◈ netchecks.org

17 فحصًا · بدون حساب · مُستضاف ذاتيًا

اختبر شبكتك بنقرة واحدة

17 أداة تشخيص شبكة مجانية في لوحة تحكم واحدة.

الأسئلة الشائعة

0 أدوات تتبع · 14 لغة · وضع داكن وفاتح · مُستضاف ذاتيًا

← جميع المقالات

Practical guide

Why These Tools Exist: Reading Results, Judging Warnings, and When You Actually Need a VPN

Run a port scan, a header inspector, or a blacklist check against almost any real target and you'll get back a wall of technical detail: open ports, header names, certificate fields, list after list. None of it comes with a verdict attached. A result on its own doesn't tell you whether you're looking at something completely normal or something that needs fixing tonight - that judgment call is a separate skill from running the tool, and it's the one piece most diagnostic sites never actually teach.

This article is that missing layer. It won't turn anyone into a penetration tester, and it's not a substitute for a proper security audit on anything that actually matters - but it covers what each tool in this kit is really answering, how to read a result without swinging between panic and complacency, which warnings deserve a same-day fix versus a shrug, concrete examples of open ports that are fine versus open ports that are a real problem, and when reaching for a VPN is the right move instead of just another thing to configure.

What each tool is actually answering

It helps to sort the sixteen tools in this kit into four questions, because the right way to read a result depends entirely on which question it's answering. Ping and Traceroute answer "can I reach it, and if not, where does the path break" - pure connectivity, nothing about security. DNS Lookup, Whois, and GeoIP answer "who is this, and where does it actually live" - identity and ownership, useful for verifying a target is what it claims to be before trusting it. Port Scan, HTTP Headers, SSL Checker, and Blacklist Check answer "what does this system expose to the outside world, and should it" - this is the group that actually touches security, and the one this article spends the most time on. Subnet Calculator, Speed Test, and the two dictionary lookups answer "how much, or how big" - pure capacity and reference information, no risk judgment involved at all.

Knowing which bucket a tool sits in changes how you should react to its output. A Traceroute showing a hop that times out isn't a security finding - it's usually a router configured to ignore ICMP, completely unrelated to whether anything is actually wrong. A Port Scan showing an open port, on the other hand, is exactly the kind of result that deserves the rest of this article's attention, because it's telling you something real about what's reachable from outside.

Reading a result without over- or under-reacting

The single most useful habit when reading any of these tools' output is comparing the result against what you actually intended to be there - not against some imagined ideal of a perfectly locked-down system, which doesn't exist and isn't the goal. A web server with ports 80 and 443 open is not a finding; it's the entire point of running a web server. The question that actually matters is always "does this match what I meant to expose", not "is anything at all open or configured".

Most of what these tools surface is informational rather than alarming: a missing optional security header, a slightly older TLS cipher still offered alongside modern ones for compatibility, a WHOIS record with privacy redaction enabled - none of these are emergencies, and treating every line of output as equally urgent is how real warnings end up ignored along with the noise. The useful skill is triage: read the whole result once, mentally sort each line into "expected", "worth a closer look", or "reachable from the internet and shouldn't be", and only act urgently on that last category.

Is a warning actually serious? A field guide

A few of the most common warnings, and roughly how urgently each one actually deserves attention. A missing security header (Content-Security-Policy, Strict-Transport-Security) is real but rarely urgent on its own - it's a hardening gap, worth fixing on the next maintenance window, not a five-alarm fire, since it needs to be combined with another vulnerability to actually be exploited. An expired or soon-to-expire TLS certificate is genuinely urgent - it breaks trust for every visitor the moment it lapses, with no gradual warning to end users, so this is one to fix before it happens, not after. A blacklist listing is urgent specifically if the affected system sends email - mail silently stops arriving at major providers within hours, and the fix (identifying and removing the cause, then requesting delisting) can take days, so this is worth checking proactively rather than waiting for a client to notice their emails aren't landing.

An open port is the one that depends most entirely on context, which is exactly why it gets its own section below with concrete examples rather than a single blanket rule. The short version: the same open port can be completely fine on one system and a serious problem on another, purely based on which service it is and who's supposed to be able to reach it.

