What a port check tests
A TCP port is one numbered endpoint that software can use for network connections. A listening service may accept traffic on a particular port, such as HTTPS on 443 or a game server on a configured port. This tool asks the site's server to attempt one TCP connection to your own public IP address, as seen by the site's connection, on the single port you chose. It never accepts a hostname or another target IP. That design keeps this page from becoming a general scanner for other people's computers.
Open means a TCP connection was accepted at the time of the test. It does not identify the software or confirm that it is configured safely. Closed or filtered means the connection did not succeed before the short timeout. A firewall may silently discard a request, a router may have no forwarding rule, the service may be stopped, or the operating system may reject the connection. The browser cannot distinguish these causes from the outside.
Why a home port may look closed
To expose a device behind a home router, the service usually needs to listen on the device's local interface and the router needs a matching port-forward rule to that device. Both the router firewall and the device firewall must allow the traffic. Check the service's own port setting and confirm the device still has the local address used in the forwarding rule. Some routers do not support connecting back to their own public address from inside the same network, so run this test from a phone on mobile data or another outside connection.
Carrier-grade NAT adds another router controlled by the internet provider. With CGNAT, your router may not own the public address displayed on this site, so ordinary port forwarding on your router alone cannot create an inbound route. Double NAT has a similar effect when two routers are in series. Ask your provider whether it can assign a public IPv4 address or use a supported IPv6 firewall rule. Our port-forwarding guide and CGNAT explanation cover those layouts.
Use the result carefully
Only check a port for a service you administer. A positive result means the port is reachable, so confirm the service uses authentication, current software, and only the access it needs. A negative result is not a security audit: it says nothing about UDP, other ports, internal network exposure, or vulnerabilities in a service. The test is a momentary check from one network location, and provider or firewall rules can change the result later.
Frequently asked questions
Which address is tested?
The site's server uses the source address from your HTTP connection. No destination address is accepted in the form.
Why is a port closed when forwarding is configured?
The service may not be listening, a firewall may block it, the device address may have changed, or CGNAT/double NAT may prevent inbound traffic.
Does it test UDP?
No. It attempts one TCP connection only. UDP has no equivalent connection handshake and is not checked here.
Does the endpoint keep my address?
The server uses the request source address for the connection attempt and does not save the result or address; standard hosting logs may apply.
More free tools: IP lookup · Blacklist check · WebRTC test · Speed test