◈ netchecks.org

17 Prüfungen · ohne Konto · selbst gehostet

Testen Sie Ihr Netzwerk mit einem Klick

17 kostenlose Netzwerk-Diagnosetools in einem Dashboard.

FAQ

0 Tracker · 14 Sprachen · Hell- und Dunkelmodus · selbst gehostet

← Alle Artikel

Practical guide

Why These Tools Exist: Reading Results, Judging Warnings, and When You Actually Need a VPN

Run a port scan, a header inspector, or a blacklist check against almost any real target and you'll get back a wall of technical detail: open ports, header names, certificate fields, list after list. None of it comes with a verdict attached. A result on its own doesn't tell you whether you're looking at something completely normal or something that needs fixing tonight - that judgment call is a separate skill from running the tool, and it's the one piece most diagnostic sites never actually teach.

This article is that missing layer. It won't turn anyone into a penetration tester, and it's not a substitute for a proper security audit on anything that actually matters - but it covers what each tool in this kit is really answering, how to read a result without swinging between panic and complacency, which warnings deserve a same-day fix versus a shrug, concrete examples of open ports that are fine versus open ports that are a real problem, and when reaching for a VPN is the right move instead of just another thing to configure.

What each tool is actually answering

It helps to sort the sixteen tools in this kit into four questions, because the right way to read a result depends entirely on which question it's answering. Ping and Traceroute answer "can I reach it, and if not, where does the path break" - pure connectivity, nothing about security. DNS Lookup, Whois, and GeoIP answer "who is this, and where does it actually live" - identity and ownership, useful for verifying a target is what it claims to be before trusting it. Port Scan, HTTP Headers, SSL Checker, and Blacklist Check answer "what does this system expose to the outside world, and should it" - this is the group that actually touches security, and the one this article spends the most time on. Subnet Calculator, Speed Test, and the two dictionary lookups answer "how much, or how big" - pure capacity and reference information, no risk judgment involved at all.

Knowing which bucket a tool sits in changes how you should react to its output. A Traceroute showing a hop that times out isn't a security finding - it's usually a router configured to ignore ICMP, completely unrelated to whether anything is actually wrong. A Port Scan showing an open port, on the other hand, is exactly the kind of result that deserves the rest of this article's attention, because it's telling you something real about what's reachable from outside.

Reading a result without over- or under-reacting

The single most useful habit when reading any of these tools' output is comparing the result against what you actually intended to be there - not against some imagined ideal of a perfectly locked-down system, which doesn't exist and isn't the goal. A web server with ports 80 and 443 open is not a finding; it's the entire point of running a web server. The question that actually matters is always "does this match what I meant to expose", not "is anything at all open or configured".

Most of what these tools surface is informational rather than alarming: a missing optional security header, a slightly older TLS cipher still offered alongside modern ones for compatibility, a WHOIS record with privacy redaction enabled - none of these are emergencies, and treating every line of output as equally urgent is how real warnings end up ignored along with the noise. The useful skill is triage: read the whole result once, mentally sort each line into "expected", "worth a closer look", or "reachable from the internet and shouldn't be", and only act urgently on that last category.

Is a warning actually serious? A field guide

A few of the most common warnings, and roughly how urgently each one actually deserves attention. A missing security header (Content-Security-Policy, Strict-Transport-Security) is real but rarely urgent on its own - it's a hardening gap, worth fixing on the next maintenance window, not a five-alarm fire, since it needs to be combined with another vulnerability to actually be exploited. An expired or soon-to-expire TLS certificate is genuinely urgent - it breaks trust for every visitor the moment it lapses, with no gradual warning to end users, so this is one to fix before it happens, not after. A blacklist listing is urgent specifically if the affected system sends email - mail silently stops arriving at major providers within hours, and the fix (identifying and removing the cause, then requesting delisting) can take days, so this is worth checking proactively rather than waiting for a client to notice their emails aren't landing.

An open port is the one that depends most entirely on context, which is exactly why it gets its own section below with concrete examples rather than a single blanket rule. The short version: the same open port can be completely fine on one system and a serious problem on another, purely based on which service it is and who's supposed to be able to reach it.