Open ports: what's normal and what's a real risk

Three rough categories cover almost every real-world case. Ports meant to be public - 443 (HTTPS) and 80 (HTTP) on anything hosting a website - being open is not a finding at all; it's the service working as designed, and a scan confirming they're reachable is exactly what should happen. Administrative ports - 22 (SSH) and 3389 (RDP) are the two seen most often - are fine to have open specifically to the people who need them, but worth reviewing if a scan shows them reachable from the entire internet rather than from a known, restricted set of addresses; the fix here isn't necessarily to close them, it's to restrict who can reach them (a firewall allowlist, key-only SSH authentication with password login disabled, or moving access behind a VPN entirely, covered below). Database and internal-service ports - 3306 (MySQL), 5432 (PostgreSQL), 27017 (MongoDB), and legacy protocols like 23 (Telnet) with no encryption at all - being reachable from the public internet is almost never intentional and almost always a real problem; these are designed to be talked to by an application server sitting next to them on the same private network, not queried directly by anyone on the internet, and a surprising number of real data breaches trace back to exactly this: a database left with its default port open to the world, often because a cloud security group or a home router's port-forwarding rule was set up carelessly and never revisited.

How this actually happens in practice is almost always mundane rather than malicious: a router's UPnP feature auto-opens a port for one application and never closes it again after that device is gone; a cloud security group gets set to "anywhere" during testing because it's faster than configuring the right IP range, and the ticket to fix it later never gets filed; a database gets spun up for a quick prototype with default credentials and default network settings, and the prototype quietly becomes the production system six months later. None of this requires an attacker doing anything clever - it just requires nobody double-checking what's actually reachable, which is precisely the gap a port scan is built to close.

The same scan finding - an open port - lands in a different risk bucket purely based on which port it is and who's supposed to reach it.

When you actually need a VPN (and when you don't)

A VPN is the right tool specifically for one recurring problem: you (or a small, known group of people) need to reach something - an admin panel, an SSH server, an internal dashboard - from outside its own network, without making it reachable by everyone else on the internet too. Rather than port-forwarding SSH or RDP directly to the world and then trying to lock it down with firewall rules and fail2ban, putting it behind a VPN removes it from the public internet's view entirely: nobody can even attempt to connect unless they've already authenticated onto the VPN first, which collapses most of the open-port risk described above before a single login attempt happens. Modern options like WireGuard (covered in "The Rise of the VPN" article on this blog) make this genuinely easy to set up, with a fraction of the configuration and attack surface of older protocols like PPTP or IPsec.

A VPN is equally the right call whenever a device is regularly used on untrusted networks - a coffee shop, a conference, an airport - where anyone else on the same WiFi can potentially observe or intercept unencrypted traffic; routing that traffic through a VPN removes the local network as a point of interception, which is a real and common threat, not a theoretical one. It's also the standard way to connect two private networks together, for example a small business's office and its cloud servers, without exposing either one directly to the internet in between.

Where a VPN is not the fix: a genuinely misconfigured public-facing service - a database with no authentication reachable from anywhere, a web application with a real vulnerability - doesn't get safer by also running a VPN somewhere else on the network. Wrapping a broken lock in another door doesn't fix the lock; the actual exposure needs to be closed at the source (authentication enabled, the port removed from public reach, the vulnerability patched), and a VPN's job is specifically for controlling who can reach something that's intentionally not meant to be fully public - not for papering over something that's leaking regardless.

خلاصة

The practical version of everything above: run the relevant tool, compare what it shows against what you actually intended to expose, and treat "reachable from the entire internet, and it shouldn't be" as the one signal worth acting on urgently - everything else is triage, not panic. For anything that genuinely only a specific person or a small team should reach, a VPN removes it from the public internet's view entirely rather than trying to defend a door that's standing wide open; for everything else, the fix is almost always tightening what's already there rather than adding another layer on top of it.

← جميع المقالات

التحقق من عنوان IP الخاص بي

عنوان IP العام الخاص بك وموقع شبكتك، يتم اكتشافهما تلقائيًا.

يتم التحميل تلقائيًا عند فتح NetChecks — لا حاجة لإدخال أي شيء. استخدم زر التحديث بعد تغيير الشبكة أو إعادة الاتصال بالشبكة الافتراضية الخاصة (VPN).

متصفحك

فحص شامل بخطوة واحدة

يشغّل جميع الفحوصات ذات الصلة على عنوان IP أو اسم مضيف واحد دفعة واحدة: DNS، whois، ping، traceroute، فحص للمنافذ المعروفة (1-1024)، رؤوس HTTP وشهادة SSL.

أدخل نطاقًا أو عنوان IP وشغّله للتحقق من DNS وwhois وping وtraceroute والمنافذ الشائعة ورؤوس HTTP وشهادة SSL دفعة واحدة.

تعمل معظم الفحوصات بالتوازي - وعادة ما تنتهي خلال حوالي 30 ثانية، وأكثر إذا كان الهدف بطيئًا أو غير قابل للوصول.

