083, 2087 and 2222 are scanned and attacked constantly. If only you and your team need them, allow them for specific IP addresses only, or put them behind a VPN.

This tool tests public internet addresses only. Private, loopback, link-local, carrier-grade NAT, documentation and other reserved ranges (IPv4 and IPv6) are refused, including hostnames that resolve to them. Each visitor can run 20 checks per hour.

Official documentation: firewall-cmd manual (firewalld) · Test-NetConnection (Microsoft Learn) · ss(8) manual page

Related: TCP Ping (Port 80/443 Latency) · SMTP Test: Free STARTTLS, Certificate and Banner Check · AI Firewall Rule Builder for CSF, firewalld, nftables and UFW · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense · Harden SSH AlmaLinux 9: Secure Setup in 15 Minutes

See also: CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans · Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall · Imunify360 False Positives: Find the Rule ID and Fix It

Frequently asked questions

What is the difference between a closed and a filtered port?

A closed port answers with a reset, so the host is reachable but nothing accepts the connection. A filtered port does not answer at all, which almost always means a firewall is silently dropping the packets.

Can this tool check UDP ports?

No. It opens TCP connections only. UDP services such as DNS on 53 or SIP on 5060 need a protocol-specific test, for example a DNS query or a SIP OPTIONS request.

Why is port 25 not tested?

Our hosting provider blocks outbound connections on port 25, as many providers do to prevent spam. Test 587 or 465 here, or test 25 from another server.

Is it legal to check open ports on a server?

Checking your own servers is normal administration. Only test hosts you own or manage, or have permission to test; this tool limits checks to 10 ports and 20 checks per hour to keep it a diagnostic tool, not a scanner.

Why does the port show open here but not from my office?

Our server and your office have different IP addresses. A firewall allow list, a country block or your ISP filtering outbound traffic can block you while allowing us. Test from your machine with nc or Test-NetConnection to compare.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.