Open ports: what's normal and what's a real risk

Three rough categories cover almost every real-world case. Ports meant to be public - 443 (HTTPS) and 80 (HTTP) on anything hosting a website - being open is not a finding at all; it's the service working as designed, and a scan confirming they're reachable is exactly what should happen. Administrative ports - 22 (SSH) and 3389 (RDP) are the two seen most often - are fine to have open specifically to the people who need them, but worth reviewing if a scan shows them reachable from the entire internet rather than from a known, restricted set of addresses; the fix here isn't necessarily to close them, it's to restrict who can reach them (a firewall allowlist, key-only SSH authentication with password login disabled, or moving access behind a VPN entirely, covered below). Database and internal-service ports - 3306 (MySQL), 5432 (PostgreSQL), 27017 (MongoDB), and legacy protocols like 23 (Telnet) with no encryption at all - being reachable from the public internet is almost never intentional and almost always a real problem; these are designed to be talked to by an application server sitting next to them on the same private network, not queried directly by anyone on the internet, and a surprising number of real data breaches trace back to exactly this: a database left with its default port open to the world, often because a cloud security group or a home router's port-forwarding rule was set up carelessly and never revisited.

How this actually happens in practice is almost always mundane rather than malicious: a router's UPnP feature auto-opens a port for one application and never closes it again after that device is gone; a cloud security group gets set to "anywhere" during testing because it's faster than configuring the right IP range, and the ticket to fix it later never gets filed; a database gets spun up for a quick prototype with default credentials and default network settings, and the prototype quietly becomes the production system six months later. None of this requires an attacker doing anything clever - it just requires nobody double-checking what's actually reachable, which is precisely the gap a port scan is built to close.

The same scan finding - an open port - lands in a different risk bucket purely based on which port it is and who's supposed to reach it.

When you actually need a VPN (and when you don't)

A VPN is the right tool specifically for one recurring problem: you (or a small, known group of people) need to reach something - an admin panel, an SSH server, an internal dashboard - from outside its own network, without making it reachable by everyone else on the internet too. Rather than port-forwarding SSH or RDP directly to the world and then trying to lock it down with firewall rules and fail2ban, putting it behind a VPN removes it from the public internet's view entirely: nobody can even attempt to connect unless they've already authenticated onto the VPN first, which collapses most of the open-port risk described above before a single login attempt happens. Modern options like WireGuard (covered in "The Rise of the VPN" article on this blog) make this genuinely easy to set up, with a fraction of the configuration and attack surface of older protocols like PPTP or IPsec.

A VPN is equally the right call whenever a device is regularly used on untrusted networks - a coffee shop, a conference, an airport - where anyone else on the same WiFi can potentially observe or intercept unencrypted traffic; routing that traffic through a VPN removes the local network as a point of interception, which is a real and common threat, not a theoretical one. It's also the standard way to connect two private networks together, for example a small business's office and its cloud servers, without exposing either one directly to the internet in between.

Where a VPN is not the fix: a genuinely misconfigured public-facing service - a database with no authentication reachable from anywhere, a web application with a real vulnerability - doesn't get safer by also running a VPN somewhere else on the network. Wrapping a broken lock in another door doesn't fix the lock; the actual exposure needs to be closed at the source (authentication enabled, the port removed from public reach, the vulnerability patched), and a VPN's job is specifically for controlling who can reach something that's intentionally not meant to be fully public - not for papering over something that's leaking regardless.

Fazit

The practical version of everything above: run the relevant tool, compare what it shows against what you actually intended to expose, and treat "reachable from the entire internet, and it shouldn't be" as the one signal worth acting on urgently - everything else is triage, not panic. For anything that genuinely only a specific person or a small team should reach, a VPN removes it from the public internet's view entirely rather than trying to defend a door that's standing wide open; for everything else, the fix is almost always tightening what's already there rather than adding another layer on top of it.

← Alle Artikel

Meine-IP-Prüfung

Ihre öffentliche IP-Adresse und Ihr Netzwerkstandort, automatisch erkannt.

Wird beim Öffnen von NetChecks automatisch geladen — keine Eingabe nötig. Nutzen Sie die Schaltfläche Aktualisieren nach einem Netzwerk- oder VPN-Wechsel.

Ihr Browser

All-in-One-Scan

Führt in einem Durchgang alle relevanten Prüfungen für eine IP-Adresse oder einen Hostnamen aus: DNS, Whois, Ping, Traceroute, ein Scan der bekannten Ports (1–1024), HTTP-Header und das SSL-Zertifikat.

Geben Sie eine Domain oder IP-Adresse ein und starten Sie den Scan, um DNS, Whois, Ping, Traceroute, gängige Ports, HTTP-Header und das SSL-Zertifikat auf einmal zu prüfen.

Die meisten Prüfungen laufen parallel – dauert in der Regel etwa 30 Sekunden, länger, wenn das Ziel langsam oder nicht erreichbar ist.

