What an open port means
Three outcomes are possible and they are not interchangeable. Open means something accepted a TCP connection on that port — a service is listening and reachable from the public internet. Closed means the host answered but refused: it is up, nothing is listening there. Filtered means nothing came back at all, which normally indicates a firewall dropping packets silently rather than rejecting them, and is usually what you want to see for a port you are not using.
The scan runs from our server against the address you give, so it tells you what the public internet sees. A port that is open to your local network but firewalled from outside will correctly show as filtered here, which is exactly the check most people actually want.
Common ports
How the scan is run, and its limits
This is one of only three tools on the site where a connection leaves our server toward an address you supplied, so the validation is the feature rather than a formality. The target is resolved first and judged afterwards — checking a hostname is pointless, since a name like internal.example.com can resolve happily to a private address — and the address we are actually about to open a socket to is what gets vetted. Private, loopback and reserved ranges are refused.
The scan covers a fixed catalogue of well-known ports rather than an arbitrary range, and there is a limit of ten scans per hour per visitor. Both constraints exist for the same reason: a tool that scans anything at any rate is a tool that will be used against people who did not ask for it.
Scan what you own or have written permission to test. Unauthorised scanning is at minimum a breach of most providers' terms of service and, depending on the jurisdiction, can be an offence in its own right.
Frequently asked questions
Is it legal to scan ports?
Scanning your own servers, or systems you have written authorisation to test, is legal. Scanning someone else’s host without permission breaches most acceptable-use policies and may be a criminal offence depending on where you and the target are.
What is the difference between “closed” and “filtered”?
Closed means the host actively refused the connection — it is reachable and nothing is listening. Filtered means the packet vanished, typically because a firewall dropped it. For a port you are not using, filtered is the better result.
Why can I not scan a full port range?
The tool checks a fixed catalogue of well-known ports. A full-range scan from a shared server is slow, noisy, and useful mainly to people scanning hosts they do not own.
Can I scan a local address like 192.168.1.1?
No. The target is resolved and then checked, and private, loopback and reserved addresses are refused — otherwise the tool would be a way to probe our own internal network from the outside. Scan a local network with a tool running inside it.
My port is open but the service does not work — why?
An open port only means a TCP connection was accepted. The service behind it may be misconfigured, listening on the wrong interface, or rejecting the request at the application layer. Check latency with the ping test and then look at the service’s own logs.
Why is there a scan limit?
Ten scans per hour keeps the tool useful for checking your own servers and useless as a scanning platform. It is the same reason the port list is fixed rather than arbitrary.