◈ netchecks.org

17 verificações · sem conta · auto-hospedado

Teste sua rede em um clique

Dix-sept ferramentas gratuitas de diagnóstico de rede em um só painel.

Perguntas frequentes

0 rastreadores · 14 idiomas · modo claro e escuro · auto-hospedado

← Todos os artigos

Practical guide

Why These Tools Exist: Reading Results, Judging Warnings, and When You Actually Need a VPN

Run a port scan, a header inspector, or a blacklist check against almost any real target and you'll get back a wall of technical detail: open ports, header names, certificate fields, list after list. None of it comes with a verdict attached. A result on its own doesn't tell you whether you're looking at something completely normal or something that needs fixing tonight - that judgment call is a separate skill from running the tool, and it's the one piece most diagnostic sites never actually teach.

This article is that missing layer. It won't turn anyone into a penetration tester, and it's not a substitute for a proper security audit on anything that actually matters - but it covers what each tool in this kit is really answering, how to read a result without swinging between panic and complacency, which warnings deserve a same-day fix versus a shrug, concrete examples of open ports that are fine versus open ports that are a real problem, and when reaching for a VPN is the right move instead of just another thing to configure.

What each tool is actually answering

It helps to sort the sixteen tools in this kit into four questions, because the right way to read a result depends entirely on which question it's answering. Ping and Traceroute answer "can I reach it, and if not, where does the path break" - pure connectivity, nothing about security. DNS Lookup, Whois, and GeoIP answer "who is this, and where does it actually live" - identity and ownership, useful for verifying a target is what it claims to be before trusting it. Port Scan, HTTP Headers, SSL Checker, and Blacklist Check answer "what does this system expose to the outside world, and should it" - this is the group that actually touches security, and the one this article spends the most time on. Subnet Calculator, Speed Test, and the two dictionary lookups answer "how much, or how big" - pure capacity and reference information, no risk judgment involved at all.

Knowing which bucket a tool sits in changes how you should react to its output. A Traceroute showing a hop that times out isn't a security finding - it's usually a router configured to ignore ICMP, completely unrelated to whether anything is actually wrong. A Port Scan showing an open port, on the other hand, is exactly the kind of result that deserves the rest of this article's attention, because it's telling you something real about what's reachable from outside.

Reading a result without over- or under-reacting

The single most useful habit when reading any of these tools' output is comparing the result against what you actually intended to be there - not against some imagined ideal of a perfectly locked-down system, which doesn't exist and isn't the goal. A web server with ports 80 and 443 open is not a finding; it's the entire point of running a web server. The question that actually matters is always "does this match what I meant to expose", not "is anything at all open or configured".

Most of what these tools surface is informational rather than alarming: a missing optional security header, a slightly older TLS cipher still offered alongside modern ones for compatibility, a WHOIS record with privacy redaction enabled - none of these are emergencies, and treating every line of output as equally urgent is how real warnings end up ignored along with the noise. The useful skill is triage: read the whole result once, mentally sort each line into "expected", "worth a closer look", or "reachable from the internet and shouldn't be", and only act urgently on that last category.

Is a warning actually serious? A field guide

A few of the most common warnings, and roughly how urgently each one actually deserves attention. A missing security header (Content-Security-Policy, Strict-Transport-Security) is real but rarely urgent on its own - it's a hardening gap, worth fixing on the next maintenance window, not a five-alarm fire, since it needs to be combined with another vulnerability to actually be exploited. An expired or soon-to-expire TLS certificate is genuinely urgent - it breaks trust for every visitor the moment it lapses, with no gradual warning to end users, so this is one to fix before it happens, not after. A blacklist listing is urgent specifically if the affected system sends email - mail silently stops arriving at major providers within hours, and the fix (identifying and removing the cause, then requesting delisting) can take days, so this is worth checking proactively rather than waiting for a client to notice their emails aren't landing.

