Skip to content

Exposure and discovery

Exposed services checker

See whether a domain's servers accept connections on ports that should rarely be open to the internet: databases, remote desktop, Windows file sharing, the Docker API, and plaintext services such as Telnet and FTP. Exposed databases and remote desktop are frequent targets of automated attacks.

Run this check on a domain you have verified

Looking for exposed services means opening connections to ports on your servers, so Ironfang runs it only after you prove you control the domain (a DNS TXT record) and confirm you are authorised to assess it. It is part of the free External Security Check: create an account, add the domain, verify it and run the check.

The 21 ports it tries
  • FTP21
  • SSH22
  • Telnet23
  • HTTP80
  • HTTPS443
  • SMB445
  • Microsoft SQL Server1433
  • Oracle Database1521
  • Docker API2375
  • MySQL / MariaDB3306
  • Remote Desktop (RDP)3389
  • PostgreSQL5432
  • VNC5900
  • CouchDB5984
  • Redis6379
  • HTTP (alternate)8080
  • HTTPS (alternate)8443
  • Cassandra9042
  • Elasticsearch9200
  • Memcached11211
  • MongoDB27017

What this checks

What the result means

A service that accepts connections from the internet can be reached by anyone, including the automated scanners that sweep address ranges for open databases and remote desktop logins. For many sites only the web ports need to be public; the rest should be reachable only from known networks, a VPN or a bastion host.

A finding means a port accepted a TCP connection from the scanner. It does not mean the service accepts logins or has a known flaw. It means the service is reachable, and so open to password guessing and to any vulnerability found in it later.

Databases, SMB, the Docker API and plaintext services are raised as High, remote desktop as Medium. SSH and extra web ports are informational, because they are often public on purpose; review them rather than close them by reflex.

How to fix common issues

Database port reachable from the internet

Close the port to the internet with a firewall or security group, and reach the database over a private network, VPN or bastion instead. If it must be public, restrict it to known source addresses.

More in the Database ports check reference

Remote desktop port reachable from the internet

Put remote desktop behind a VPN or a gateway with multi-factor authentication, and close the port to the internet.

More in the Remote desktop ports check reference

Windows file sharing reachable from the internet

Block port 445 at your firewall. Use a VPN or a cloud file service for remote access to files.

More in the File sharing check reference

Container API port reachable from the internet

Close port 2375 to the internet immediately. If remote access is needed, use the TLS-protected port with client certificates, behind a firewall.

More in the Container APIs check reference

Unencrypted remote service reachable

Replace Telnet with SSH and FTP with SFTP or FTPS, and close the old ports.

More in the Plaintext services check reference

SSH reachable from the internet

Review whether SSH needs to be public. If so, disable password logins (PasswordAuthentication no), keep OpenSSH updated, and consider restricting source addresses.

More in the SSH check reference

Web service on a non-standard port

Check what is running on the port. Close it if it is not meant to be public, or make sure it is patched and protected.

More in the Additional web services check reference

Cyber Essentials and ISO 27001

The firewalls theme of Cyber Essentials is about controlling which services in scope can be reached from the internet, and a list of reachable ports is technical evidence for it. In ISO/IEC 27001:2022 the same evidence supports Annex A 8.20 Networks security and 8.21 Security of network services.

The check shows what is reachable, not the rules behind it. The organisation still has to decide which services may be public, record who approved each inbound rule and why, and review the rules so that ones no longer needed are removed.

Scope and limitations

Related guides

Questions

Why can I not check any domain for open ports?
Because the check connects to the domain's servers. Ironfang runs it only for a domain whose DNS you control, proven with a TXT record, and after you confirm you are authorised to assess it. None of the free tools on this site scans ports.
Is an open SSH port a problem?
Not in itself, so it is reported as informational. Use key-based logins only, keep OpenSSH updated, and limit it to known source addresses where you can.
What traffic does the check send?
One TCP connection attempt to each listed port, paced per address, from Ironfang Security's published scanner address. Nothing is sent over the connection, and a greeting is read only from services that speak first.
My site is behind Cloudflare. Is my origin server checked?
No. Cloudflare addresses are skipped, because an open port there is Cloudflare's, not yours. An origin server's ports are checked only when the domain resolves to its address directly.

Related security tools