How to Check Open Ports: A Complete Guide to Port Scanning

Last Updated: October 2026

Quick Summary

  • ✓ Network ports (0–65535) identify specific services on a computer — HTTP uses port 80, HTTPS uses 443, SSH uses 22.
  • ✓ Ports can be open (accepting connections), closed (no service listening), or filtered (blocked by a firewall).
  • ✓ Use netstat, ss, nmap, or PowerShell to check ports from the command line.
  • ✓ Open ports you don't need are a security risk — close them or block them with a firewall.
  • ✓ Our online Port Checker tool lets you test ports without installing software.

What Are Network Ports?

A network port is a 16-bit number (ranging from 0 to 65,535) that serves as a communication endpoint on a networked device. While an IP address identifies a computer on the network, the port number identifies a specific service or application running on that computer. Together, an IP address and a port number form a socket — the unique address where data is sent and received.

Think of it like an apartment building: the IP address is the building's street address, and each port number is an apartment number within the building. Mail (network data) is addressed to both the building and a specific apartment so it reaches the right recipient.

Ports operate at the transport layer (Layer 4) of the OSI model and are used by two protocols: TCP (Transmission Control Protocol) and UDP (User Datagram Protocol). A TCP port and a UDP port with the same number are distinct endpoints — port 53/TCP and port 53/UDP are separate and can run different services simultaneously.

TCP vs UDP

Understanding the difference between TCP and UDP is essential for port scanning and network troubleshooting:

TCP (Transmission Control Protocol)
Connection-oriented protocol that establishes a connection through a three-way handshake (SYN, SYN-ACK, ACK) before transmitting data. TCP guarantees delivery, ordering, and error-checking. It is used for web browsing (HTTP/HTTPS), email (SMTP, IMAP, POP3), file transfer (FTP, SFTP), remote access (SSH), and database connections. Most port scanning focuses on TCP because its handshake mechanism makes it easy to determine whether a port is open.
UDP (User Datagram Protocol)
Connectionless protocol that sends data without establishing a connection or waiting for acknowledgments. UDP is faster but does not guarantee delivery or ordering. It is used for DNS queries (port 53), streaming media, online gaming, VoIP (SIP on port 5060), DHCP (ports 67/68), and SNMP (port 161). UDP port scanning is slower and less reliable because there is no handshake — the absence of a response could mean the port is open, filtered, or the packet was lost.

Port Number Ranges

The Internet Assigned Numbers Authority (IANA) divides the 65,536 port numbers into three ranges:

Well-Known Ports (0–1023)

These ports are assigned to widely-used protocols and services by IANA. On Unix-like systems, binding to ports below 1024 typically requires root (superuser) privileges. Here are the most important well-known ports every network administrator should know:

  • Port 20/21 — FTP: File Transfer Protocol. Port 21 handles control commands; port 20 handles data transfer in active mode. FTP transmits credentials in plain text, so SFTP (port 22) or FTPS are preferred.
  • Port 22 — SSH: Secure Shell. Provides encrypted remote terminal access and secure file transfer (SCP/SFTP). SSH replaced the insecure Telnet protocol.
  • Port 23 — Telnet: Unencrypted remote access protocol. Considered insecure because all data (including passwords) is transmitted in plain text. Should be disabled in favor of SSH.
  • Port 25 — SMTP: Simple Mail Transfer Protocol. Used for sending email between mail servers. Modern email submission from clients uses port 587 (with STARTTLS) or port 465 (implicit TLS).
  • Port 53 — DNS: Domain Name System. Handles domain name resolution. Uses both UDP (for standard queries) and TCP (for zone transfers and large responses).
  • Port 80 — HTTP: Hypertext Transfer Protocol. The standard port for unencrypted web traffic. Most websites redirect port 80 traffic to port 443 (HTTPS).
  • Port 110 — POP3: Post Office Protocol v3. Used by email clients to retrieve mail from a server. The encrypted version (POP3S) uses port 995.
  • Port 143 — IMAP: Internet Message Access Protocol. Another email retrieval protocol that supports server-side message management. The encrypted version (IMAPS) uses port 993.
  • Port 443 — HTTPS: HTTP over TLS. The standard port for encrypted web traffic. This is the most important port for modern web services.

