MYiP
Back to home

Public Port Diagnostics

MYiP would test only your own current public address — the single one it already receives from the server (CF-Connecting-IP) — against a fixed, conservative allowlist of well-known ports. The supported $0 deployment cannot originate raw TCP probes, so this page reports the exact limitation openly and never substitutes invented results.

Port Diagnostics

Diagnostic status

Unsupported

Unsupported

Active port probing is not performed in this deployment

A browser cannot establish inbound TCP connections, so a real port check would have to run on the edge. The current deployment targets the Cloudflare Free plan, which does not provide raw outbound TCP sockets; Cloudflare also prohibits outbound connections to port 25 and blocks outbound sockets to Cloudflare IP ranges. MYiP therefore does not attempt any port scan and reports no invented results.

Target

Target address

Checking your connection…

The single public address MYiP already receives from the server (CF-Connecting-IP). The browser cannot choose a target, and no arbitrary hostname or IP is ever scanned.

Ports tested

Port 21

Not tested

This port was not tested in this run.

Port 22

Not tested

This port was not tested in this run.

Port 25

Not tested

This port was not tested in this run.

Port 53

Not tested

This port was not tested in this run.

Port 80

Not tested

This port was not tested in this run.

Port 110

Not tested

This port was not tested in this run.

Port 143

Not tested

This port was not tested in this run.

Port 443

Not tested

This port was not tested in this run.

Port 465

Not tested

This port was not tested in this run.

Port 587

Not tested

This port was not tested in this run.

Port 993

Not tested

This port was not tested in this run.

Port 995

Not tested

This port was not tested in this run.

Port 1194

Not tested

This port was not tested in this run.

Port 1723

Not tested

This port was not tested in this run.

Port 3306

Not tested

This port was not tested in this run.

Port 3389

Not tested

This port was not tested in this run.

Port 5900

Not tested

This port was not tested in this run.

Port 8080

Not tested

This port was not tested in this run.

Port 8443

Not tested

This port was not tested in this run.

Results

In this deployment no ports were actually probed, because active probing is unavailable. Every port below is shown as Not tested. MYiP never substitutes an invented or guessed result.

Interpretation

Port results describe whether a TCP connection was accepted. They are not a security assessment: an open port is not a vulnerability, and a closed or filtered port is not a guarantee of safety.

Open

Open — the target accepted a TCP connection. The connection is closed immediately; no service interaction, banner or payload ever takes place.

Closed

Closed — the target refused the connection. This says nothing about whether the underlying service is otherwise safe.

Filtered or unreachable

Filtered or unreachable — no response reached the probe. On a home connection this most often reflects firewall or NAT behaviour, not an application verdict.

Scope

This diagnostic would test only your own current public IP, on a fixed allowlist of 19 well-known ports — never 65,535 ports. By design it would use a small concurrency, short timeouts, per-IP rate limits, and no UDP, no banner grabbing, no service exploitation and no payload beyond the minimum connection attempt. Connected sockets would be closed immediately. Nothing about a scan is stored or logged.

Exact limitation: this diagnostic would need to originate TCP probes from the edge, because browsers cannot open inbound connections. Raw outbound TCP sockets are a Cloudflare Workers runtime capability that the $0 Free tier this product targets does not provide; Cloudflare also blocks outbound sockets to Cloudflare IP ranges and prohibits outbound connections to port 25 (which is in the allowlist). The Free tier budgets (10 ms CPU, 6 simultaneous outgoing connections) would make multi-port probing impractical regardless. No VPS was added to fake this capability. The safe alternative today is a manual, local check of the same allowlist from a trusted device you control, or — if the operator later moves to a paid Workers plan — a narrowly gated probe limited to the requesting visitor’s own CF-Connecting-IP.

Results are ephemeral and produced locally by the shared engine. No scan history, IP, hostname or result is stored, sent to third parties, or used for analytics or fingerprinting.