The fastest way to check if a port is open
The quickest method depends on what you're checking. If you want to know whether your computer is listening on a specific port, use the command line tool built into your operating system — netstat on Windows or Mac, or ss on Linux. If you want to test whether a port on a remote computer or server is reachable from outside, use an online port checker or the telnet command.
Most people need one of these two things: either they're troubleshooting why a program won't connect (check your own machine), or they're testing whether a server is accessible from the internet (check from outside). The tool you pick depends on which problem you're solving.
Key Takeaways
- Use netstat (Windows/Mac) or ss (Linux) to see which ports your own computer is listening on right now.
- Use telnet or an online port checker to test whether a port on a remote server is reachable from your location.
- A port can be open on your machine but still unreachable from the internet if a firewall or router is blocking it.
- Different programs use different ports by convention — web servers typically use port 80 (HTTP) or 443 (HTTPS), while SSH uses port 22.
Checking ports on your own Windows computer
Open Command Prompt by pressing Windows key + R, typing cmd, and pressing Enter. Then type this command and press Enter:
netstat -ano
This shows every port your computer is currently listening on. You'll see columns for Protocol (TCP or UDP), Local Address (your computer's address and port number), Foreign Address, and State. Look for the port number you're interested in — for example, port 8080 would appear as :8080 in the Local Address column. If you see it listed with a State of LISTENING, that port is open and something on your computer is using it. The number in the PID column tells you which program owns that port; you can match it to a process name in Task Manager if you need to know which application it is.
If you see a port listed but the State shows TIME_WAIT or CLOSE_WAIT instead of LISTENING, the port is not currently accepting new connections — the program either closed it or is in the process of closing it. Only ports showing LISTENING are actively open and ready to receive traffic.
Checking ports on Mac or Linux from the command line
Open Terminal. On Mac, press Command + Space, type terminal, and press Enter. On Linux, open your terminal application from the menu or press Ctrl + Alt + T.
On Mac, type:
netstat -an | grep LISTEN
On Linux, type:
ss -tuln
Both commands show ports your computer is listening on. Look for the port number you're checking — it will appear after a colon in the address column. If you see it listed, that port is open. The ss command on Linux is newer and faster than netstat, though both work.
The output shows the protocol (tcp or udp), the local address with the port number, and the state. If you're looking for a specific port, you can narrow the results by piping to grep — for example, ss -tuln | grep 8080 will show only port 8080 if it's listening.
Testing if a remote port is reachable
If you need to know whether someone else's server or a computer on another network has a port open, you can't use netstat on that machine unless you have direct access to it. Instead, test the connection from your own computer using telnet.
On Windows, you may need to enable telnet first. Open Command Prompt as Administrator, then type:
dism /online /Enable-Feature /FeatureName:TelnetClient
Then use telnet to test the connection:
telnet example.com 8080
Replace example.com with the server address and 8080 with the port you're testing. If the port is open and reachable, you'll see a blank screen or a connection message. If it times out or shows "Connection refused," the port is closed or blocked. On Mac and Linux, telnet is usually already installed — just run the same command.
Using an online port checker
If you don't want to use the command line, several websites let you enter a server address and port number to test whether it's reachable. Search for "port checker" and you'll find tools like CanYouSeeMe.org or similar services. Enter your server's public IP address or domain name and the port number, then click the button to test. These tools work from their servers, so they can tell you whether the port is reachable from the internet — something telnet from your home computer might not catch if your ISP or a firewall is blocking outbound connections to that port.
Keep in mind that an online port checker tests from one location on the internet. A port might be open and reachable from some places but blocked by your ISP or a firewall rule elsewhere. If you're testing a server you control, use an online checker to see what the outside world sees, then use telnet or netstat to verify the port is actually listening on the server itself.
Understanding the difference between open and reachable
A port can be open on your computer but still unreachable from outside. This happens when a firewall, router, or network rule is blocking access. For example, your web server might be listening on port 8080 (you'd see it in netstat), but if your router's firewall isn't forwarding traffic to that port, nobody on the internet can reach it.
If netstat shows a port is listening but telnet or an online checker says it's not reachable, check your firewall settings. On Windows, open Windows Defender Firewall and look for the program in the allowed apps list. On Mac, check System Preferences > Security & Privacy > Firewall Options. On Linux, check your firewall rules with sudo ufw status or sudo iptables -L depending on which firewall you're using. You may also need to configure port forwarding on your router if you're trying to reach a computer on your home network from the internet.
Common ports and what uses them
Knowing which port a service typically uses helps you know what to look for. Port 80 is HTTP (unencrypted web traffic), port 443 is HTTPS (encrypted web traffic), port 22 is SSH (secure shell for remote access), port 3306 is MySQL databases, port 5432 is PostgreSQL databases, and port 8080 is often used for development web servers or proxies. If you're troubleshooting a specific application, check its documentation to find which port it listens on — the port number is usually configurable.
Ports below 1024 are called privileged ports and typically require administrator or root access to listen on them. Ports 1024 and above are unprivileged and can be used by regular user programs. This is why development servers and testing tools often use higher port numbers like 8000, 8080, or 9000.
Frequently Asked Questions
Why does netstat show a port as LISTENING but I can't connect to it?
The port is open on your computer, but something is blocking access from outside — usually a firewall or router. Check your Windows Defender Firewall settings or your router's firewall to see if the port is allowed. You can also test from another computer on the same network to rule out internet-level blocking.
What's the difference between TCP and UDP ports?
TCP is connection-based and reliable — it's used for web traffic, email, and file transfers where every packet must arrive. UDP is connectionless and faster but doesn't may provide delivery — it's used for video streaming, online games, and voice calls where speed matters more than perfection. Most services use TCP, but some use UDP or both.
Can I check if a port is open without using the command line?
Yes. On Windows, you can use the Resource Monitor graphical tool — press Windows key + R, type resmon.exe, go to the Network tab, and look for your program in the Processes with Network Activity section. On Mac, Activity Monitor shows network connections under the Network tab. For remote servers, use an online port checker website instead of telnet.
Does checking a port on my own computer require administrator access?
On Windows, netstat works without administrator rights, but some detailed information requires it. On Mac and Linux, basic netstat or ss commands work as a regular user, though some options need sudo. If you get a permission error, try running the command with sudo or administrator privileges.
What if a port shows as ESTABLISHED instead of LISTENING?
ESTABLISHED means your computer has an active outgoing connection on that port — it's connecting to something else, not listening for incoming connections. LISTENING means your computer is waiting for incoming connections. If you're checking whether a service is running and accepting connections, look for LISTENING, not ESTABLISHED.