لا تعمل خطوة فحص المنافذ إلا بعد تحديد مربع الموافقة أعلاه - جميع الفحوصات الأخرى تعمل بغض النظر عن ذلك.

بينغ (Ping)

يرسل طلبات ICMP echo إلى مضيف للتحقق من إمكانية الوصول إليه وزمن الاستجابة.

أدخل اسم مضيف أو عنوان IP واضغط على Ping لإرسال طلبات ICMP echo وقياس زمن الاستجابة ذهابًا وإيابًا.

You Host ICMP Echo Request (type 8) ICMP Echo Reply (type 0) measures: RTT · TTL · packet loss

      

تعرف أكثر على بينغ (Ping)

ما هو

يرسل Ping حزم ICMP Echo Request إلى مضيف ويقيس الوقت الذي تستغرقه حزم ICMP Echo Reply للعودة. إنه أبسط اختبار اتصال شبكي موجود على الإطلاق: يجيب بالضبط عن سؤال واحد، "هل هذا الجهاز قابل للوصول، وبأي سرعة؟". صُمِّم بروتوكول ICMP (RFC 792) عام 1981 خصيصًا لنقل رسائل التحكم والتشخيص عبر شبكات IP، بمعزل عن أي حركة تطبيقات - وPing هو أشهر تطبيق له وأكثرها توفرًا عالميًا، موجود عمليًا في كل نظام تشغيل وجهاز شبكي منذ أقدم إصداراته.

كيف يعمل

تحمل كل حزمة ICMP حقل TTL (مدة البقاء) يُنقَص بواحد عند كل موجّه يعبره؛ فإذا وصل إلى الصفر قبل بلوغ الوجهة، تُسقَط الحزمة ويُرسَل خطأ إلى المرسل. يعكس زمن الذهاب والإياب (RTT) المُقاس بالميلي ثانية زمن الاستجابة التراكمي للشبكة على طول الرحلة كاملة، وليس فقط الجزء الأخير القريب من الوجهة - وهذه نقطة كثيرًا ما يُساء فهمها، إذ قد يكون السبب الحقيقي لنتيجة ping بطيئة في أي نقطة على المسار، وليس بالضرورة قرب الخادم المُختبَر. يُرسل ping عادة عدة حزم متتالية بدلًا من حزمة واحدة، مما يتيح التمييز بين ارتفاع مؤقت في زمن الاستجابة ومشكلة متكررة، وحساب معدل فقدان الحزم على العينة.

تفسير النتائج

زمن استجابة منخفض ومستقر - بضعة ميلي ثانية على شبكة محلية، من 10 إلى 50 مللي ثانية لوجهة داخل نفس الدولة، وأكثر بكثير لاتصال عبر القارات - يشير إلى اتصال سليم. حتى فقدان حزم بسيط (فوق 1-2%) ضار بشكل خاص للاستخدامات الحساسة لزمن الاستجابة مثل VoIP أو الجلسات التفاعلية عن بُعد، حيث تظهر كل حزمة مفقودة كخلل أو انقطاع مسموع. تباين كبير في زمن الاستجابة من حزمة إلى أخرى (jitter) غالبًا ما يكون، لهذه الاستخدامات نفسها، مشكلة أكبر من زمن استجابة مرتفع لكنه مستقر تمامًا. "انتهت مهلة الطلب" تعني عدم وصول أي رد خلال الوقت المحدد - قد يكون المضيف متوقفًا فعليًا، أو قد يحجب جدار حماية بروتوكول ICMP بصمت، أو قد يكون هناك مسار معطل في مكان ما على الطريق؛ أما "الوجهة غير قابلة للوصول" فهي مختلفة وأكثر إفادة: أرسل موجّه وسيط صراحة رسالة يفيد فيها بأنه لم يتمكن من إعادة توجيه الحزمة، مما يساعد في تحديد مكان المشكلة الفعلي بدقة أكبر.

الأخطاء الشائعة

أكثر خطأ تفسيري شيوعًا هو الاستنتاج بأن المضيف "متوقف" بمجرد فشل ping، بينما في الواقع تحجب خوادم وأجهزة كثيرة جدًا - خصوصًا خلف جدار حماية جيد الضبط، أو مستضافة لدى مزودي الخدمات السحابية الكبار - بروتوكول ICMP الوارد عمدًا كسياسة، وهي مع ذلك تعمل بشكل كامل وقابلة للوصول على خدماتها الفعلية (HTTP، قاعدة بيانات، إلخ). لذلك فإن غياب استجابة ping دليل معتبر على التوقف فقط عند اقترانه بمؤشرات أخرى، مثل عدم استجابة التطبيق نفسه أيضًا. وبالمقابل، لا يضمن نجاح ping إطلاقًا أن خدمة التطبيق المستضافة على ذلك الجهاز تعمل بشكل صحيح - فهاتان طبقتان مستقلتان تمامًا في مكدس الشبكة.

