Is my port open? Test your port forwarding

We connect to your port from outside your network.

Updated

A number from 1 to 65535.

One TCP port, one try, no data sent. We never store the port you test. UDP cannot be tested this way.

Looking up your public IPv4…

This check runs over IPv4; we cannot see your IPv6 address here. IP to ISP by DB-IP.

The problem

What the port check result means

We open one TCP connection to the port you choose on your public IPv4, wait up to 3 seconds, and close it. We send no data. There are four possible results.

Open: something accepted the connection. Your forward probably works, but check that it is your app and not the router's own admin page, which some routers serve on 80, 443 or 8080.

Closed (refused): a device answered and said nothing is listening. Usually that is your router or host, so traffic reaches you: the forward points at the wrong LAN IP or port, or the app is not running, is bound to 127.0.0.1 instead of 0.0.0.0, or is blocked by the host firewall. Some ISP gateways answer the refusal themselves, so run the CGNAT check if the rule looks right. On Windows, a network set to "Public" blocks most incoming connections.

No response (timed out): the connection was dropped silently. Common causes are CGNAT or double NAT, a firewall, a forward that points at a device that is off, or an ISP port block. Xfinity's published list, for example, blocks 25, 135 to 139 and 445 in both directions and 1080 inbound, and many ISPs block 25 and 80 on residential plans.

Unreachable: a router on the path sent back 'unreachable', often because the forward points at a device that is off.

Why use GetAStatic?

What you get if the fix is a static IPv4

  • A dedicated public IPv4 that works behind CGNAT, double NAT and gateways with no port forwarding
  • Open TCP or UDP ports in the dashboard, not on the router: 5 open ports on Plus, unlimited open ports on Pro
  • Get around ISP blocks on residential connections, such as inbound port 80
  • VPN and IP in one price, from $2/mo, with a 7-day money-back guarantee
How it works

When the problem is CGNAT or an ISP block

First find out whether you have a public address. If your router's WAN IP matches your public IP, you are not behind CGNAT. Then, if a high port such as 25565 tests open and port 80 does not, the ISP or the router's own admin page is holding 80. If the WAN IP is different, run the CGNAT check: no forward rule on your router can work behind CGNAT.

GetAStatic gives you a dedicated public IPv4 over WireGuard. The machine that runs your service (or your router) dials out to our node in Kansas City, Missouri or San Jose, California, so CGNAT cannot block it, and your ISP never sees the inbound connection, so its port blocks do not apply. You open the ports you need in the dashboard; every other port stays closed.

A static IP tunnel does not fix everything. If the app is not listening, or the host firewall blocks it, the result is the same with or without us. Work through steps 1 and 2 below first.

Setup

Port forwarding not working? Work through these in order

Most failed forwards come down to one of these six steps. Stop at the first one that fails.

  1. Check the app is listening on the machine itself. Open localhost:PORT (or connect to 127.0.0.1 on that port) from the same machine. If that fails, the app is not running or uses another port.
  2. Check it is reachable on your LAN. From another device on the same network, connect to the machine's LAN IP and port. If that fails, the app may be bound to 127.0.0.1 instead of 0.0.0.0, the host firewall may block it, or Windows may have the network set to "Public".
  3. Compare your router's WAN IP with your public IP. If they differ, you are behind CGNAT or double NAT, and a forward on your router cannot work. Use the CGNAT check to find out which.
  4. Check the forward rule. It must point at the right LAN IP (give the machine a DHCP reservation so it does not change), with the right external and internal port, and the right protocol (TCP or UDP). Make sure the router's remote admin or a UPnP mapping is not already using that port.
  5. Test from outside your network. Use this tool, or a phone on mobile data with Wi-Fi off. Testing from inside your LAN often fails because many routers do not support NAT loopback.
  6. If everything above checks out and the test still gets no response, your ISP may block the port. Try a high port such as 25565 or 8443 to confirm.
PortProtocolUsed for
25565TCPMinecraft Java Edition
32400TCPPlex Media Server
8123TCPHome Assistant
22TCPSSH
443TCPHTTPS website or reverse proxy
3389TCPWindows Remote Desktop

The tool above covers step 5. A static IPv4 tunnel from GetAStatic fixes steps 3 and 6, and makes step 4 unnecessary when WireGuard runs on the host itself. It does not fix steps 1 and 2: those are on your machine.

Good to know

Limits of this check, and of the fix

  • The check runs over IPv4. We cannot see your IPv6 address here.
  • One TCP port per test. UDP is not tested: a closed UDP port and a working one often look the same from outside, and WireGuard never answers unauthenticated packets. For WireGuard, check for a recent handshake instead.
  • To tell CGNAT apart from a port problem, you need your router's WAN address. No browser can read it, so the CGNAT check asks you to enter it.
  • The ISP name comes from a public IP-to-ISP database (DB-IP). It is a hint, not a verdict.
  • Privacy: we use your IP address only to show it to you and to test the port you choose. We test only your own address, one port per request. We never store the port you test. We only count which kind of result came up, for example 'open' or 'no response', like any page view. Normal web-server logs apply.
  • Each location gets one dedicated IPv4; Pro and Ultra include two. The device that uses it needs a WireGuard client (or a router that runs WireGuard). It is built for a stable address, not anonymity: the IP you connect from is logged.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Why does my port show closed when I forwarded it?

Closed means a device answered. Usually that is your router or host, so traffic reaches your network: the forward points at the wrong LAN IP or port, or the app is not running, is bound to 127.0.0.1, or is blocked by the host firewall (on Windows, check the network is not set to Public). Some ISP gateways answer the refusal themselves, so run the CGNAT check if the rule looks right.

02How do I check if Minecraft port 25565 is open?

Start the server, enter 25565 in the checker above and run it. Open means outside players can reach it. No response usually means CGNAT, a firewall, or a forward to the wrong machine. Bedrock uses UDP 19132, which this tool cannot test.

03Does my ISP block port 80 or port 25?

Many residential ISPs block port 25, and many block inbound 80. Port 25 blocks are mostly outbound, which stops you sending mail. This tool tests inbound. Xfinity's published list blocks 25, 135 to 139 and 445 in both directions. If your WAN IP matches your public IP and a high port tests open but 80 does not, the ISP or your router's admin page is holding 80.

04Can I port forward behind CGNAT?

No. Under CGNAT the ISP shares your public address with other customers, so a forward on your router never sees outside traffic. You need a public IP from the ISP, or a tunnel that gives you one, such as a static IPv4 over WireGuard from GetAStatic.

05Can you check a UDP port?

No. A closed UDP port and a working one look the same from outside, because most UDP services do not answer a stranger. For WireGuard, check for a recent handshake instead: the peer shows one as soon as traffic gets through.

06What do you do with my IP address?

We use your IP address only to show it to you and to test the port you choose. We test only your own address, one port per request. We never store the port you test. We only count which kind of result came up, for example 'open' or 'no response', like any page view. Normal web-server logs apply.

Have more questions? See the full FAQ →