An open port is the one that depends most entirely on context, which is exactly why it gets its own section below with concrete examples rather than a single blanket rule. The short version: the same open port can be completely fine on one system and a serious problem on another, purely based on which service it is and who's supposed to be able to reach it.

Open ports: what's normal and what's a real risk

Three rough categories cover almost every real-world case. Ports meant to be public - 443 (HTTPS) and 80 (HTTP) on anything hosting a website - being open is not a finding at all; it's the service working as designed, and a scan confirming they're reachable is exactly what should happen. Administrative ports - 22 (SSH) and 3389 (RDP) are the two seen most often - are fine to have open specifically to the people who need them, but worth reviewing if a scan shows them reachable from the entire internet rather than from a known, restricted set of addresses; the fix here isn't necessarily to close them, it's to restrict who can reach them (a firewall allowlist, key-only SSH authentication with password login disabled, or moving access behind a VPN entirely, covered below). Database and internal-service ports - 3306 (MySQL), 5432 (PostgreSQL), 27017 (MongoDB), and legacy protocols like 23 (Telnet) with no encryption at all - being reachable from the public internet is almost never intentional and almost always a real problem; these are designed to be talked to by an application server sitting next to them on the same private network, not queried directly by anyone on the internet, and a surprising number of real data breaches trace back to exactly this: a database left with its default port open to the world, often because a cloud security group or a home router's port-forwarding rule was set up carelessly and never revisited.

How this actually happens in practice is almost always mundane rather than malicious: a router's UPnP feature auto-opens a port for one application and never closes it again after that device is gone; a cloud security group gets set to "anywhere" during testing because it's faster than configuring the right IP range, and the ticket to fix it later never gets filed; a database gets spun up for a quick prototype with default credentials and default network settings, and the prototype quietly becomes the production system six months later. None of this requires an attacker doing anything clever - it just requires nobody double-checking what's actually reachable, which is precisely the gap a port scan is built to close.

The same scan finding - an open port - lands in a different risk bucket purely based on which port it is and who's supposed to reach it.

When you actually need a VPN (and when you don't)

A VPN is the right tool specifically for one recurring problem: you (or a small, known group of people) need to reach something - an admin panel, an SSH server, an internal dashboard - from outside its own network, without making it reachable by everyone else on the internet too. Rather than port-forwarding SSH or RDP directly to the world and then trying to lock it down with firewall rules and fail2ban, putting it behind a VPN removes it from the public internet's view entirely: nobody can even attempt to connect unless they've already authenticated onto the VPN first, which collapses most of the open-port risk described above before a single login attempt happens. Modern options like WireGuard (covered in "The Rise of the VPN" article on this blog) make this genuinely easy to set up, with a fraction of the configuration and attack surface of older protocols like PPTP or IPsec.

A VPN is equally the right call whenever a device is regularly used on untrusted networks - a coffee shop, a conference, an airport - where anyone else on the same WiFi can potentially observe or intercept unencrypted traffic; routing that traffic through a VPN removes the local network as a point of interception, which is a real and common threat, not a theoretical one. It's also the standard way to connect two private networks together, for example a small business's office and its cloud servers, without exposing either one directly to the internet in between.

Where a VPN is not the fix: a genuinely misconfigured public-facing service - a database with no authentication reachable from anywhere, a web application with a real vulnerability - doesn't get safer by also running a VPN somewhere else on the network. Wrapping a broken lock in another door doesn't fix the lock; the actual exposure needs to be closed at the source (authentication enabled, the port removed from public reach, the vulnerability patched), and a VPN's job is specifically for controlling who can reach something that's intentionally not meant to be fully public - not for papering over something that's leaking regardless.

Em resumo

The practical version of everything above: run the relevant tool, compare what it shows against what you actually intended to expose, and treat "reachable from the entire internet, and it shouldn't be" as the one signal worth acting on urgently - everything else is triage, not panic. For anything that genuinely only a specific person or a small team should reach, a VPN removes it from the public internet's view entirely rather than trying to defend a door that's standing wide open; for everything else, the fix is almost always tightening what's already there rather than adding another layer on top of it.