Der Portscan-Schritt läuft erst, wenn das Einwilligungskästchen oben aktiviert ist – alle anderen Prüfungen laufen unabhängig davon.

Ping

Sendet ICMP-Echo-Anfragen an einen Host, um Erreichbarkeit und Latenz zu prüfen.

Geben Sie einen Hostnamen oder eine IP-Adresse ein und klicken Sie auf Ping, um ICMP-Echo-Anfragen zu senden und die Round-Trip-Latenz zu messen.

You Host ICMP Echo Request (type 8) ICMP Echo Reply (type 0) measures: RTT · TTL · packet loss

      

Mehr erfahren über Ping

Was es ist

Ping sendet ICMP-Echo-Request-Pakete an einen Host und misst, wie lange die ICMP-Echo-Reply-Pakete für die Rückkehr benötigen. Es ist der grundlegendste Netzwerkkonnektivitätstest überhaupt: Er beantwortet genau eine Frage - "Ist dieser Rechner erreichbar, und wie schnell?". Das ICMP-Protokoll (RFC 792) wurde 1981 speziell dafür entwickelt, Steuer- und Diagnosenachrichten über IP-Netzwerke zu übertragen, unabhängig von jeglichem Anwendungsverkehr - Ping ist seine bekannteste und am universellsten verfügbare Implementierung, praktisch auf jedem Betriebssystem und Netzwerkgerät seit dessen frühesten Versionen vorhanden.

Wie es funktioniert

Jedes ICMP-Paket trägt ein TTL-Feld (Time To Live), das bei jedem durchquerten Router um eins verringert wird; erreicht es null, bevor das Ziel erreicht ist, wird das Paket verworfen und ein Fehler an den Absender zurückgesendet. Die gemessene Umlaufzeit (RTT) in Millisekunden spiegelt die kumulierte Netzwerklatenz über die gesamte Hin- und Rückstrecke wider, nicht nur den letzten Abschnitt in der Nähe des Ziels - ein Punkt, der oft missverstanden wird, da langsame Ping-Ergebnisse ihre eigentliche Ursache an jeder Stelle des Pfades haben können, nicht zwingend in der Nähe des getesteten Servers. Ein Ping sendet in der Regel mehrere Pakete hintereinander statt nur eines, wodurch sich ein einmaliger Latenz-Ausreißer von einem wiederkehrenden Problem unterscheiden und eine Paketverlustrate über die Stichprobe berechnen lässt.

Ergebnisse interpretieren

Eine stabile, niedrige RTT - wenige Millisekunden in einem lokalen Netzwerk, 10 bis 50 ms für ein Ziel im selben Land, und deutlich mehr bei einer interkontinentalen Verbindung - deutet auf eine gesunde Verbindung hin. Selbst ein geringer Paketverlust (über 1-2 %) wirkt sich besonders schädlich auf latenzempfindliche Anwendungen wie VoIP oder interaktive Remote-Sitzungen aus, bei denen sich jedes verlorene Paket als Aussetzer oder hörbarer Abriss bemerkbar macht. Eine stark schwankende Latenz von Paket zu Paket (Jitter) ist für dieselben Anwendungsfälle oft problematischer als eine hohe, aber vollkommen stabile Latenz. "Zeitüberschreitung der Anfrage" bedeutet, dass innerhalb der vorgesehenen Zeit keine Antwort eingetroffen ist - der Host könnte tatsächlich ausgefallen sein, eine Firewall könnte ICMP stillschweigend blockieren, oder eine Route könnte irgendwo auf dem Pfad unterbrochen sein; "Ziel nicht erreichbar" ist etwas anderes und aussagekräftiger: Ein zwischengeschalteter Router hat ausdrücklich eine Nachricht zurückgesendet, dass er das Paket nicht weiterleiten konnte, was hilft, den Ort des tatsächlichen Problems einzugrenzen.

Häufige Fehler

Der häufigste Fehlschluss ist es, einen Host in dem Moment als "ausgefallen" zu betrachten, in dem ein Ping fehlschlägt, obwohl sehr viele Server und Geräte - besonders hinter einer gut gehärteten Firewall oder bei großen Cloud-Anbietern gehostet - eingehendes ICMP bewusst als Richtlinie blockieren, während sie auf ihren tatsächlichen Diensten (HTTP, eine Datenbank usw.) voll funktionsfähig und erreichbar sind. Eine ausbleibende Ping-Antwort ist deshalb nur dann ein aussagekräftiger Beleg für einen Ausfall, wenn sie mit anderen Signalen kombiniert wird, etwa dass auch die Anwendung selbst nicht antwortet. Umgekehrt garantiert ein erfolgreicher Ping keineswegs, dass der auf dieser Maschine gehostete Anwendungsdienst korrekt funktioniert - das sind zwei völlig unabhängige Schichten des Netzwerk-Stacks.

