Skip to content
Oh Dear

Ports you didn't open

Port scanning.

A firewall change opens port 3306, and the homepage still returns 200. Oh Dear scans all 65,535 TCP ports on your server once a day, and tells you when what's open doesn't match the list of ports you expect.

10-day free trial · No credit card required · Every feature included

All 65,535 TCP ports Scanned once a day
  • Bitmovin
  • HBO Nordic
  • Obsidian
  • Laravel
  • Fathom Analytics
  • PHP 8
  • Stanford University
  • Takeaway.com
  • IGN
  • VRT NWS
  • spatie

Two different questions

Up doesn't mean closed.

Uptime monitoring asks whether your server answers. Port scanning asks what else answers. One can pass while the other fails, on the same machine, on the same day.

One server, two verdicts Illustrative

The uptime check sees

Homepage
200 OK
Server
Answers
Verdict
Up

The port scan sees

Ports 80, 443
Open, as listed
Port 3306
Open, not listed
Verdict
Unexpected open port

Want one port checked every minute instead? That's TCP port monitoring, the neighboring check.

How ports open

Nobody opens these ports on purpose.

Nobody plans these. The site stays up through every one of them, so an uptime check never notices.

Cache 6379

Redis, reachable from the internet.

A Redis instance meant for internal use ends up public. It was never on your list, so the scan reports it.

Port 6379 open, not on your list
Database 3306 · 5432 · 27017

A database port, opened by a firewall change.

A rule edit or a migration puts MySQL, PostgreSQL, or MongoDB on the public internet. Nothing on the site looks different.

Port 3306 open, not on your list
Deploy leftover High port

A debug service, left running.

A staging tool stays up on a random high port after the deploy ships. You never listed it, so the scan flags it.

Port 9229 open, not on your list
Remote access 22

SSH where only the web should be.

A server that should answer on 80 and 443 also answers on 22. The scan compares what answers against what you listed.

Port 22 open, not on your list

How the list works

List what's allowed. The scan reports the rest.

There's no second list of ports to keep closed. Anything open that you didn't list is the finding.

Four steps, then a daily scan.

  1. List Pick the ports that should be open, from a list of common ones or by number. New monitors start with 80 and 443. A mail server usually adds 25, 587, and 993.
  2. Review The first scan never alerts. It shows every open port it found as "to review", and one click marks a port as expected.
  3. Scan Once a day, Oh Dear scans all 65,535 TCP ports and compares what's open against your list.
  4. Alert A listed port that's closed, or an unlisted port that's open, fails the check. By default you hear about it after the first failed scan.
Brandon Tanaka
Oh Dear has helped us get ahead of outages instead of hearing about it from customers.

Brandon Tanaka, Director of Engineering at Integrated Rental Systems

Said about Oh Dear in general. A port finding reaches you on the same channels as every other alert.

Where this check ends

What the scan sees, and what it doesn't.

Port scanning answers one question: which TCP ports on this server accept a connection from the internet? Everything past that belongs to a different check.

What it checks

  • All 65,535 TCP ports on the public IPv4 address of a Server monitor.
  • Ports on your list that are closed.
  • Ports that are open but not on your list.
  • The banner or product and version a service sends, for the 25 lowest open ports.
  • The moment everything is back to what you listed.

What it does not

  • UDP ports and IPv6 addresses.
  • Website monitors. Port scanning runs on Server monitors.
  • One port checked every minute: TCP port monitoring.
  • Whether the server answers at all: ping monitoring.
  • Testing what someone could do with an open port. That's a penetration test.

If the hostname resolves to a Cloudflare address, Oh Dear skips the scan, because it would only see Cloudflare's edge. Set the origin IP address on the monitor and it scans your server instead.

Operational ownership

Each finding goes to the owner of that server.

A closed mail port on client A isn't the same incident as an open database on client B. Each Server monitor keeps its own list, and each finding goes to the people responsible for that box, on the channels they already use.

Rather wait for a second scan before anyone is paged? Raise the number of failed scans in a row in that monitor's notification settings.

Slack
Email
Webhook
Explore notifications and routing

No feature tiers

Every check.
Every plan.

Port scanning is included on every plan. You pay for the number of things you monitor, not per check.

Start with everything on.

Try the daily port scan alongside uptime, DNS, domain, and the rest of the website-health toolkit.


  • Port scanning on every plan
  • Every monitoring feature included
  • Plans scale by monitored site count
  • No credit card required
Start a free trial

10-day free trial. No credit card.

