Exposure and discovery
Exposed services checker
See whether a domain's servers accept connections on ports that should rarely be open to the internet: databases, remote desktop, Windows file sharing, the Docker API, and plaintext services such as Telnet and FTP. Exposed databases and remote desktop are frequent targets of automated attacks.
Run this check on a domain you have verified
Looking for exposed services means opening connections to ports on your servers, so Ironfang runs it only after you prove you control the domain (a DNS TXT record) and confirm you are authorised to assess it. It is part of the free External Security Check: create an account, add the domain, verify it and run the check.
The 21 ports it tries
- FTP21
- SSH22
- Telnet23
- HTTP80
- HTTPS443
- SMB445
- Microsoft SQL Server1433
- Oracle Database1521
- Docker API2375
- MySQL / MariaDB3306
- Remote Desktop (RDP)3389
- PostgreSQL5432
- VNC5900
- CouchDB5984
- Redis6379
- HTTP (alternate)8080
- HTTPS (alternate)8443
- Cassandra9042
- Elasticsearch9200
- Memcached11211
- MongoDB27017
What this checks
- One TCP connection attempt to each of 21 fixed ports, listed above, on the domain's public addresses.
- Databases: SQL Server (1433), Oracle (1521), MySQL and MariaDB (3306), PostgreSQL (5432), CouchDB (5984), Redis (6379), Cassandra (9042), Elasticsearch (9200), Memcached (11211) and MongoDB (27017).
- Remote access and file sharing: SSH (22), Remote Desktop (3389), VNC (5900) and SMB (445).
- Plaintext and container services: FTP (21), Telnet (23) and the unencrypted Docker API (2375).
- Web ports: 80 and 443, which a website is expected to answer on, and the alternate ports 8080 and 8443.
- Nothing is sent to any port. Each connection is opened and closed, and a greeting is read only from services that speak first: FTP, SSH, MySQL and VNC.
What the result means
A service that accepts connections from the internet can be reached by anyone, including the automated scanners that sweep address ranges for open databases and remote desktop logins. For many sites only the web ports need to be public; the rest should be reachable only from known networks, a VPN or a bastion host.
A finding means a port accepted a TCP connection from the scanner. It does not mean the service accepts logins or has a known flaw. It means the service is reachable, and so open to password guessing and to any vulnerability found in it later.
Databases, SMB, the Docker API and plaintext services are raised as High, remote desktop as Medium. SSH and extra web ports are informational, because they are often public on purpose; review them rather than close them by reflex.
How to fix common issues
Database port reachable from the internet
Close the port to the internet with a firewall or security group, and reach the database over a private network, VPN or bastion instead. If it must be public, restrict it to known source addresses.
Remote desktop port reachable from the internet
Put remote desktop behind a VPN or a gateway with multi-factor authentication, and close the port to the internet.
Windows file sharing reachable from the internet
Block port 445 at your firewall. Use a VPN or a cloud file service for remote access to files.
Container API port reachable from the internet
Close port 2375 to the internet immediately. If remote access is needed, use the TLS-protected port with client certificates, behind a firewall.
Unencrypted remote service reachable
Replace Telnet with SSH and FTP with SFTP or FTPS, and close the old ports.
SSH reachable from the internet
Review whether SSH needs to be public. If so, disable password logins (PasswordAuthentication no), keep OpenSSH updated, and consider restricting source addresses.
Web service on a non-standard port
Check what is running on the port. Close it if it is not meant to be public, or make sure it is patched and protected.
Cyber Essentials and ISO 27001
The firewalls theme of Cyber Essentials is about controlling which services in scope can be reached from the internet, and a list of reachable ports is technical evidence for it. In ISO/IEC 27001:2022 the same evidence supports Annex A 8.20 Networks security and 8.21 Security of network services.
The check shows what is reachable, not the rules behind it. The organisation still has to decide which services may be public, record who approved each inbound rule and why, and review the rules so that ones no longer needed are removed.
Scope and limitations
- It tries only the 21 listed ports. A service on any other port is not seen.
- Addresses in Cloudflare's proxy network are skipped, because an open port there belongs to Cloudflare and says nothing about your origin server. The origin behind them is not looked for or tested.
- It sees what is reachable from the scanner's address. A firewall rule that admits only certain source addresses can hide a port that others can still reach.
- It does not log in, send requests, try passwords or look for vulnerabilities in the services it finds. It is an automated external check, not a penetration test.
Related guides
Questions
- Why can I not check any domain for open ports?
- Because the check connects to the domain's servers. Ironfang runs it only for a domain whose DNS you control, proven with a TXT record, and after you confirm you are authorised to assess it. None of the free tools on this site scans ports.
- Is an open SSH port a problem?
- Not in itself, so it is reported as informational. Use key-based logins only, keep OpenSSH updated, and limit it to known source addresses where you can.
- What traffic does the check send?
- One TCP connection attempt to each listed port, paced per address, from Ironfang Security's published scanner address. Nothing is sent over the connection, and a greeting is read only from services that speak first.
- My site is behind Cloudflare. Is my origin server checked?
- No. Cloudflare addresses are skipped, because an open port there is Cloudflare's, not yours. An origin server's ports are checked only when the domain resolves to its address directly.
Related security tools
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.
- Technology detector - See the web server, CDN and frameworks a site's home page discloses.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- End-of-life software checker - See whether a site advertises software versions that no longer receive security fixes.