← Todos os artigos

Verificação do meu IP

Seu endereço IP público e localização de rede, detectados automaticamente.

Carrega automaticamente ao abrir o NetChecks — não é necessário inserir nada. Use o botão Atualizar após trocar de rede ou reconectar a VPN.

Seu navegador

Verificação tudo-em-um

Executa todas as verificações relevantes em um IP ou nome de host em uma única passagem: DNS, whois, ping, traceroute, uma varredura de portas conhecidas (1-1024), cabeçalhos HTTP e o certificado SSL.

Insira um domínio ou endereço IP e execute para verificar DNS, whois, ping, traceroute, portas comuns, cabeçalhos HTTP e o certificado SSL de uma só vez.

A maioria das verificações é executada em paralelo - normalmente termina em cerca de 30 segundos, mais se o alvo for lento ou inacessível.

A etapa de varredura de portas só é executada quando a caixa de consentimento acima estiver marcada - todas as outras verificações são executadas de qualquer forma.

Ping

Envia solicitações ICMP echo a um host para verificar sua acessibilidade e latência.

Insira um nome de host ou endereço IP e clique em Ping para enviar solicitações ICMP echo e medir a latência de ida e volta.

You Host ICMP Echo Request (type 8) ICMP Echo Reply (type 0) measures: RTT · TTL · packet loss

      

Saiba mais sobre Ping

O que é

O Ping envia pacotes ICMP Echo Request a um host e mede quanto tempo demoram a voltar os pacotes ICMP Echo Reply. É o teste de conectividade de rede mais básico que existe: responde exatamente a uma pergunta, "esta máquina está acessível, e com que rapidez?". O protocolo ICMP (RFC 792) foi concebido em 1981 especificamente para transportar mensagens de controlo e diagnóstico em redes IP, à margem de qualquer tráfego de aplicação - o Ping é a sua implementação mais conhecida e universalmente disponível, presente praticamente em todos os sistemas operativos e dispositivos de rede desde as suas primeiras versões.

Como funciona

Cada pacote ICMP transporta um campo TTL (Time To Live) que é decrementado em um em cada router que atravessa; se chegar a zero antes de alcançar o destino, o pacote é descartado e um erro é enviado de volta ao remetente. O tempo de ida e volta (RTT), medido em milissegundos, reflete a latência de rede acumulada ao longo de todo o trajeto, não apenas a última etapa junto ao destino - um ponto muitas vezes mal interpretado, já que um resultado de ping lento pode ter a sua causa em qualquer ponto do trajeto, não necessariamente junto ao servidor testado. Um ping normalmente envia vários pacotes seguidos em vez de apenas um, o que permite distinguir um pico de latência pontual de um problema recorrente e calcular uma taxa de perda de pacotes sobre a amostra.

Interpretar os resultados

Um RTT baixo e estável - alguns milissegundos numa rede local, entre 10 e 50 ms para um destino dentro do mesmo país, e notavelmente mais para uma ligação intercontinental - indica uma ligação saudável. Mesmo uma pequena perda de pacotes (acima de 1-2%) é particularmente prejudicial para usos sensíveis à latência, como VoIP ou sessões remotas interativas, onde cada pacote perdido se manifesta como um corte ou uma falha audível. Uma latência muito variável de um pacote para o outro (jitter) é frequentemente, para estes mesmos usos, mais problemática do que uma latência elevada mas perfeitamente estável. "Tempo limite excedido" significa que não chegou nenhuma resposta dentro do prazo previsto - o host pode estar realmente em baixo, uma firewall pode estar a bloquear silenciosamente o ICMP, ou pode haver uma rota quebrada algures no trajeto; "Destino inacessível" é diferente e mais informativo: um router intermédio enviou explicitamente uma mensagem a dizer que não conseguiu reencaminhar o pacote, o que ajuda a delimitar onde está realmente o problema.

