My IP Check
Your public IP address and network location, detected automatically.
Loads automatically when you open NetChecks — no input needed. Use the Refresh button to re-check after switching networks or reconnecting your VPN.
Your browser
All-in-One Scan
Runs every relevant check against one IP or hostname in a single pass: DNS, whois, ping, traceroute, a well-known-ports scan (1-1024), HTTP headers and the SSL certificate.
Enter a domain or IP address and run it to check DNS, whois, ping, traceroute, common ports, HTTP headers, and the SSL certificate all at once.
Most checks run in parallel - typically finishes in about 30 seconds, longer if the target is slow or unreachable.
The port scan step only runs once the consent checkbox above is checked - every other check runs regardless.
Ping
Send ICMP echo requests to a host to check reachability and latency.
Enter a hostname or IP address and press Ping to send ICMP echo requests and measure round-trip latency.
Traceroute
Trace the network path (hop by hop) to a destination host.
Enter a hostname or IP address and run it to see every network hop between this server and the destination, with latency per hop.
DNS Lookup (Nslookup)
Query DNS records: A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, CAA.
Enter a domain, choose a record type (A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, or CAA), then look it up.
Whois
Look up registration information for a domain or IP address.
Enter a domain or IP address to look up its registration details — registrar, owner organization, and important dates.
Blacklist Check
Check whether an IP address or domain is listed on public spam/abuse blocklists (DNSBL).
Enter an IPv4 address or domain and run it to check 7 public DNSBL/RBL blocklists at once - each shows as listed, not listed, or check failed.
TCP Port Scan
Check whether TCP ports are open on a host or IP: common ports, a custom list, or the full 1-65535 range.
Enter a host or IP, pick common ports, a custom list, or the full range, then scan to see which TCP ports respond.
A full range scan can take up to ~100 seconds. Large scans (more than 100 ports, including custom ranges/lists) are limited to 1 per minute per visitor.
Open ports (0)
HTTP Header Inspector
Fetch the HTTP response status and headers for a URL.
Enter a URL to fetch its HTTP response status code and every response header the server sends back.
SSL / TLS Certificate Checker
Inspect a host's TLS certificate: issuer, validity dates, and days remaining.
Enter a hostname to inspect its TLS certificate — issuer, validity dates, and days remaining before it expires.
Learn more about SSL / TLS Certificate Checker
What it is
This tool analyzes the TLS certificate presented by a server when a secure connection is established: issuing certificate authority, expiration date, the full set of domains covered, and the integrity of the certificate chain up to the trusted root - the information that determines whether a visitor's browser will show a trusted connection or a warning.
How it works
During the TLS handshake that precedes any encrypted exchange, the server presents its full certificate chain: the site's own certificate, one or more intermediate certificates, up to a root authority trusted by browsers. The tool retrieves this chain exactly as presented and extracts the relevant metadata from it, without needing to establish a full application-level session beyond that handshake.
Reading the results
An expiration date coming up soon is the single most critical alert to watch - an expired certificate immediately and completely breaks the trust shown by the browser for every visitor, with no gradual degradation. The SAN (Subject Alternative Name) field precisely lists every domain and subdomain actually covered by the certificate; a domain missing from that list will consistently trigger a trust error despite an otherwise perfectly valid, non-expired certificate. An incomplete chain, typically a missing intermediate certificate in the server's response, sometimes works without any visible error in browsers that already have that intermediate certificate cached locally, but fails in others that don't - a very classic cause of the "it works for me but not for the client" symptom.
Common mistakes
A common confusion is testing a certificate only from your own everyday browser, which may have a missing intermediate certificate cached and so masks a chain that is actually incomplete - a direct check of the chain exactly as presented on the network reveals problems invisible from a browser that silently compensates. Another trap: renewing a certificate without restarting or reloading the service that uses it can leave the old, expired certificate active in memory despite the new file being present on disk, giving the misleading impression that the renewal had no effect.
When to use it
Renewing a certificate with enough lead time before it expires, rather than discovering the problem in production once visitors start reporting errors. Diagnosing a trust error reported only by certain users on specific browsers or systems, a typical symptom of an incomplete certificate chain. Confirming that an automatic renewal (via Let's Encrypt, for example) actually completed successfully after its scheduled run, without waiting for a user complaint. Checking the exact SAN coverage before adding a new subdomain expected to be protected by an already-existing certificate.
Geo-IP Lookup
Look up the geographic location and network info for an IP address. Leave empty to look up your own public IP.
Enter any IP address, or leave it empty to look up your own, to see its approximate location and network/ISP info.
Subnet / CIDR Calculator
Computed entirely in your browser — no data sent to the server.
Enter an IP address and CIDR prefix (e.g. 192.168.1.0/24) to instantly compute the network range, broadcast address, and usable host count.
Speed Test
Basic download/upload throughput test against this server (accuracy depends on the server's own uplink).
Press Start to measure download and upload throughput against this server. Accuracy depends on this server's own connection.
Country Code Dictionary
ISO 3166-1 alpha-2 country codes — searched entirely in your browser.
Search or browse the list of ISO 3166-1 alpha-2 country codes, looked up entirely in your browser.
| Country | ISO Code |
|---|
Phone Dialing Code Dictionary
International calling codes by country — searched entirely in your browser.
Search or browse international calling codes by country, looked up entirely in your browser.
| Country | Dial Code |
|---|
World Clock
Pick a time zone to see the current time — drag the globe to spin it.
Pick a time zone from the list, or drag the globe, to see the current time there.
—
—
Drag to rotate the globe.
French Mobile Network Status
Mobile antenna sites down or under maintenance in France, by operator (Orange, Free, SFR, Bouygues Telecom), from ARCEP's public data. Snapshot updated once a day by ARCEP - not a minute-by-minute feed.
Browse mobile antenna and fibre outage data by French operator — no input needed, updated automatically from ARCEP's public data.
Most affected departments
Number of sites currently down or under maintenance, by department. Click an operator above to filter.
Data: Arcep — Sites indisponibles · Official network status map
Fixed Network (Fibre)
Fibre (FTTH) network quality by operator: reported-outage rate and connection-failure rate, from ARCEP's public data. Monthly indicators, 6-month rolling average - not a live feed like the mobile section.
By operator (parent group)
Averages over the last 6 available months, per infrastructure-operator parent group.