How to read the result
- Open — something accepted the connection. The port is reachable from the internet; whether it is the program you meant is worth a look with
ss -tlnpon the machine. - Closed — your router or machine answered and refused. Typically the port is not forwarded, or the program is not running or listens on
127.0.0.1only. - No answer (filtered) — nothing came back within three seconds. A firewall is dropping the connection, the forward points to a machine that is off, or your provider filters the port.
Checking a server or another address
Choose Another IP address to test a server from outside its own network — after opening a port in its firewall, or to see whether a game server is reachable before you hand out the address. The check comes from our test server in Amsterdam, so a firewall that only lets in certain countries or addresses shows the port as filtered even when it is open for you. Enter the address itself; for a domain, look its A or AAAA record up with the DNS lookup first.
One address can be checked twenty times in ten minutes and a hundred times a day by all visitors together, and a whole /24 (or IPv6 /48) sixty times an hour and 250 times a day, one port per check — enough to test your own services, not enough to sweep a network. Private and reserved ranges cannot be checked at all.
Port forwarding checklist
- 1The program listens on all interfaces
Linux sudo ss -tlnp | grep 25565Look for
0.0.0.0:25565or[::]:25565. A line with127.0.0.1only accepts connections from the machine itself. - 2The machine's own firewall lets it in
On Linux with UFW:
sudo ufw allow 25565/tcp. On Windows, add an inbound rule in Windows Defender Firewall for the program or the port. - 3The router forwards the port
Forward the TCP port to the machine’s LAN address (give it a fixed one in the router’s DHCP settings, or the forward breaks the next time it changes).
- 4Your line has a public address of its own
Compare the WAN address on the router’s status page with the address the checker reports. If they differ, or the WAN address starts with
100.64to100.127, your provider puts you behind carrier-grade NAT; ask for a public IPv4 address, or run the service on a server instead.
On a VPS there is no router in between: the server has its own public address, so only steps 1 and 2 apply. A “closed” there is usually a service that is not running — the same thing a client reports as Connection refused.
Common TCP ports
| Port | Service | Note |
|---|---|---|
| 22 | SSH | Often moved to another port to cut log noise |
| 25 | SMTP | Many home and mobile providers block it outbound and inbound |
| 80 / 443 | HTTP / HTTPS | Some home providers block 80 inbound |
| 3389 | Remote Desktop (RDP) | Better reached through a VPN or limited to your IP |
| 3306 | MySQL / MariaDB | Should normally not be open to the internet |
| 5432 | PostgreSQL | Should normally not be open to the internet |
| 25565 | Minecraft: Java Edition | Bedrock uses UDP 19132, which this tool cannot test |
| 30120 | FiveM | Uses UDP on the same port as well |
| 32400 | Plex Media Server | Remote access needs this one forwarded |
UDP-only services — Valheim, Palworld, most voice servers — cannot be tested by a connection check, because UDP has no handshake to complete. The surest test is the game’s own client connecting from outside your network.
Frequently asked
How do I check whether a port is open?
Enter the port number and run the check. Our server in Amsterdam then tries to open a TCP connection to that port — on your public IP address, the one this page reaches us from, or on the address you enter — and reports whether anything answered within three seconds. To test port forwarding, run it from the network you want to test, with the service already running.
Why does it say closed or no answer when my service is running?
“Closed” means the connection reached a device that turned it away: the port is not forwarded to your machine, or nothing listens on it. “No answer” means nothing answered at all, usually a firewall dropping the packets. Check the router's port forwarding, the firewall on the machine itself (ufw, Windows Defender Firewall) and that the service listens on 0.0.0.0 rather than only on 127.0.0.1. If the WAN address your router shows differs from the address on this page, your provider has you behind carrier-grade NAT, and no forwarding rule on your router can make a port reachable.
Can I check a port on another IP address or server?
Yes: choose “Another IP address” and enter a public IPv4 or IPv6 address — an address, not a host name. Each check tests one port. One address can be checked twenty times in ten minutes and a hundred times a day by all visitors together, and a whole /24 (or IPv6 /48) sixty times an hour and 250 times a day — enough to test your own services, not enough to sweep a network. Private, reserved and our own network's addresses are refused. A check of another address is logged with that address's network, the port, the result and your own network, never full addresses.
Does it work for UDP ports or over IPv6?
TCP only. UDP has no handshake, so a silent UDP port cannot be told apart from a filtered one without speaking the game's or the service's own protocol. IPv6 addresses can be checked when you enter one; your own address is checked over IPv4, the protocol this page reaches our server with.
Is the check safe for my network?
It opens one TCP connection and closes it again as soon as it is accepted: no data is sent and nothing is read from your service. Each visitor can run ten checks a minute.
Related guides
UFW firewall setup: deny by default, open what you serve
Configure UFW the safe way: allow SSH first, open only the ports you serve, restrict sensitive ports by source, and rate-limit the noise.
SSH connection refused — the four causes and how to fix each
'Connection refused' on port 22 means the server said no, not the network. How to check sshd, the port, the firewall and the address — in order.
Address already in use (EADDRINUSE) — free the port
Something already holds the port you want. How to find the process, stop it or switch ports, and handle the TIME_WAIT case after a restart.