About the Home Network Exposure Check
Your router is the front door of every device in the house, and it has 65,535 doorways. This check stands outside and knocks on the ones that should never answer at home: Remote Desktop, Telnet, Windows file sharing, camera streams, NAS admin pages, the router’s own admin page, the ISP management port and more — 20 in the free scan, 92 in the extended one. Automated scanners sweep the entire IPv4 internet in under an hour, so anything open here has already been found by someone.
Each door comes back open (something accepted the connection), closed (your router refused) or stealth (nothing answered). Open ones are explained in plain words with the setting that usually caused them — UPnP, a device’s remote-access feature, or router remote management — and how to turn it off.
The scan tests only the address your browser connected from. Nothing you type can point it anywhere else. It opens connections and reads the greeting a service offers; it never sends passwords or exploits. Limits, stated plainly: UDP is not tested, this site is reachable over IPv4 only, and behind carrier-grade NAT or a VPN the scan reaches your ISP or VPN, not your house — the page tells you which.
…Scans the address above and nothing else. On a work, school or café network that is their connection — only scan a network you are responsible for.
Open your router’s status page (often 192.168.0.1, 192.168.1.1 or 10.0.0.1) and find its WAN or Internet IP. Type it here — it is compared in your browser and never sent anywhere.
Pick your router or ISP gateway for the exact menus, taken from each maker’s own support pages (checked 2026-09-27).
A one-page report of this scan with every open port, its risk and the fix — for a landlord, an ISP support call, or the family member who set up the router.
Each scan is snapshotted in this browser only. Scan again next week and any door that opened or closed is shown here.
How to Use the Home Network Exposure Check
Run it from a device on your home Wi-Fi or wired network, with any VPN switched off — otherwise you are testing the VPN. Check that the address shown matches what you expect, press Scan my connection, and wait a few seconds while our server attempts a connection to each port, ten per second. Anything marked open is reachable by every computer on the internet. Fix what you find, wait five minutes (scans are limited to one per address every five minutes) and run it again to confirm.
Open, Closed and Stealth, Precisely
A TCP connection starts with a three-message handshake. The scanner sends the first message and waits up to two seconds. If a device replies to continue the handshake, the port is open: a program is listening and will talk to anyone. If the reply is a reset, the port is closed: the router or a device is there but nothing listens on that port. If nothing comes back, or a firewall sends an “unreachable” notice instead, the port is stealth. Home routers ship in stealth mode for most ports, which is why a clean result usually shows a wall of stealth rather than a wall of closed.
Our classification was tested before launch against an independent implementation on the same server: 88 of 88 port results agreed across four targets with known answers — our own server, its IPv6 address, a public test service that answers on every port, and a reserved address where nothing can answer.
The Ports That Matter Most
| Port | What it is | Why it is dangerous when open |
|---|---|---|
| 3389 | Remote Desktop | One of the most brute-forced services online; a leading ransomware entry point |
| 445 | Windows file sharing (SMB) | How WannaCry spread in 2017 |
| 23 | Telnet | How Mirai built a botnet of cameras and routers from factory passwords |
| 7547 | TR-069 ISP management | A flaw here knocked about 900,000 Deutsche Telekom routers offline in 2016 |
| 80 / 8080 / 443 / 8443 | Router or device web admin | Remote management turned on, or a camera or NAS published to the world |
| 554 | Camera video (RTSP) | Many cameras stream without a password |
| 5900 | VNC screen sharing | Full control of a desktop, often with a weak password |
Why Ports Open Themselves: UPnP
Universal Plug and Play lets any program on your network ask the router to forward a port to it, with no password and no prompt. Games consoles and video-calling apps use it to make connections work; so do cheap cameras, and so does malware. Most consumer routers ship with UPnP on. If this scan finds a port you never opened, UPnP is the first suspect. Turning it off can break online gaming (you may see a “strict NAT” warning), in which case forward the console’s specific ports by hand instead — a deliberate, visible rule beats an invisible automatic one.
Carrier-Grade NAT, VPNs and IPv6
- Carrier-grade NAT (CGNAT) gives your router an address in
100.64.0.0/10, shared behind one public address with many other customers. Inbound connections cannot reach you at all — protective, but it also means this scan tests your ISP’s equipment. Mobile broadband, many fixed-wireless and satellite services, and some fibre providers use it. - Double NAT — an ISP gateway in front of your own router — shows up as a
private WAN address (
192.168.x.x,10.x.x.x) on your router. The scan reaches the ISP box; your own router’s settings are behind it. - VPN: the scan tests the VPN provider’s server. Turn the VPN off to test home.
- IPv6 has no NAT: each device may have its own globally reachable address, protected only by the router’s IPv6 firewall. This site is IPv4-only, so that path is not tested here.
After a Clean Result
Stealth across the board is the goal, but it only describes this moment. A new camera with UPnP can open a port tonight. Re-scan after adding any smart device, after a router firmware update, and whenever you change ISP equipment. The Router & Home Network Hardening Scorecard covers the settings a scan cannot see — default passwords, WPS, firmware age and known vulnerabilities in your exact model — and the Two-Factor Authentication Planner protects the cloud accounts that most “remote access” features rely on. Browse every Security & Privacy tool for more.
Frequently Asked Questions
Is it legal to port scan my own IP address?
Checking a connection you are responsible for is standard practice and is what router makers and ISPs themselves recommend. This tool only ever tests the address your own browser connected from, and it only opens a connection and reads the greeting a service volunteers. If you are on someone else's network, such as work, a school or a café, you would be testing their connection, so ask first.
What is the difference between an open, closed and stealth port?
Open means a device accepted the connection: a service is listening and reachable from anywhere. Closed means your router or device answered with a refusal, so something exists at the address but nothing is listening on that port. Stealth, also called filtered, means nothing answered at all within two seconds; to a scanner the port looks like empty space, which is the best result.
Why would a port be open on my home network if I never opened it?
The usual culprits are UPnP, which lets any device on your network ask the router to open a port without asking you; a remote-access or cloud feature on a camera, NAS or game console; router remote management switched on; or an old port-forward rule someone set up years ago. ISP-supplied gateways may also leave port 7547 open for the provider's own management.
Does this scan work if I am behind carrier-grade NAT or a VPN?
Not in the way you want. With carrier-grade NAT, common on mobile and some fibre and satellite services, your router has a private 100.64.x.x address and hundreds of customers share the public one, so the scan tests the ISP gateway rather than your home. With a VPN on, it tests the VPN server. Compare the address shown here with the WAN address on your router status page to know which case you are in.
Why is UDP not tested, and why does IPv6 matter?
A TCP port answers a connection attempt; UDP usually stays silent whether it is open or not, so an outside UDP check produces unreliable results and is not offered. Separately, this site is reachable only over IPv4, so it tests your IPv4 address. If your ISP provides IPv6, each device can have its own public address with no NAT in front, and your router's IPv6 firewall is what protects it.