Registered Ports (1024–49151)

These ports are assigned by IANA to specific services upon request but do not require elevated privileges to use. Notable examples include:

  • Port 1433 — Microsoft SQL Server
  • Port 3306 — MySQL
  • Port 3389 — RDP (Remote Desktop Protocol)
  • Port 5432 — PostgreSQL
  • Port 5900 — VNC (Virtual Network Computing)
  • Port 6379 — Redis
  • Port 8080 — HTTP Alternate (commonly used for development servers and proxies)
  • Port 8443 — HTTPS Alternate
  • Port 27017 — MongoDB

Dynamic / Ephemeral Ports (49152–65535)

These ports are used temporarily by client applications for outgoing connections. When your browser connects to a website on port 443, your operating system assigns a random ephemeral port (e.g., 52847) as the source port for that connection. These ports are never assigned to specific services and are allocated dynamically by the OS kernel.

Port States: Open, Closed, and Filtered

When you scan a port, it will be in one of three states:

Open
A service is actively listening on this port and accepting connections. When a scanner sends a TCP SYN packet to an open port, the target responds with SYN-ACK. This means the service is running and reachable. An open port is not inherently dangerous, but every open port is a potential attack surface that must be secured.
Closed
No service is listening on this port, but the port is accessible (not blocked by a firewall). The target responds to a TCP SYN packet with a RST (reset) packet, indicating that the connection was refused. Closed ports confirm that the host is alive and reachable, but no service is available on that specific port.
Filtered
A firewall, packet filter, or other network security device is blocking the port, preventing the scanner from determining whether it is open or closed. The probe packets are silently dropped with no response, or an ICMP unreachable message is returned. Filtered ports are the hardest to diagnose because the scanner must wait for a timeout before concluding the port is filtered.

Why Check Open Ports?

Checking open ports is a fundamental task in network security and administration. Here are the primary reasons to perform port checks:

  • Security audits: Identify services exposed to the internet that should not be. An unexpected open port could indicate a misconfigured service, a backdoor, or malware communicating with a command-and-control server.
  • Firewall verification: Confirm that your firewall rules are working as intended. After configuring firewall rules, scan your external IP to verify that only the intended ports are accessible from the internet.
  • Troubleshooting connectivity: When a service is unreachable, checking whether its port is open helps isolate whether the problem is with the service itself, the firewall, or the network path.
  • Compliance: Many security frameworks (PCI DSS, SOC 2, ISO 27001) require regular port scanning and documentation of exposed services.
  • Attack surface reduction: Every open port is a potential entry point. Regular scanning helps maintain the principle of least privilege by ensuring only necessary ports are open.

How to Check Ports on Windows

Using netstat

The netstat command displays active network connections and listening ports. Open Command Prompt or PowerShell and run:

  • netstat -an — Shows all connections and listening ports in numeric format. Look for lines with "LISTENING" in the State column to see which ports are open on your machine.
  • netstat -ano — Adds the process ID (PID) so you can identify which application is using each port. Cross-reference the PID in Task Manager to find the process name.
  • netstat -an | findstr :443 — Filters output to show only connections on port 443.

Using PowerShell Test-NetConnection

PowerShell provides a built-in cmdlet to test whether a specific port is open on a remote host:

  • Test-NetConnection -ComputerName example.com -Port 443 — Tests TCP connectivity to port 443 on example.com. The output includes TcpTestSucceeded: True/False.
  • Test-NetConnection -ComputerName 192.168.1.1 -Port 22 — Tests SSH port on a specific IP address.
  • 1..1024 | ForEach-Object { Test-NetConnection -ComputerName example.com -Port $_ -WarningAction SilentlyContinue } | Where-Object TcpTestSucceeded — Scans all well-known ports (slow but works without third-party tools).

Using PowerShell TcpClient

For faster port testing in PowerShell, you can use the .NET TcpClient class directly:

  • $tcp = New-Object System.Net.Sockets.TcpClient; $tcp.ConnectAsync('example.com', 443).Wait(1000); $tcp.Connected — Returns True if port 443 is open, with a 1-second timeout.