Wann man es einsetzt

Das Erste, was vor einer Ticket-Eskalation geprüft werden sollte: Reagiert die Maschine überhaupt, bevor weiter nachgeforscht wird? Bestätigung der Konnektivität nach einer Änderung einer Firewall-Regel oder einer Routing-Tabelle, um sicherzustellen, dass die Änderung den Zugriff nicht unterbrochen hat. Ermittlung einer Latenz-Baseline vor einem VoIP-Rollout oder einem Betreiberleitungs-Failover, um bei später eingehenden Beschwerden über die Anrufqualität einen objektiven Vergleichspunkt zu haben. Eine schlanke, ressourcenschonende regelmäßige Zustandsprüfung für einen MSP, der mehrere Kundenstandorte parallel überwacht, stets als Ergänzung zu - niemals als Ersatz für - eine tiefergehende Überwachung auf Anwendungsebene.

Traceroute

Verfolgt den Netzwerkpfad (Hop für Hop) zu einem Zielhost.

Geben Sie einen Hostnamen oder eine IP-Adresse ein und starten Sie den Scan, um jeden Netzwerk-Hop zwischen diesem Server und dem Ziel mit der jeweiligen Latenz zu sehen.

You TTL=1 TTL=2 TTL=3 Host each hop replies "ICMP Time Exceeded" until TTL reaches the host

      

DNS-Abfrage (Nslookup)

Fragt DNS-Einträge ab: A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, CAA.

Geben Sie eine Domain ein, wählen Sie einen Eintragstyp (A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV oder CAA) und starten Sie die Abfrage.

You Root .com Auth NS ① query root ② referral → TLD ③ referral → auth NS ④ answer

      

Whois

Ruft Registrierungsinformationen für eine Domain oder IP-Adresse ab.

Geben Sie eine Domain oder IP-Adresse ein, um deren Registrierungsdaten abzurufen: Registrar, Inhaberorganisation und wichtige Daten.

You Registry RDAP / :43 query: domain / IP reply: registrar, dates, name servers

      

Blacklist-Prüfung

Prüft, ob eine IP-Adresse oder Domain auf öffentlichen Spam-/Missbrauchs-Blacklists (DNSBL) gelistet ist.

Geben Sie eine IPv4-Adresse oder Domain ein und starten Sie die Prüfung, um 7 öffentliche DNSBL/RBL-Blacklists gleichzeitig abzufragen - jede wird als gelistet, nicht gelistet oder Prüfung fehlgeschlagen angezeigt.

You zen.spamhaus.org spamcop.net sorbs.net +4 more reverse-IP DNS query to each DNSBL zone, in parallel

      

TCP-Portscan

Prüft, ob TCP-Ports auf einem Host oder einer IP offen sind: gängige Ports, eine benutzerdefinierte Liste oder der vollständige Bereich 1–65535.

Geben Sie einen Host oder eine IP ein, wählen Sie gängige Ports, eine benutzerdefinierte Liste oder den vollen Bereich, und scannen Sie, um zu sehen, welche TCP-Ports antworten.

You 22 open 443 open 3389 closed 8080 closed SYN → SYN-ACK = open · SYN → RST = closed

        
      

HTTP-Header-Prüfung

Ruft den HTTP-Antwortstatus und die Header für eine URL ab.

Geben Sie eine URL ein, um deren HTTP-Statuscode und alle vom Server gesendeten Antwort-Header abzurufen.

You Server GET / HTTP/1.1 200 OK + headers Content-Type · Strict-Transport-Security · X-Frame-Options …

      

SSL-/TLS-Zertifikatsprüfung

Prüft das TLS-Zertifikat eines Hosts: Aussteller, Gültigkeitsdaten und verbleibende Tage.

Geben Sie einen Hostnamen ein, um dessen TLS-Zertifikat zu prüfen: Aussteller, Gültigkeitsdaten und verbleibende Tage bis zum Ablauf.

You Host ClientHello → ← ServerHello + Certificate + Finished Root CA Intermediate Leaf (site) certificate chain of trust · validity dates checked

      

Geo-IP-Abfrage

Ruft den geografischen Standort und Netzwerkinformationen für eine IP-Adresse ab. Leer lassen, um Ihre eigene öffentliche IP abzufragen.

