Redis, reachable from the internet.
A Redis instance meant for internal use ends up public. It was never on your list, so the scan reports it.
Ports you didn't open
A firewall change opens port 3306, and the homepage still returns 200. Oh Dear scans all 65,535 TCP ports on your server once a day, and tells you when what's open doesn't match the list of ports you expect.
10-day free trial · No credit card required · Every feature included
Two different questions
Uptime monitoring asks whether your server answers. Port scanning asks what else answers. One can pass while the other fails, on the same machine, on the same day.
The uptime check sees
The port scan sees
Want one port checked every minute instead? That's TCP port monitoring, the neighboring check.
How ports open
Nobody plans these. The site stays up through every one of them, so an uptime check never notices.
A Redis instance meant for internal use ends up public. It was never on your list, so the scan reports it.
A rule edit or a migration puts MySQL, PostgreSQL, or MongoDB on the public internet. Nothing on the site looks different.
A staging tool stays up on a random high port after the deploy ships. You never listed it, so the scan flags it.
A server that should answer on 80 and 443 also answers on 22. The scan compares what answers against what you listed.
How the list works
There's no second list of ports to keep closed. Anything open that you didn't list is the finding.
Oh Dear has helped us get ahead of outages instead of hearing about it from customers.
Brandon Tanaka, Director of Engineering at Integrated Rental Systems
Said about Oh Dear in general. A port finding reaches you on the same channels as every other alert.
Where this check ends
Port scanning answers one question: which TCP ports on this server accept a connection from the internet? Everything past that belongs to a different check.
If the hostname resolves to a Cloudflare address, Oh Dear skips the scan, because it would only see Cloudflare's edge. Set the origin IP address on the monitor and it scans your server instead.
Operational ownership
A closed mail port on client A isn't the same incident as an open database on client B. Each Server monitor keeps its own list, and each finding goes to the people responsible for that box, on the channels they already use.
Rather wait for a second scan before anyone is paged? Raise the number of failed scans in a row in that monitor's notification settings.
No feature tiers
Port scanning is included on every plan. You pay for the number of things you monitor, not per check.
Try the daily port scan alongside uptime, DNS, domain, and the rest of the website-health toolkit.
10-day free trial. No credit card.
For the technically curious
You give Oh Dear a server and a list of ports. Once a day it scans the server from outside your network and compares the result with your list.
Want all the technical details?
Before the first check
What the scan sees, how often it runs, and where this check ends.
An outside-in check of what your server exposes. Oh Dear runs a TCP SYN scan of all 65,535 ports on a Server monitor, compares the open ports against the list you gave it, and fails the check when a listed port is closed or an unlisted port is open.
Add the server as a Server monitor and turn on port scanning. The first scan lists every open port it finds, so you can mark the ones you expect. From then on, every scan is compared against that list.
Once a day by default. You can space scans further apart in the monitor's settings, but they never run more than once a day. A full scan of every port is heavier than a single-port check, which is why it runs less often.
TCP port monitoring connects to one port you name, every minute by default, and tells you whether it answers. Port scanning sweeps all 65,535 TCP ports once a day and tells you what differs from your list. Use the first to know a service is up. Use the second to know nothing unexpected is open.
Yes. You get a notification when a port on your list is closed, when a port that is not on your list is open, and again when everything is back to what you listed. By default the alert goes out after the first failed scan. You can ask for up to 20 failed scans in a row before you hear about it.
No. Before the first scan Oh Dear does not know which open ports you expect, so every port would look unexpected. The first scan marks each open port as "to review", and one click marks it as expected. Alerts start from the next scan.
Something on your server now accepts connections from the internet that did not before. Often that is you: a new service or a deploy. It can also be a firewall change that exposed a database, or a service that was meant to stay internal. Either way, it is worth a look. If the port is fine, add it to your list and the check goes green.
As few as possible. A typical web server needs 80 and 443, plus SSH if you manage it over the internet. Databases, caches, and admin panels should rarely face the internet directly. Oh Dear shows you what is open, so you can close what should not be.
Websites often sit behind a CDN or a load balancer, so a scan would report the edge, not your server. On a Server monitor, the address scanned is the server itself. If a hostname resolves to Cloudflare, Oh Dear skips the scan. Set the origin IP address on the monitor and it scans that instead.
No. The scan covers TCP ports on one public IPv4 address. UDP ports and IPv6 addresses are not scanned.
No, and for this check you usually should not. The point is to see what the rest of the internet sees. If you allow the scanner through, it reports ports that are only open to Oh Dear. The scanner addresses are published at /used-ips so you can recognize them in your logs.
No. A penetration test looks for weaknesses you can exploit, at one point in time. Port scanning watches every day for the difference between the ports you expect and the ports that answer. It tells you a port is open. It does not test what someone could do with it.
Yes. Every feature is on every plan, and you can try it during the 10-day free trial without a credit card.
Get started
Add a server and list the ports that should be open. Every feature on. No credit card.