ScreenshotNeo

BlogComparisons

6 Online Port Scanners for Finding Open Ports

Compare six online port scanners, understand open versus filtered results, and troubleshoot port forwarding safely from an external network.

By the ScreenshotNeo team29 September 20269 min read

6 Online Port Scanners for Finding Open Ports

Online port scanners test your public host from outside your network. They are useful for confirming a router forward, checking whether a service is exposed, and getting a quick view of an internet-facing attack surface.

For a forwarding problem, start with a single-port checker. For a broader authorized assessment, use a scanner that supports custom ports, service detection, or a larger port range. A result describes what the scanner can observe from its own network; it may differ from a scan run inside your LAN.

Quick comparison

Scanner Best use Ports and protocols Useful capabilities
HackerTarget Online Nmap Scanner Broader external assessment Free scan checks 10 common TCP ports; paid options include all 65,535 TCP ports, UDP and custom selections Nmap service/version detection, scheduled scans, reports, IPv6 and API access are described by HackerTarget
ViewDNS Port Scanner Fast common-port check 15 listed TCP ports: 21, 22, 23, 25, 80, 110, 139, 143, 445, 1433, 1521, 3306, 3389, 8080 and 8443 Simple named-service reachability check
DNSChecker Online Port Checker Custom port and forwarding checks Custom lists, common-port presets, TCP or UDP Accepts a domain or IP and reports open, closed, or timed-out/blocked
PortChecker.co One-port router diagnosis One specified port on your current or another IP Explains how blocked ports affect applications and games; useful after adding a port forward
YouGetSignal Open Port Check Tool External forwarding and firewall check One selected port on an IP or domain Selectable scanning region; guidance for port forwarding and server applications
IPVoid TCP Port Scanner Authorized custom TCP checks Common or custom ports, IPv4 or IPv6 Uses Nmap; IPVoid says to scan only addresses you control or are authorized to test

1. HackerTarget Online Nmap Scanner

Choose HackerTarget when you need more than a single yes/no answer. Its free online scan checks ten common TCP ports and includes Nmap service/version detection. HackerTarget describes paid capabilities for all 65,535 TCP ports, UDP, custom selections, scheduled scans, reports, IPv6 and API access. That makes it the strongest choice in this list for an ongoing perimeter review.

An external scanner observes the path through DNS, NAT, firewalls, and the listening service.
An external scanner observes the path through DNS, NAT, firewalls, and the listening service.

Use the hostname or public IP that should receive traffic. If DNS has recently changed, verify the address first; otherwise you may scan an old server.

2. ViewDNS Port Scanner

ViewDNS is a focused check against 15 frequently used service ports. It is convenient when you want to ask whether a named service such as SSH (22), HTTP (80), HTTPS alternate (8443), MySQL (3306), or RDP (3389) is reachable. It does not replace a custom or full-range assessment, but it is quick for a first pass.

3. DNSChecker Online Port Checker

DNSChecker fits cases where you know the exact ports to test. Enter a domain or IP, provide a custom list or choose common ports, and select TCP or UDP. Its result distinguishes open, closed, and timed-out or blocked outcomes. This is useful for checking several game, VPN, or self-hosted application ports after a router change.

4. PortChecker.co

PortChecker.co is designed around one specific port. It can use your current public IP or another address and includes explanations for blocked ports affecting applications and games. Use it immediately after creating a port-forward rule, while the service is running and listening on the internal host.

5. YouGetSignal Open Port Check Tool

YouGetSignal checks a selected port on a domain or IP and lets you choose a region for the external check. A selectable region can help reveal a routing or geo-specific firewall policy. It is a practical second check when a port appears open from one location but not another.

6. IPVoid TCP Port Scanner

IPVoid provides common or custom TCP port checks and accepts IPv4 or IPv6 input. It states that the service uses Nmap. Its terms also require that you scan only IP addresses you control or are authorized to scan. Treat that authorization requirement as a baseline for every scanner in this list.

How to choose the right scanner

Your question Start here Why
Did my router forward TCP 25565? PortChecker.co or YouGetSignal One-port external confirmation is fast and easy to repeat
Are several specified TCP and UDP ports reachable? DNSChecker Custom lists and protocol selection match the question
Which common services are exposed? ViewDNS It checks a defined set of common service ports
Do I need service/version detection? HackerTarget Its online Nmap scan includes detection; broader options are described for paid use
Do I need IPv6 or custom TCP ranges? IPVoid or HackerTarget Both describe capabilities for custom or IPv6-oriented checks
Do I need recurring perimeter monitoring? HackerTarget Scheduled scans and reports are among its described paid capabilities
Choose scan breadth and protocol based on the question you need to answer.
Choose scan breadth and protocol based on the question you need to answer.

What open, closed, and filtered mean

Nmap defines open as a port where an application is actively accepting connections. Closed means the host is reachable but no application is listening. Filtered means packet filtering prevents the scanner from determining whether the port is open. Nmap also uses unfiltered, open|filtered, and closed|filtered when the probe cannot separate those states. See the Nmap port-scanning documentation.

A web result is an observation from that scanner’s network. Firewalls, NAT, routing, source IP allowlists, IPv4 versus IPv6, and the probe method can produce different results from an internal scan. A timeout is therefore inconclusive: it does not prove that no service exists.