Geben Sie eine beliebige IP-Adresse ein, oder lassen Sie das Feld leer, um Ihre eigene abzufragen, und sehen Sie deren ungefähren Standort sowie Netzwerk-/ISP-Informationen.

IP address Geo / RIR database City · Country ASN · Org

        
        
      

Subnetz-/CIDR-Rechner

Wird vollständig in Ihrem Browser berechnet — es werden keine Daten an den Server gesendet.

Geben Sie eine IP-Adresse und ein CIDR-Präfix ein (z. B. 192.168.1.0/24), um sofort den Netzwerkbereich, die Broadcast-Adresse und die Anzahl nutzbarer Hosts zu berechnen.

network bits (prefix) host bits /24 example — split moves with your prefix

      

Geschwindigkeitstest

Einfacher Download-/Upload-Durchsatztest gegenüber diesem Server (die Genauigkeit hängt von der Uplink-Anbindung des Servers ab).

Klicken Sie auf Start, um Download- und Upload-Durchsatz gegen diesen Server zu messen. Die Genauigkeit hängt von der eigenen Verbindung dieses Servers ab.

You Server ↓ download ↑ upload throughput (Mbps)

      

Ländercode-Verzeichnis

ISO-3166-1-Alpha-2-Ländercodes — die Suche erfolgt vollständig in Ihrem Browser.

Durchsuchen Sie die Liste der ISO-3166-1-Alpha-2-Ländercodes, die vollständig in Ihrem Browser durchsucht wird.

LandISO-Code

Telefonvorwahl-Verzeichnis

Internationale Vorwahlen nach Land — die Suche erfolgt vollständig in Ihrem Browser.

Durchsuchen Sie internationale Landesvorwahlen nach Land, vollständig in Ihrem Browser durchsucht.

LandVorwahl

Weltzeituhr

Wählen Sie eine Zeitzone, um die aktuelle Uhrzeit zu sehen – ziehen Sie den Globus, um ihn zu drehen.

Wählen Sie eine Zeitzone aus der Liste oder ziehen Sie den Globus, um die aktuelle Uhrzeit dort zu sehen.

Deine Zeit
--:--:--
—

—

Ausgewahlte Zeit
--:--:--
—
— UTC±00:00
Unterschied zu dir —

—

Ziehen, um den Globus zu drehen.

Status des französischen Mobilfunknetzes

Mobilfunk-Antennenstandorte in Frankreich, die ausgefallen oder in Wartung sind, nach Betreiber (Orange, Free, SFR, Bouygues Telecom), auf Basis der öffentlichen Daten der ARCEP. Der Stand wird einmal täglich von der ARCEP aktualisiert – kein minutengenauer Feed.

Durchsuchen Sie Daten zu Mobilfunk- und Glasfaser-Ausfällen nach französischem Betreiber — keine Eingabe nötig, automatisch aktualisiert aus den öffentlichen Arcep-Daten.

Quelle: ARCEP, Datensatz „Sites indisponibles“, veröffentlicht unter Licence Ouverte / Etalab 2.0 – kommerzielle Weiterverwendung ausdrücklich erlaubt, anders als die zuvor in diesem Tab verwendeten IODA/CAIDA-Daten. Das Symbol Normal/Beobachtung/Alarm ist eine hausinterne Schätzung (heutige Ausfallzahl im Vergleich zum Median der Vortage), keine offizielle ARCEP-Einstufung. Quellenlinks unten.

Am stärksten betroffene Departements

Anzahl der aktuell ausgefallenen oder in Wartung befindlichen Standorte, nach Departement. Klicken Sie oben auf einen Betreiber, um zu filtern.

Daten: Arcep — Sites indisponibles · Offizielle Netzstatuskarte


Festnetz (Glasfaser)

Qualität des Glasfasernetzes (FTTH) nach Betreiber: gemeldete Ausfallrate und Anschluss-Fehlerrate, auf Basis der öffentlichen Daten der ARCEP. Monatliche Kennzahlen, gleitender 6-Monats-Durchschnitt – kein Live-Feed wie beim Mobilfunkteil.

Quelle: ARCEP, Datensatz „Qualité des réseaux en fibre optique“, veröffentlicht unter Licence Ouverte / Etalab 2.0 – kommerzielle Weiterverwendung ausdrücklich erlaubt. Quellenlinks unten.

Nach Betreiber (Muttergesellschaft)

Durchschnittswerte der letzten 6 verfügbaren Monate, je Infrastrukturbetreiber-Muttergesellschaft.

Daten: Arcep — Qualité des réseaux en fibre optique