Erros comuns

O erro de interpretação mais comum é concluir que um host está "em baixo" assim que um ping falha, quando na verdade muitos servidores e dispositivos - especialmente atrás de uma firewall bem configurada, ou alojados em grandes fornecedores cloud - bloqueiam deliberadamente o ICMP de entrada por política, estando totalmente operacionais e acessíveis nos seus serviços reais (HTTP, uma base de dados, etc.). A ausência de resposta a um ping só é uma evidência significativa de indisponibilidade quando combinada com outros sinais, como a própria aplicação também não responder. Inversamente, um ping bem-sucedido não garante de forma alguma que o serviço de aplicação alojado nessa máquina esteja a funcionar corretamente - são duas camadas da pilha de rede totalmente independentes.

Quando usar

A primeira coisa a verificar antes de escalar um ticket: a máquina sequer responde, antes de investigar mais a fundo? Confirmar a conectividade após uma alteração de regra de firewall ou de tabela de encaminhamento, para garantir que a alteração não quebrou o acesso. Estabelecer uma medição de latência de referência antes de um lançamento de VoIP ou de um failover de ligação de operadora, para haver um ponto de comparação objetivo se surgirem queixas sobre a qualidade das chamadas mais tarde. Uma verificação de estado periódica e leve para um MSP que monitoriza vários sites de clientes em paralelo, sempre como complemento - nunca como substituto - de uma monitorização mais profunda ao nível da aplicação.

Traceroute

Rastreia o caminho de rede (salto a salto) até um host de destino.

Insira um nome de host ou endereço IP e execute para ver cada salto de rede entre este servidor e o destino, com a latência de cada salto.

You TTL=1 TTL=2 TTL=3 Host each hop replies "ICMP Time Exceeded" until TTL reaches the host

      

Consulta DNS (Nslookup)

Consulta registros DNS: A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, CAA.

Insira um domínio, escolha um tipo de registro (A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV ou CAA) e faça a consulta.

You Root .com Auth NS ① query root ② referral → TLD ③ referral → auth NS ④ answer

      

Whois

Consulta as informações de registro de um domínio ou endereço IP.

Insira um domínio ou endereço IP para consultar seus dados de registro: registrador, organização proprietária e datas importantes.

You Registry RDAP / :43 query: domain / IP reply: registrar, dates, name servers

      

Verificação de lista negra

Verifica se um endereço IP ou domínio está listado em listas negras públicas de spam/abuso (DNSBL).

Insira um endereço IPv4 ou domínio e execute para verificar 7 listas negras (DNSBL/RBL) públicas de uma vez - cada uma aparece como listada, não listada ou falha na verificação.

You zen.spamhaus.org spamcop.net sorbs.net +4 more reverse-IP DNS query to each DNSBL zone, in parallel

      

Varredura de portas TCP

Verifica se as portas TCP estão abertas em um host ou IP: portas comuns, uma lista personalizada, ou o intervalo completo 1-65535.

Insira um host ou IP, escolha portas comuns, uma lista personalizada ou o intervalo completo, e escaneie para ver quais portas TCP respondem.

You 22 open 443 open 3389 closed 8080 closed SYN → SYN-ACK = open · SYN → RST = closed

        
      

Inspetor de cabeçalhos HTTP

Obtém o status da resposta HTTP e os cabeçalhos de uma URL.

Insira uma URL para obter seu código de status HTTP e todos os cabeçalhos de resposta enviados pelo servidor.

You Server GET / HTTP/1.1 200 OK + headers Content-Type · Strict-Transport-Security · X-Frame-Options …

      

Verificador de certificado SSL / TLS

Inspeciona o certificado TLS de um host: emissor, datas de validade e dias restantes.

Insira um nome de host para inspecionar seu certificado TLS: emissor, datas de validade e dias restantes até expirar.