متى تستخدمه

أول ما يجب التحقق منه قبل تصعيد تذكرة: هل يستجيب الجهاز أصلًا، قبل التحقيق أكثر؟ تأكيد الاتصال بعد تغيير قاعدة جدار حماية أو جدول توجيه، للتأكد من أن التغيير لم يقطع الوصول. تحديد قياس أساسي لزمن الاستجابة قبل نشر VoIP أو تبديل احتياطي لخط مزود، لتوفير نقطة مقارنة موضوعية إذا وردت شكاوى عن جودة المكالمات لاحقًا. فحص حالة دوري وخفيف لمزود MSP يراقب عدة مواقع عملاء بالتوازي، دائمًا كمكمِّل - وليس بديلًا أبدًا - لمراقبة أعمق على مستوى التطبيق.

تتبع المسار (Traceroute)

يتتبع مسار الشبكة (قفزة بقفزة) إلى مضيف الوجهة.

أدخل اسم مضيف أو عنوان IP وشغّله لرؤية كل قفزة شبكة بين هذا الخادم والوجهة، مع زمن الاستجابة لكل قفزة.

You TTL=1 TTL=2 TTL=3 Host each hop replies "ICMP Time Exceeded" until TTL reaches the host

      

بحث DNS (Nslookup)

استعلام عن سجلات DNS: A، AAAA، MX، TXT، NS، CNAME، SOA، PTR، SRV، CAA.

أدخل نطاقًا، واختر نوع السجل (A أو AAAA أو MX أو TXT أو NS أو CNAME أو SOA أو PTR أو SRV أو CAA)، ثم ابحث.

You Root .com Auth NS ① query root ② referral → TLD ③ referral → auth NS ④ answer

      

Whois

البحث عن معلومات تسجيل نطاق أو عنوان IP.

أدخل نطاقًا أو عنوان IP للاطلاع على بيانات تسجيله: المسجّل والمؤسسة المالكة والتواريخ المهمة.

You Registry RDAP / :43 query: domain / IP reply: registrar, dates, name servers

      

فحص القائمة السوداء

يتحقق مما إذا كان عنوان IP أو نطاق مدرجًا في قوائم سوداء عامة للبريد العشوائي/الإساءة (DNSBL).

أدخل عنوان IPv4 أو نطاقًا وشغّله للتحقق من 7 قوائم سوداء عامة (DNSBL/RBL) دفعة واحدة - يظهر كل منها كمدرَج أو غير مدرَج أو فشل الفحص.

You zen.spamhaus.org spamcop.net sorbs.net +4 more reverse-IP DNS query to each DNSBL zone, in parallel

      

فحص منافذ TCP

تحقق مما إذا كانت منافذ TCP مفتوحة على مضيف أو IP: منافذ شائعة، قائمة مخصصة، أو النطاق الكامل 1-65535.

أدخل مضيفًا أو عنوان IP، واختر المنافذ الشائعة أو قائمة مخصصة أو النطاق الكامل، ثم افحص لمعرفة أي منافذ TCP تستجيب.

You 22 open 443 open 3389 closed 8080 closed SYN → SYN-ACK = open · SYN → RST = closed

        
      

فاحص ترويسات HTTP

يجلب حالة استجابة HTTP وترويساتها لعنوان URL.

أدخل عنوان URL للحصول على رمز حالة استجابة HTTP وكل رؤوس الاستجابة التي يرسلها الخادم.

You Server GET / HTTP/1.1 200 OK + headers Content-Type · Strict-Transport-Security · X-Frame-Options …

      

فاحص شهادة SSL / TLS

يفحص شهادة TLS لمضيف: الجهة المصدرة، تواريخ الصلاحية، والأيام المتبقية.

أدخل اسم مضيف لفحص شهادة TLS الخاصة به: الجهة المُصدرة وتواريخ الصلاحية وعدد الأيام المتبقية قبل انتهائها.

You Host ClientHello → ← ServerHello + Certificate + Finished Root CA Intermediate Leaf (site) certificate chain of trust · validity dates checked

      

بحث الموقع الجغرافي لـ IP

يبحث عن الموقع الجغرافي ومعلومات الشبكة لعنوان IP. اتركه فارغًا لعرض عنوان IP العام الخاص بك.

