TCP exposure diagnostics

TCP Port Checker

Check whether selected TCP services are reachable on an authorised public IP address or domain.

Public targets only Up to 12 ports Live server check
Reachability basics

What a TCP port check tells you

A TCP port check shows whether a destination accepts connections on specific service ports from the internet. It is useful after DNS resolves correctly but a website, mail server or remote desktop session still fails to connect.

This tool attempts a short TCP connection from the Zerolink server and classifies each port as open, closed or filtered. It tests reachability only — it does not scan for vulnerabilities, brute-force credentials or probe systems you are not authorised to assess.

For a broader workflow, start with DNS lookup, then use ping or traceroute if the host itself appears unreachable before checking individual ports here. Compare measured throughput with the internet speed test when the service is slow but ports look open.

Practical workflows

When to check specific ports

Test only the service ports related to the failure, then widen the check only if the host itself is reachable.

Website loads over HTTP but not HTTPS

  1. Check ports 80 and 443 on the domain or server IP.
  2. If 80 is open but 443 is closed, review the TLS service and certificate binding.
  3. If 443 is filtered, inspect firewall rules and upstream security policies.
  4. Run the website audit for response and metadata issues.

Cannot connect to email or remote desktop

  1. Test the expected service ports such as 25, 465, 587, 993 or 3389.
  2. Compare open versus filtered results — filtered often means a firewall is blocking external access.
  3. Confirm the service is listening on the server and bound to the public interface.
  4. Restrict admin ports to trusted IPs or a VPN whenever possible.

Audit unexpected public exposure

  1. Check database and admin ports such as 3306, 5432, 6379 or 22.
  2. Investigate any open result that should not be internet-facing.
  3. Close the port at the firewall or move the service behind a VPN.
  4. Pair exposure review with the blacklist checker if mail reputation is affected.
01

Check TCP reachability

Enter a destination and a comma-separated list of ports.

Common:

Check only systems you own or have explicit permission to test. Results originate from the Zerolink server.

Interpret results carefully

What each port status means

Open

The destination accepted the TCP connection. Confirm that the exposed service is intentional, updated and access-controlled.

Closed

The host responded but refused the connection, normally because no service is listening or a firewall rejected it.

Filtered

No response arrived before timeout. A firewall or network policy may be silently dropping the connection.

Reduce unnecessary exposure

Restrict administration and database services to trusted addresses or a VPN. Use the Ping and Reachability Tool when the entire destination appears unreachable.

Port checker questions

What does an open TCP port mean?

An open result means the destination accepted a TCP connection on that port. It does not confirm that the service is secure or correctly configured.

What is the difference between closed and filtered?

Closed usually means the host actively refused the connection. Filtered means no response arrived before timeout, commonly because a firewall silently dropped the request.

Why does the tool show a different result from my computer?

The connection originates from the Zerolink hosting server. Firewalls, routing and geographic policies can produce different results from another network.

Which ports should normally be publicly open?

Only ports required by the intended public service should be exposed. Common examples are 80 and 443 for websites; administrative and database ports should usually be restricted.

Does an open port prove that my system is vulnerable?

No. It confirms reachability only. Vulnerability assessment requires authorised service identification, configuration review and security testing.

Can this tool check UDP ports?

No. This release tests TCP reachability only. UDP services such as DNS or some games require different diagnostic methods.

Why is there a 12-port limit?

The limit keeps checks focused and prevents misuse for broad unauthorised scanning. Run additional batches if you need to review more ports on the same host.

Should I test by domain or IP address?

Both work. A domain is convenient, but the tool resolves to an IP before connecting. If DNS recently changed, compare results against the direct address as well.

Using this port checker with Zerolink services

Test authorised public ports for VPN, mail or camera viewers hosted behind a Zerolink connection in Haryana. Always limit checks to systems you own or have permission to assess.

Leased line Enterprise networking CCTV installation

Link copied