Port scanner, for hosts you are authorised to test

Check what is listening on a host you run. This one needs an account and a statement that you are authorised to test the target, and every scan is recorded against the account that ran it.

Why this page asks for more than the others

Scanning a host you do not have permission to test is unlawful in many jurisdictions and is an abuse of our outbound address everywhere. An abuse report has to reach a person, so there is no anonymous lane here and there never will be: with no account there is nothing to bound and nobody to answer for it.

What is refused before a packet is sent

Private, loopback and link-local ranges, the cloud metadata address, our own infrastructure, and anything on the denylist. A range wider than the per-scan cap is refused outright rather than truncated, because a truncated scan of the wrong thing is still a scan of the wrong thing. None of those refusals is configurable.

What is recorded, and why that is the deal

The account, the target, the time and your authorisation statement — kept, not rotated away. That record is what an abuse report from an upstream provider is answered with, and being able to answer one is the condition of offering this at all.

Questions

Is port scanning legal?

It depends where you and the target are, and scanning a host you are not authorised to test is unlawful in many jurisdictions regardless of intent. That is why scanning here needs an account and a per-scan statement that you are authorised to test that target — and why every scan is logged against the account that ran it.

Why do I have to sign in to run a scan?

Because an abuse report has to reach somebody. A scan that cannot be attributed to an account cannot be answered for, cannot be rate-limited meaningfully, and cannot be stopped by suspending anything. There is deliberately no anonymous allowance.

What will you refuse to scan?

Private, loopback and link-local ranges, the cloud metadata address, our own infrastructure, and anything on the denylist. Those refusals are not configurable by a customer, and a range larger than the per-scan cap is refused before any packet is sent.