◈ netchecks.org

17 checks · no account · self-hosted

Free Online Port Scanner Tool

17 free network diagnostic tools in one dashboard.

FAQ

0 trackers · 14 languages · dark & light mode · self-hosted

My IP Check

Your public IP address and network location, detected automatically.

Loads automatically when you open NetChecks — no input needed. Use the Refresh button to re-check after switching networks or reconnecting your VPN.

Your browser

All-in-One Scan

Runs every relevant check against one IP or hostname in a single pass: DNS, whois, ping, traceroute, a well-known-ports scan (1-1024), HTTP headers and the SSL certificate.

Enter a domain or IP address and run it to check DNS, whois, ping, traceroute, common ports, HTTP headers, and the SSL certificate all at once.

Most checks run in parallel - typically finishes in about 30 seconds, longer if the target is slow or unreachable.

The port scan step only runs once the consent checkbox above is checked - every other check runs regardless.

Ping

Send ICMP echo requests to a host to check reachability and latency.

Enter a hostname or IP address and press Ping to send ICMP echo requests and measure round-trip latency.

You Host ICMP Echo Request (type 8) ICMP Echo Reply (type 0) measures: RTT · TTL · packet loss

      

Traceroute

Trace the network path (hop by hop) to a destination host.

Enter a hostname or IP address and run it to see every network hop between this server and the destination, with latency per hop.

You TTL=1 TTL=2 TTL=3 Host each hop replies "ICMP Time Exceeded" until TTL reaches the host

      

DNS Lookup (Nslookup)

Query DNS records: A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, CAA.

Enter a domain, choose a record type (A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, or CAA), then look it up.

You Root .com Auth NS ① query root ② referral → TLD ③ referral → auth NS ④ answer

      

Whois

Look up registration information for a domain or IP address.

Enter a domain or IP address to look up its registration details — registrar, owner organization, and important dates.

You Registry RDAP / :43 query: domain / IP reply: registrar, dates, name servers

      

Blacklist Check

Check whether an IP address or domain is listed on public spam/abuse blocklists (DNSBL).

Enter an IPv4 address or domain and run it to check 7 public DNSBL/RBL blocklists at once - each shows as listed, not listed, or check failed.

You zen.spamhaus.org spamcop.net sorbs.net +4 more reverse-IP DNS query to each DNSBL zone, in parallel

      

TCP Port Scan

Check whether TCP ports are open on a host or IP: common ports, a custom list, or the full 1-65535 range.

Enter a host or IP, pick common ports, a custom list, or the full range, then scan to see which TCP ports respond.

You 22 open 443 open 3389 closed 8080 closed SYN → SYN-ACK = open · SYN → RST = closed

        
      

Learn more about TCP Port Scan

What it is

Port Scan tests the state of a set of TCP ports on a given target, revealing exactly which network services are reachable from the outside at a given moment - basic information for any security audit or network configuration validation.

How it works

For each port tested, the tool attempts a standard TCP connection via a SYN handshake. Three outcomes are possible from that attempt: the port responds and accepts the connection (it is open, a service is actively listening there), it responds but explicitly rejects the connection (it is closed, the host is reachable but nothing is listening at that specific spot), or no response arrives within the allotted time (it is filtered, which usually reflects a firewall silently dropping the request without ever letting it reach the service or even respond to it).

Reading the results

An open port is neither good nor bad news in itself - it is entirely the context that determines whether it is expected or a problem: port 443 open on a public web server is perfectly normal and desired, that same port open on an internal workstation with no reason to expose a web service is on the other hand suspicious and worth investigating. A filtered port (no response at all) rather than a closed one (an explicit rejection) is often a sign that a firewall is intercepting the request upstream of the server itself, before it even reaches it - a useful distinction for knowing where to look when a block is unexpected.

Common mistakes

A common confusion is treating a filtered port as equivalent to a closed one in an audit report, when the distinction is operationally important: a closed port proves the host is reachable and nothing is listening, while a filtered port proves nothing about what is actually behind the firewall - the service could well be running normally, simply protected. Another trap: a port scan run from one point on the network only reflects visibility from that exact point - a port can appear closed from the internet but perfectly open and reachable from the internal network, which is often the intended configuration rather than an anomaly.

