A port is not a hole in your computer. It is a number — one of 65,536 addresses that let a single machine run many network services at once and keep their traffic separate. Whether a port is open, closed or filtered describes how the machine answers when something knocks, and the difference between those three answers is the whole subject.
The three states, and what each one means
| State | What the machine does | What it tells an outsider |
|---|---|---|
| Open | A service is listening and accepts the connection | Something is running here, and here is roughly what |
| Closed | Nothing is listening, but the machine replies to say so | The host exists and is reachable — just not on this port |
| Filtered | No reply at all; a firewall discards the request silently | Nothing, which is the point |
The distinction people miss is between closed and filtered. A closed port is polite: it sends back a refusal, which confirms the machine is there. A filtered port says nothing, so a scanner cannot tell whether the host is protected, switched off, or does not exist. That silence is why firewalls drop packets rather than reject them.
What a port checker actually does
A port checker, or port scanner, sends a connection request to a range of ports and records how each one answers. For TCP that means starting the three-way handshake: the scanner sends a SYN packet, and an open port replies with SYN-ACK, a closed port replies with RST, and a filtered port replies with nothing at all. The scanner reads those three responses and builds its report.
The same tool serves both sides. Administrators run it to confirm that only the services they intended are reachable; attackers run it to find services worth attacking. Neither the tool nor the technique is inherently one or the other — the difference is whose machine you point it at, and scanning hosts you do not own or have permission to test is unlawful in many jurisdictions.
Ports worth recognising
Numbers 0 to 1023 are the well-known ports, assigned to standard services. Seeing one of these open tells you immediately what is probably running.
| Port | Service | Note |
|---|---|---|
| 22 | SSH | Remote administration. A common target for automated login attempts |
| 25 | SMTP | Mail transfer. Frequently blocked by home providers |
| 53 | DNS | Name lookups, usually UDP |
| 80 | HTTP | Unencrypted web traffic |
| 443 | HTTPS | Encrypted web traffic — the one port almost everything now uses |
| 3306 | MySQL | Should almost never be open to the internet |
| 3389 | RDP | Remote Desktop. Exposing this directly is a well-known way to get compromised |
How to see which ports are open on your own machine
On Windows, open Command Prompt and run netstat -ano. The LISTENING lines are your open ports, and the number in the last column is the process ID — look it up on the Details tab of Task Manager to see which program is responsible. In PowerShell, Get-NetTCPConnection -State Listen gives the same picture more readably.
That tells you what is listening on the machine. What the outside world can reach is a different question, because your router usually stands in the way. A home connection typically presents no open ports to the internet at all unless someone has configured port forwarding — which is why an online port checker showing everything filtered is the normal, healthy result rather than a problem to fix.
Should you close open ports?
A port is open because a program is listening on it, so the useful question is not how to close the port but whether that program should be running and reachable. Stop the service and the port closes by itself. If the service is needed locally but not remotely, the answer is a firewall rule rather than shutting it down.
Three habits cover most of the risk: do not forward ports on your router unless you have a specific reason, put remote access behind a VPN rather than exposing RDP or SSH directly, and check what your machine is listening on after installing software that quietly adds a background service.
Frequently asked questions
What is the difference between a closed port and a filtered port?
A closed port answers to say nothing is listening, which confirms the machine exists. A filtered port does not answer at all, because a firewall discarded the request, so a scanner learns nothing.
Are open ports dangerous?
Not in themselves. An open port simply means a service is listening. The risk comes from what that service is, whether it is patched, and whether it should be reachable from where it is being reached.
How many ports are there?
65,536 for each of TCP and UDP, numbered 0 to 65535. Ports 0 to 1023 are well-known and assigned to standard services, 1024 to 49151 are registered, and the rest are dynamic.
Is it legal to scan someone else’s ports?
Scanning your own equipment is fine. Scanning systems you neither own nor have written permission to test is treated as unauthorised access in many jurisdictions, whatever the intent.
Why does an online port checker say all my ports are filtered?
Because your router is doing its job. Home connections normally expose nothing to the internet unless port forwarding has been set up deliberately.
Does closing ports make me safe?
It reduces what is reachable, which helps, but most compromises arrive through software you are already running — a browser, a mail client, an out-of-date application — rather than through a listening port.
Related reading
For the wider picture see how to protect yourself from cybersecurity threats and what to do when malware strikes your website.
2 Comments
Thanks for sharing the information with us!
Thanks for sharing the information with us!