Port Checker
Check whether one well-known port on a host answers — open, closed, or timed out.
Checking for an existing session…
Enter a host and pick a port.
How it works
This opens a TCP connection to one host on one well-known port and closes it immediately — no data sent, no banner read. It answers exactly one question: did something respond on that port right now.
Why this is not a port scanner
A scanner sweeps a range of ports, or several hosts, looking for what is open. This checks one port you picked, from a fixed list of well-known services, against one host you named. That is a deliberate, structural limit — arbitrary ports and multi-port sweeps are not just discouraged here, they are not something the interface can express.
A timeout is not the same as "closed"
A closed port answers with a TCP reset, which is fast and unambiguous. A firewall that silently drops the connection produces no answer at all, which looks identical to a slow network path from the outside. Read a timeout as "nothing came back," not as a confident "this port is closed."
What it will not check
Private, loopback, link-local, CGNAT and other non-public addresses are refused, including hostnames that resolve
to one — the check runs from Quietlytic's servers, not your network, so it can only tell you what the public
internet sees. Port 25 (SMTP) is not offered because the platform this runs on does not permit outbound
connections to it, and addresses on Cloudflare's own network are reported as blocked for the same
reason: the answer would describe the platform, not the host. Checks are limited to 10 per hour from one IP
address.
Example
Check 3389 (RDP) or 22 (SSH) on a host you manage to confirm a firewall change actually
took effect before assuming it did. Check 6379 (Redis) or 3306 (MySQL) on a
public-facing host — either answering from the internet is usually a finding worth writing up on its own.
Frequently asked questions
Why only one port at a time instead of scanning a range?
Because a range scan against a host you do not control is the behaviour this tool was deliberately built to never do. A single well-known port from a fixed allowlist gives you a genuine reachability answer — "is SSH reachable from the internet" — without the tool becoming infrastructure for probing hosts at scale, which is both an abuse vector and, against a host you do not have permission to test, a legal problem.
Why can a firewall drop make this look the same as the port being closed?
Because from outside the connection, they produce the identical signal: nothing comes back. A closed port replies with a TCP reset — fast. A firewall that silently drops the packet produces no reply at all, which reads as a timeout rather than a reset. This tool reports both as distinct states where it can tell the difference, but a timeout should be read as "did not answer," not confidently as "definitely closed."
Does this tell me what is running on the port?
No. It opens a connection and closes it immediately without exchanging any data — no banner grab, no service fingerprinting. That is a deliberate limit, not a missing feature: banner grabbing reads as more intrusive than a bare reachability check, and this tool is built to stay on the safe side of that line.
Related tools
Common Ports Lookup
Look up what normally listens on a TCP or UDP port, and why it matters if it is exposed.
LocalDNS Lookup
Query A, AAAA, MX, TXT, NS, CNAME, SOA and CAA records for any domain.
Sends dataPrivate & Public IP Classifier
Tell whether an address is routable, private, loopback or otherwise reserved.
LocalSSL Certificate Lookup
Every certificate publicly logged for a domain, decoded — via Certificate Transparency, not a live handshake.
Sends dataCIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
LocalIP Subnet Calculator
Enter an IPv4 address with a prefix or subnet mask, see the whole subnet, and divide it.
Local