When to use it

Auditing a server's real network exposure before it goes into production, to make sure no unintended service is listening publicly. Concretely confirming that a firewall rule actually blocks the intended port once applied, rather than relying solely on the declared configuration. Confirming that a service is genuinely reachable from the outside after a deployment or a NAT rule change, before announcing its availability. Quickly checking, as part of a routine check, that no unexpected port was left open by mistake after a technical intervention.

HTTP Header Inspector

Fetch the HTTP response status and headers for a URL.

Enter a URL to fetch its HTTP response status code and every response header the server sends back.

You Server GET / HTTP/1.1 200 OK + headers Content-Type · Strict-Transport-Security · X-Frame-Options …

      

SSL / TLS Certificate Checker

Inspect a host's TLS certificate: issuer, validity dates, and days remaining.

Enter a hostname to inspect its TLS certificate — issuer, validity dates, and days remaining before it expires.

You Host ClientHello → ← ServerHello + Certificate + Finished Root CA Intermediate Leaf (site) certificate chain of trust · validity dates checked

      

Geo-IP Lookup

Look up the geographic location and network info for an IP address. Leave empty to look up your own public IP.

Enter any IP address, or leave it empty to look up your own, to see its approximate location and network/ISP info.

IP address Geo / RIR database City · Country ASN · Org

Subnet / CIDR Calculator

Computed entirely in your browser — no data sent to the server.

Enter an IP address and CIDR prefix (e.g. 192.168.1.0/24) to instantly compute the network range, broadcast address, and usable host count.

network bits (prefix) host bits /24 example — split moves with your prefix

      

Speed Test

Basic download/upload throughput test against this server (accuracy depends on the server's own uplink).

Press Start to measure download and upload throughput against this server. Accuracy depends on this server's own connection.

You Server ↓ download ↑ upload throughput (Mbps)

      

Country Code Dictionary

ISO 3166-1 alpha-2 country codes — searched entirely in your browser.

Search or browse the list of ISO 3166-1 alpha-2 country codes, looked up entirely in your browser.

CountryISO Code

Phone Dialing Code Dictionary

International calling codes by country — searched entirely in your browser.

Search or browse international calling codes by country, looked up entirely in your browser.

CountryDial Code

World Clock

Pick a time zone to see the current time — drag the globe to spin it.

Pick a time zone from the list, or drag the globe, to see the current time there.

Your time
--:--:--
—

—

Selected time
--:--:--
—
— UTC±00:00
Difference vs. you —

—

Drag to rotate the globe.

French Mobile Network Status

Mobile antenna sites down or under maintenance in France, by operator (Orange, Free, SFR, Bouygues Telecom), from ARCEP's public data. Snapshot updated once a day by ARCEP - not a minute-by-minute feed.

Browse mobile antenna and fibre outage data by French operator — no input needed, updated automatically from ARCEP's public data.

Source: ARCEP, "Sites indisponibles" dataset, published under Licence Ouverte / Etalab 2.0 - commercial reuse explicitly allowed, unlike the IODA/CAIDA data this tab used before. The Normal/Watch/Alert badge is an in-house estimate (today's outage count vs. the median of prior days), not an official ARCEP classification. Source links below.

Most affected departments

Number of sites currently down or under maintenance, by department. Click an operator above to filter.

Data: Arcep — Sites indisponibles · Official network status map


Fixed Network (Fibre)

Fibre (FTTH) network quality by operator: reported-outage rate and connection-failure rate, from ARCEP's public data. Monthly indicators, 6-month rolling average - not a live feed like the mobile section.

Source: ARCEP, "Qualité des réseaux en fibre optique" dataset, published under Licence Ouverte / Etalab 2.0 - commercial reuse explicitly allowed. Source links below.

By operator (parent group)

Averages over the last 6 available months, per infrastructure-operator parent group.

Data: Arcep — Qualité des réseaux en fibre optique