How to Check Ports on macOS and Linux

Using ss (Socket Statistics)

The ss command is the modern replacement for netstat on Linux. It is faster and provides more detailed information:

  • ss -tlnp — Shows all TCP listening ports with process names. The flags mean: -t (TCP), -l (listening), -n (numeric), -p (process).
  • ss -ulnp — Shows all UDP listening ports with process names.
  • ss -tlnp | grep :443 — Filters to show only port 443.

Using netstat (macOS / older Linux)

  • netstat -an | grep LISTEN — Lists all listening ports on macOS or older Linux systems.
  • netstat -tlnp — On Linux with net-tools installed, shows TCP listening ports with process names.

Using nmap (Network Mapper)

nmap is the industry-standard port scanning tool used by security professionals worldwide. It is available for Linux, macOS, and Windows:

  • nmap example.com — Scans the 1,000 most common TCP ports on a host.
  • nmap -p 1-65535 example.com — Scans all 65,535 TCP ports (full port scan).
  • nmap -sU example.com — Performs a UDP port scan (requires root/admin privileges).
  • nmap -sV example.com — Detects the version of services running on open ports.
  • nmap -sS example.com — Performs a SYN scan (half-open scan), which is faster and stealthier than a full connect scan.
  • nmap -A example.com — Aggressive scan: OS detection, version detection, script scanning, and traceroute in one command.

Using nc (Netcat)

Netcat is a lightweight utility for testing individual ports:

  • nc -zv example.com 443 — Tests if port 443 is open. The -z flag means scan without sending data; -v enables verbose output.
  • nc -zv example.com 20-100 — Scans a range of ports from 20 to 100.
  • nc -zuv example.com 53 — Tests a UDP port (the -u flag selects UDP).

Using Our Online Port Checker Tool

If you want to check open ports from an external perspective without installing any software, our Port Checker tool scans common TCP ports on any public IP address or domain name from our infrastructure. This is particularly useful for:

  • Verifying that your firewall is blocking ports correctly from the outside world
  • Confirming that a service is reachable from the internet (not just from your local network)
  • Quick checks when you do not have access to command-line tools
  • Testing port forwarding configurations on your router

The tool shows the state of each port (open or closed/filtered) and identifies the standard service associated with each port number.

Common Security Risks of Open Ports

Every open port represents a potential entry point for attackers. Here are the most significant risks:

  • Brute-force attacks: Services like SSH (22), RDP (3389), and FTP (21) are constantly targeted by automated bots attempting to guess passwords. If you must expose these services, use key-based authentication, fail2ban, or move them to non-standard ports.
  • Exploitation of vulnerabilities: Software listening on open ports may contain known vulnerabilities. Unpatched web servers, database servers, or application servers are prime targets. Keep all exposed software updated.
  • Data exfiltration: Malware on a compromised system may open ports to communicate with command-and-control servers. Unexpected open ports on outbound scans can indicate compromise.
  • Denial of Service (DoS): Open ports can be targeted with traffic floods to exhaust server resources. Rate limiting and DDoS protection help mitigate this risk.
  • Information disclosure: Service banners on open ports can reveal software versions and operating system details, helping attackers choose targeted exploits. Configure services to minimize information in banners.

How Firewalls Work

A firewall is a network security device (hardware or software) that monitors and controls incoming and outgoing network traffic based on predetermined rules. Firewalls are the primary defense mechanism for controlling which ports are accessible.

Packet Filtering

The simplest type of firewall. It examines each network packet independently and decides whether to allow or block it based on source/destination IP address, source/destination port, and protocol (TCP/UDP/ICMP). Packet filters are fast but have no understanding of connection state — they cannot determine whether a packet is part of an established conversation or a new connection attempt. Examples include basic iptables rules and router ACLs (Access Control Lists).

Stateful Inspection

Stateful firewalls track the state of network connections. They maintain a state table that records all active connections and their characteristics. When a packet arrives, the firewall checks whether it belongs to an established, legitimate connection. This allows the firewall to automatically allow return traffic for outgoing connections while blocking unsolicited incoming packets. Modern operating system firewalls (Windows Defender Firewall, Linux nftables/iptables with conntrack, macOS pf) are stateful by default.