For the technically curious

How the port scan actually works.

You give Oh Dear a server and a list of ports. Once a day it scans the server from outside your network and compares the result with your list.

  • The scan. A TCP SYN scan of all 65,535 ports. A port counts as open when it accepts the connection. Closed, filtered, and silent ports all count as not open.
  • The address. The monitor's hostname, resolved to one IPv4 address, or the origin IP address you set on the monitor. Private and reserved addresses are never scanned.
  • Where from. One scanner per continent: Frankfurt for Europe, New York for North America, and Singapore for Asia. You pick the continent per monitor. It starts with the continent of your uptime check location.
  • Cadence. Once a day by default. You can space scans further apart in the monitor's settings. They never run more than once a day.
  • Services. For the 25 lowest open ports, the report shows the banner or the product and version the service sent, when it sent one.
  • Before you are alerted. One failed scan by default. Raise it to wait for up to 20 failed scans in a row. The first scan on a new monitor never alerts.
  • Recovery. When every port is back to what you listed, you get a recovery notification.
  • History and API. A new history entry is stored whenever the findings change, with the open ports and the issues found. The same history is available through the API.
  • Published addresses. The scanner addresses are listed at /used-ips, in JSON and CSV as well as HTML, so you can recognize them in your logs.

Want all the technical details?

Before the first check

Questions about port scanning.

What the scan sees, how often it runs, and where this check ends.

What is port scanning in Oh Dear?

An outside-in check of what your server exposes. Oh Dear runs a TCP SYN scan of all 65,535 ports on a Server monitor, compares the open ports against the list you gave it, and fails the check when a listed port is closed or an unlisted port is open.

How do I audit which ports are open on my server?

Add the server as a Server monitor and turn on port scanning. The first scan lists every open port it finds, so you can mark the ones you expect. From then on, every scan is compared against that list.

How often does Oh Dear scan my ports?

Once a day by default. You can space scans further apart in the monitor's settings, but they never run more than once a day. A full scan of every port is heavier than a single-port check, which is why it runs less often.

How is this different from TCP port monitoring?

TCP port monitoring connects to one port you name, every minute by default, and tells you whether it answers. Port scanning sweeps all 65,535 TCP ports once a day and tells you what differs from your list. Use the first to know a service is up. Use the second to know nothing unexpected is open.

Will Oh Dear alert me when my open ports change?

Yes. You get a notification when a port on your list is closed, when a port that is not on your list is open, and again when everything is back to what you listed. By default the alert goes out after the first failed scan. You can ask for up to 20 failed scans in a row before you hear about it.

Does the first scan send an alert?

No. Before the first scan Oh Dear does not know which open ports you expect, so every port would look unexpected. The first scan marks each open port as "to review", and one click marks it as expected. Alerts start from the next scan.

What does it mean if a new open port is detected?

Something on your server now accepts connections from the internet that did not before. Often that is you: a new service or a deploy. It can also be a firewall change that exposed a database, or a service that was meant to stay internal. Either way, it is worth a look. If the port is fine, add it to your list and the check goes green.

Which ports should be open on my server?

As few as possible. A typical web server needs 80 and 443, plus SSH if you manage it over the internet. Databases, caches, and admin panels should rarely face the internet directly. Oh Dear shows you what is open, so you can close what should not be.

Why is port scanning only on Server monitors?

Websites often sit behind a CDN or a load balancer, so a scan would report the edge, not your server. On a Server monitor, the address scanned is the server itself. If a hostname resolves to Cloudflare, Oh Dear skips the scan. Set the origin IP address on the monitor and it scans that instead.

Does Oh Dear scan UDP ports or IPv6?

No. The scan covers TCP ports on one public IPv4 address. UDP ports and IPv6 addresses are not scanned.

Do I need to allow Oh Dear through my firewall?

No, and for this check you usually should not. The point is to see what the rest of the internet sees. If you allow the scanner through, it reports ports that are only open to Oh Dear. The scanner addresses are published at /used-ips so you can recognize them in your logs.

Does this replace a penetration test?

No. A penetration test looks for weaknesses you can exploit, at one point in time. Port scanning watches every day for the difference between the ports you expect and the ports that answer. It tells you a port is open. It does not test what someone could do with it.

Is port scanning included on every plan?

Yes. Every feature is on every plan, and you can try it during the 10-day free trial without a credit card.

See all other FAQ items

Get started

Know about the open port before anyone else does.

Add a server and list the ports that should be open. Every feature on. No credit card.