أدخل أي عنوان IP، أو اتركه فارغًا للبحث عن عنوانك الخاص، لمعرفة موقعه التقريبي ومعلومات الشبكة/مزود الخدمة.

IP address Geo / RIR database City · Country ASN · Org

        
        
      

حاسبة الشبكة الفرعية / CIDR

تُحسب بالكامل في متصفحك — لا تُرسل أي بيانات إلى الخادم.

أدخل عنوان IP وبادئة CIDR (مثل 192.168.1.0/24) لحساب نطاق الشبكة وعنوان البث ونطاق المضيفين القابلين للاستخدام فورًا.

network bits (prefix) host bits /24 example — split moves with your prefix

      

اختبار السرعة

اختبار أساسي لسرعة التنزيل/الرفع مقابل هذا الخادم (تعتمد الدقة على اتصال الخادم نفسه).

اضغط على ابدأ لقياس سرعة التنزيل والرفع مقابل هذا الخادم. تعتمد الدقة على اتصال هذا الخادم نفسه.

You Server ↓ download ↑ upload throughput (Mbps)

      

قاموس رموز الدول

رموز الدول ISO 3166-1 alpha-2 — يتم البحث بالكامل في متصفحك.

ابحث أو تصفح قائمة رموز الدول ISO 3166-1 alpha-2، ويتم البحث بالكامل داخل متصفحك.

الدولةرمز ISO

قاموس رموز الاتصال الدولية

رموز الاتصال الدولية حسب الدولة — يتم البحث بالكامل في متصفحك.

ابحث أو تصفح رموز الاتصال الدولية حسب الدولة، ويتم البحث بالكامل داخل متصفحك.

الدولةرمز الاتصال

الساعة العالمية

اختر منطقة زمنية لمعرفة الوقت الحالي — اسحب الكرة الأرضية لتدويرها.

اختر منطقة زمنية من القائمة، أو اسحب الكرة الأرضية، لرؤية الوقت الحالي هناك.

وقتك
--:--:--
—

—

الوقت المحدد
--:--:--
—
— UTC±00:00
الفارق الزمني معك —

—

اسحب لتدوير الكرة الأرضية.

حالة شبكة الهاتف المحمول في فرنسا

مواقع هوائيات الهاتف المحمول المعطلة أو قيد الصيانة في فرنسا، حسب المشغل (Orange وFree وSFR وBouygues Telecom)، من بيانات Arcep العامة. لقطة تُحدَّث مرة واحدة يوميًا - ليست بثًا لحظيًا.

تصفح بيانات أعطال هوائيات الجوال والألياف حسب المشغل الفرنسي — لا حاجة لإدخال أي شيء، يتم التحديث تلقائيًا من بيانات Arcep العامة.

المصدر: Arcep، مجموعة بيانات «Sites indisponibles»، منشورة بموجب الترخيص المفتوح / Etalab 2.0 - إعادة الاستخدام التجاري مسموح بها صراحةً، بخلاف بيانات IODA/CAIDA المستخدمة سابقًا. شارة عادي/مراقبة/تنبيه هي تقدير داخلي (عدد أعطال اليوم مقابل وسيط الأيام السابقة)، وليست تصنيفًا رسميًا من Arcep. روابط المصدر أدناه.

أكثر المقاطعات تأثرًا

عدد المواقع المعطلة حاليًا أو قيد الصيانة، حسب المقاطعة. انقر على مشغّل أعلاه للتصفية.

البيانات: Arcep — Sites indisponibles · الخريطة الرسمية لحالة الشبكة


الشبكة الثابتة (الألياف الضوئية)

جودة شبكة الألياف الضوئية (FTTH) حسب المشغّل: معدل الأعطال المُبلّغ عنها ومعدل فشل التوصيل، من بيانات Arcep العامة. مؤشرات شهرية بمتوسط متحرك لؤ6 أشهر - ليست بثًا لحظيًا كما في قسم الهاتف.

المصدر: Arcep، مجموعة بيانات «Qualité des réseaux en fibre optique»، منشورة بموجب الترخيص المفتوح / Etalab 2.0 - إعادة الاستخدام التجاري مسموح بها صراحةً. روابط المصدر أدناه.

حسب المشغّل (الشركة الأم)

متوسطات آخر 6 أشهر متاحة، حسب الشركة الأم لمشغّل البنية التحتية.

البيانات: Arcep — Qualité des réseaux en fibre optique