You Host ClientHello → ← ServerHello + Certificate + Finished Root CA Intermediate Leaf (site) certificate chain of trust · validity dates checked

      

Geolocalização de IP

Consulta a localização geográfica e as informações de rede de um endereço IP. Deixe em branco para consultar seu próprio IP público.

Insira qualquer endereço IP, ou deixe em branco para consultar o seu, para ver sua localização aproximada e informações de rede/ISP.

IP address Geo / RIR database City · Country ASN · Org

        
        
      

Calculadora de sub-rede / CIDR

Calculado inteiramente no seu navegador — nenhum dado é enviado ao servidor.

Insira um endereço IP e um prefixo CIDR (ex.: 192.168.1.0/24) para calcular instantaneamente o intervalo de rede, o endereço de broadcast e o número de hosts utilizáveis.

network bits (prefix) host bits /24 example — split moves with your prefix

      

Teste de velocidade

Teste básico de velocidade de download/upload em relação a este servidor (a precisão depende da própria conexão do servidor).

Clique em Iniciar para medir a velocidade de download e upload em relação a este servidor. A precisão depende da própria conexão deste servidor.

You Server ↓ download ↑ upload throughput (Mbps)

      

Dicionário de códigos de país

Códigos de país ISO 3166-1 alfa-2 — pesquisa feita inteiramente no seu navegador.

Pesquise ou navegue pela lista de códigos de país ISO 3166-1 alfa-2, consultada inteiramente no seu navegador.

PaísCódigo ISO

Dicionário de códigos telefônicos

Códigos de discagem internacional por país — pesquisa feita inteiramente no seu navegador.

Pesquise ou navegue pelos códigos telefônicos internacionais por país, consultados inteiramente no seu navegador.

PaísCódigo

Relógio mundial

Escolha um fuso horário para ver a hora atual — arraste o globo para girá-lo.

Escolha um fuso horário na lista, ou arraste o globo, para ver a hora atual nesse local.

Sua hora
--:--:--
—

—

Hora selecionada
--:--:--
—
— UTC±00:00
Diferenca em relacao a voce —

—

Arraste para girar o globo.

Estado da rede móvel na França

Antenas móveis fora de serviço ou em manutenção na França, por operadora (Orange, Free, SFR, Bouygues Telecom), com base em dados públicos da Arcep. Instantâneo atualizado uma vez por dia - não é um fluxo em tempo real.

Consulte os dados de falhas de antenas móveis e fibra por operadora francesa — nenhuma entrada necessária, atualizado automaticamente a partir dos dados públicos da Arcep.

Fonte: Arcep, conjunto de dados «Sites indisponibles», publicado sob Licença Aberta / Etalab 2.0 - reutilização comercial explicitamente permitida, ao contrário dos dados IODA/CAIDA usados antes. O selo Normal/Vigilância/Alerta é uma estimativa própria (falhas de hoje vs. mediana dos dias anteriores), não uma classificação oficial da Arcep. Links de origem abaixo.

Departamentos mais afetados

Número de sites atualmente fora de serviço ou em manutenção, por departamento. Clique num operador acima para filtrar.

Dados: Arcep — Sites indisponibles · Mapa oficial do estado da rede


Rede fixa (fibra)

Qualidade da rede de fibra (FTTH) por operadora: taxa de falhas reportadas e taxa de falhas de ligação, com base em dados públicos da Arcep. Indicadores mensais, média móvel de 6 meses - não é um fluxo em tempo real como a secção móvel.

Fonte: Arcep, conjunto de dados «Qualité des réseaux en fibre optique», publicado sob Licença Aberta / Etalab 2.0 - reutilização comercial explicitamente permitida. Links de origem abaixo.

Por operadora (grupo controlador)

Médias dos últimos 6 meses disponíveis, por grupo controlador do operador de infraestrutura.

Dados: Arcep — Qualité des réseaux en fibre optique