Safe workflow for checking a public port

  1. Confirm ownership and authorization. Scan only systems you own or have explicit permission to test. HackerTarget instructs users to have permission, and IPVoid’s terms restrict scans to authorized addresses.
  2. Resolve the name. Check that the hostname points to the intended public address. For a quick local check, run dig +short example.com or nslookup example.com.
  3. Start small. Test one port for forwarding, a common-port list for an exposure check, or a custom range when you have a documented assessment scope.
  4. Make the service listen. A forwarding rule cannot succeed if the application is stopped, bound only to localhost, or listening on a different port.
  5. Run the external test. Use a scanner outside your LAN. Do not rely on a device connecting to your public address from inside the same network; many routers lack NAT loopback.
  6. Validate the result. Check the host firewall, router rule, service logs, and the scanner’s protocol. Repeat from a second external vantage point after changes.
  7. Reduce exposure. If a port is unexpectedly open, identify the service, patch it, require authentication, restrict source networks, or close the port when it is unnecessary.

Command-line and code checks you control

Online scanners are valuable because they originate outside your network. For an authorized host, you can complement them with local tools. These examples do not bypass firewalls or NAT; they show how to test a service from a machine that can reach it.

# TCP connection test (Linux, macOS, or Windows with a compatible nc)
nc -vz example.com 443

# Nmap: one port, then a documented custom list
nmap -Pn -p 22,80,443 example.com

# Nmap service/version detection for an authorized target
nmap -Pn -sV -p 22,80,443 example.com
import socket

host = "example.com"
port = 443
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.settimeout(5)
try:
    sock.connect((host, port))
    print(f"{host}:{port} is reachable over TCP")
except (socket.timeout, ConnectionRefusedError, OSError) as exc:
    print(f"TCP check failed: {exc}")
finally:
    sock.close()
import net from "node:net";

const host = "example.com";
const port = 443;
const socket = net.createConnection({ host, port, timeout: 5000 });
socket.on("connect", () => {
  console.log(`${host}:${port} accepted a TCP connection`);
  socket.end();
});
socket.on("timeout", () => {
  console.log(`${host}:${port} timed out`);
  socket.destroy();
});
socket.on("error", (err) => console.log(`${host}:${port} failed: ${err.code}`));

A successful TCP handshake only proves that something accepted the connection from that vantage point. It does not prove that the application is secure, correctly configured, or reachable over UDP.

Why a port shows filtered or timed out

Router forwarding points to the wrong private address

DHCP can change the server’s LAN address. Reserve the address in DHCP or assign a static address, then update the forwarding rule.

The service is not listening

Check the application’s bind address and listening port. A process bound to 127.0.0.1 cannot receive traffic arriving on the LAN interface. On Linux, inspect listeners with ss -lntup; on Windows, use netstat -ano.

The host firewall drops the probe

Allow only the required protocol and port, then retest from outside. A silent drop commonly appears as filtered or timed out.

Carrier-grade NAT or double NAT

If your router’s WAN address differs from the address shown by an external “what is my IP” service, your ISP may use carrier-grade NAT. An upstream modem may also be routing. Put the modem in bridge mode where appropriate, forward through both devices, or request a public address from the ISP.

IPv4 and IPv6 differ

A hostname can have A and AAAA records with different firewall policies. Test the address family you intend to publish and configure its firewall separately.

UDP behaves differently

UDP has no handshake. A scanner may report open|filtered or timeout even when an application is functioning. Use an application-level test or the scanner’s UDP mode, and confirm the service logs.

Source filtering or regional policy

Allowlists, geoblocking, or cloud security groups may permit one scanner region and deny another. Repeat from a different external location and inspect access-control logs.

Performance, reliability, and cost considerations

  • Scan breadth: A single-port test returns quickly. Scanning many ports takes longer and creates more connection attempts; define the smallest scope that answers your question.
  • False conclusions: Rate limits, IDS rules, packet loss, and transient service restarts can change results. Repeat important findings and compare with server logs.
  • Vantage point: A result is specific to the scanner’s network. Region selection or a second service helps identify routing and policy differences.
  • Operational impact: Stay within an approved scope, schedule broad scans responsibly, and avoid scanning third-party infrastructure.
  • Cost: The six tools differ in free scope and paid features. HackerTarget’s broader all-port, UDP, scheduling, reporting, IPv6, and API capabilities are described as paid options. Verify current limits and terms on each provider before planning recurring scans.

Or skip the browser setup

If your next task is collecting visual evidence of a public status page, firewall dashboard, or documentation page, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP, or PDF. Cookie and consent banners are accepted and removed before capture, along with more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

See the ScreenshotNeo API documentation for the available options, including full-page capture, CSS selectors, custom headers and cookies, JavaScript, waits, blocking rules, caching, signed links, asynchronous jobs, bulk capture, and PDF settings.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

An MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

FAQ

Can an online scanner test a private 192.168.x.x address?

No. A public scanner cannot route directly to an RFC1918 private address. Test the public address and configure forwarding, or run a scanner inside the private network.

Does “closed” mean the firewall is working?

It means the host was reachable but no application accepted the connection. A firewall may reject or drop traffic differently, so inspect the firewall policy as well.

Why do two scanners disagree?

They may use different source networks, protocols, timeouts, DNS resolution, or probe methods. Compare the resolved address, protocol, and timestamp before drawing a conclusion.

Should I scan all 65,535 ports?

Only for an authorized assessment where that scope is justified. A targeted list is faster and creates less noise for routine forwarding checks.

Can a port be open but the application still unusable?

Yes. Port state only covers network reachability. Authentication, protocol negotiation, TLS, application configuration, and authorization can still fail.

Further reading

The Nmap Project describes Nmap as a free, open-source utility for network discovery and security auditing. Its official guide, Nmap Network Scanning, explains discovery, port states, service detection, and scan design in depth.