Application-Layer Firewalls

Also called Layer 7 firewalls or Web Application Firewalls (WAFs). These firewalls understand application protocols (HTTP, DNS, FTP) and can inspect the content of traffic, not just headers. They can block SQL injection attempts, cross-site scripting (XSS) payloads, and other application-layer attacks. Cloud-based WAFs like Cloudflare, AWS WAF, and Azure Front Door provide this protection at scale.

Port Forwarding Explained

Port forwarding (also called port mapping) is a technique used on NAT routers to redirect incoming traffic on a specific port to a particular device on the private network. Without port forwarding, devices behind a NAT router cannot receive unsolicited incoming connections from the internet.

How Port Forwarding Works

  1. An external client sends a request to your public IP address on a specific port (e.g., 203.0.113.50:8080).
  2. Your router receives the packet and checks its port forwarding table.
  3. The router finds a rule that maps external port 8080 to internal IP 192.168.1.100 on port 80.
  4. The router rewrites the destination address and forwards the packet to 192.168.1.100:80.
  5. The internal server processes the request and sends a response back through the router, which translates the source address back to the public IP.

Common Port Forwarding Use Cases

  • Home web server: Forward port 80/443 to a local machine running Apache, Nginx, or IIS.
  • Game server: Forward the game's specific port (e.g., Minecraft uses 25565) to the host machine.
  • Remote desktop: Forward port 3389 (RDP) to access a Windows machine remotely (use a VPN instead if possible).
  • Security cameras: Forward the camera's web interface port to view footage remotely.
  • SSH access: Forward port 22 to access a Linux machine from outside your network.

Security Considerations for Port Forwarding

Port forwarding exposes internal services to the internet, which introduces security risks. Always use strong passwords, keep software updated, and consider using a VPN instead of port forwarding for sensitive services like RDP and SSH. If you must use port forwarding, consider changing the external port to a non-standard number (security through obscurity — not a substitute for real security, but it reduces automated scanning noise).

Frequently Asked Questions

What is a network port?

A network port is a numbered endpoint (0–65535) that identifies a specific process or service on a computer. Ports allow a single IP address to handle multiple simultaneous network connections. For example, a web server listens on port 80 (HTTP) and port 443 (HTTPS) at the same time.

How do I check if a port is open on Windows?

On Windows, use netstat -an in Command Prompt to list all open ports, or Test-NetConnection -ComputerName hostname -Port 80 in PowerShell to test a specific port on a remote host. For a quick online check, use our Port Checker tool.

What is the difference between TCP and UDP ports?

TCP is connection-oriented and guarantees delivery through handshakes and acknowledgments. UDP is connectionless and does not guarantee delivery, making it faster but less reliable. TCP is used for web browsing, email, and file transfer; UDP is used for DNS, streaming, gaming, and VoIP.

What does it mean when a port is "filtered"?

A filtered port means a firewall is blocking the connection attempt, preventing the scanner from determining whether the port is open or closed. The probe packets are silently dropped. This is different from a closed port, which actively responds with a RST packet.

Is port scanning legal?

Port scanning your own systems is legal. Scanning systems you do not own is a legal gray area that varies by jurisdiction. Always obtain written permission before scanning systems you do not own.

What are the most commonly attacked ports?

The most commonly attacked ports include SSH (22), FTP (21), Telnet (23), SMTP (25), DNS (53), HTTP (80), HTTPS (443), SMB (445), RDP (3389), and MySQL (3306). These are targeted because they run well-known services that may have vulnerabilities.

How do I close an open port?

Stop the service listening on that port, or configure your firewall to block incoming connections. On Linux, use sudo ufw deny PORT. On Windows, create an inbound rule in Windows Defender Firewall to block the port.

What is port forwarding and when do I need it?

Port forwarding redirects incoming traffic on a specific external port to a device on your local network. You need it to make a service on a private network accessible from the internet, such as hosting a game server or web server from home.