Web & Internet Tools
External API Probes network ports locally via browser fetch/abort timeouts. No server-side port scans are conducted.

Port Checker & Network Port Security Reference

Audit common network service ports, security risk exposures, and test endpoint reachability

Port Checker & Network Security Reference

Evaluate network service exposure, vulnerability risks, and test reachable endpoints.

Network Audit Reference
Live Browser Socket Probe
PortServiceRisk LevelFunctionRecommended Security Action
21FTP (TCP)highFile Transfer Protocol (Cleartext credentials risk)Block or replace with SFTP (Port 22)
22SSH / SFTP (TCP)mediumSecure Shell remote terminal & encrypted transferAllow via Key Auth only, disable password auth
25SMTP (TCP)highSimple Mail Transfer Protocol (frequent spam target)Restrict outbound to verified mail relays
53DNS (UDP/TCP)mediumDomain Name System resolutionAllow internal/configured recursive resolvers
80HTTP (TCP)lowUnencrypted Web TrafficRedirect all traffic permanently (301) to HTTPS (443)
110POP3 (TCP)highPost Office Protocol email retrieval (Cleartext)Block; migrate to POP3S (Port 995)
143IMAP (TCP)highInternet Message Access Protocol (Cleartext)Block; migrate to IMAPS (Port 993)
443HTTPS (TCP)lowHypertext Transfer Protocol Secure (TLS 1.2/1.3)Allow publicly with strong cipher suites & HSTS
465SMTPS (TCP)lowEncrypted SMTP submission over TLSAllow outbound for authenticated mail sending
587Submission (TCP)lowEmail client message submission with STARTTLSAllow for authorized mail clients
993IMAPS (TCP)lowSecure IMAP over TLS email synchronizationAllow for modern mail clients
995POP3S (TCP)lowSecure POP3 over TLSAllow for secure mail clients
1433MS SQL (TCP)highMicrosoft SQL Server DatabaseStrictly isolate to private VPC; never expose to 0.0.0.0/0
1521Oracle DB (TCP)highOracle Database ListenerStrictly isolate to private internal networks
3306MySQL (TCP)highMySQL / MariaDB database portBind to 127.0.0.1 or VPC security group
3389RDP (TCP)highRemote Desktop Protocol for Windows serversBlock from public internet; require VPN + MFA
5432PostgreSQL (TCP)highPostgreSQL relational databaseBind to internal private subnet only
6379Redis (TCP)highIn-Memory Cache (often unauthenticated by default)Never expose publicly; configure requirepass and VPC bind
8080HTTP-Alt / Dev (TCP)mediumSecondary HTTP port, proxy, or dev serverVerify authentication before exposure
8443HTTPS-Alt (TCP)lowSecondary HTTPS service or admin panelProtect with IP whitelist or SSO
27017MongoDB (TCP)highMongoDB NoSQL database portIsolate behind private network with SCRAM-SHA-256

About Port Checker & Network Port Security Reference

Interactive network port security reference and browser connection reachability tester. Inspect standard ports for Web (80, 443), Remote Shell (22), Mail (25, 587, 993), Databases (3306, 5432, 27017, 6379), and evaluate security risk levels and firewall rules.

Key Capabilities & Features

  • Live browser connection probe for testable HTTP/HTTPS/WebSocket ports
  • Comprehensive security encyclopedia for 20+ common TCP/UDP ports
  • Vulnerability risk rating (High, Medium, Low) for exposed database and administrative services
  • Actionable firewall hardening rules (e.g., block cleartext FTP, isolate Redis and MySQL to VPC)
  • Filter ports by High Risk, Web Services, or Database engines

How to Use Port Checker & Network Port Security Reference

1

Select Target Host & Port

Enter an IP address or hostname and choose a port to test.

2

Run Probe

Click Probe Port to test whether the port responds or times out.

3

Review Security Reference

Consult the port catalog for vulnerability advisories and firewall recommendations.

Privacy & In-Browser Execution Guarantee

Probes network ports locally via browser fetch/abort timeouts. No server-side port scans are conducted.

Frequently Asked Questions

Can a web browser directly scan TCP or UDP ports on a remote server?

Browsers restrict raw socket creation for security. Web port checks utilize WebSocket/Fetch HTTP probes and comprehensive reference directories of standard port allocations.

Which network ports are most commonly targeted by attackers if left open?

Common targets include Port 21 (FTP), Port 22 (SSH), Port 23 (Telnet), Port 3389 (RDP), Port 445 (SMB), and unauthenticated database ports like 3306 (MySQL) and 6379 (Redis).

How can I close or secure an open port on my server?

Configure your operating system firewall (e.g. ufw deny 8080 on Ubuntu or Windows Defender Firewall) and bind backend services strictly to 127.0.0.1 (localhost).