Public Port Diagnostics
MYiP would test only your own current public address — the single one it already receives from the server (CF-Connecting-IP) — against a fixed, conservative allowlist of well-known ports. The supported $0 deployment cannot originate raw TCP probes, so this page reports the exact limitation openly and never substitutes invented results.
Port Diagnostics
Diagnostic status
UnsupportedUnsupported
Active port probing is not performed in this deployment
A browser cannot establish inbound TCP connections, so a real port check would have to run on the edge. The current deployment targets the Cloudflare Free plan, which does not provide raw outbound TCP sockets; Cloudflare also prohibits outbound connections to port 25 and blocks outbound sockets to Cloudflare IP ranges. MYiP therefore does not attempt any port scan and reports no invented results.
Target
Target address
Checking your connection…
The single public address MYiP already receives from the server (CF-Connecting-IP). The browser cannot choose a target, and no arbitrary hostname or IP is ever scanned.
Ports tested
Port 21
Not testedThis port was not tested in this run.
Port 22
Not testedThis port was not tested in this run.
Port 25
Not testedThis port was not tested in this run.
Port 53
Not testedThis port was not tested in this run.
Port 80
Not testedThis port was not tested in this run.
Port 110
Not testedThis port was not tested in this run.
Port 143
Not testedThis port was not tested in this run.
Port 443
Not testedThis port was not tested in this run.
Port 465
Not testedThis port was not tested in this run.
Port 587
Not testedThis port was not tested in this run.
Port 993
Not testedThis port was not tested in this run.
Port 995
Not testedThis port was not tested in this run.
Port 1194
Not testedThis port was not tested in this run.
Port 1723
Not testedThis port was not tested in this run.
Port 3306
Not testedThis port was not tested in this run.
Port 3389
Not testedThis port was not tested in this run.
Port 5900
Not testedThis port was not tested in this run.
Port 8080
Not testedThis port was not tested in this run.
Port 8443
Not testedThis port was not tested in this run.
Results
In this deployment no ports were actually probed, because active probing is unavailable. Every port below is shown as Not tested. MYiP never substitutes an invented or guessed result.
Interpretation
Port results describe whether a TCP connection was accepted. They are not a security assessment: an open port is not a vulnerability, and a closed or filtered port is not a guarantee of safety.
Open
Open — the target accepted a TCP connection. The connection is closed immediately; no service interaction, banner or payload ever takes place.
Closed
Closed — the target refused the connection. This says nothing about whether the underlying service is otherwise safe.
Filtered or unreachable
Filtered or unreachable — no response reached the probe. On a home connection this most often reflects firewall or NAT behaviour, not an application verdict.
Scope
This diagnostic would test only your own current public IP, on a fixed allowlist of 19 well-known ports — never 65,535 ports. By design it would use a small concurrency, short timeouts, per-IP rate limits, and no UDP, no banner grabbing, no service exploitation and no payload beyond the minimum connection attempt. Connected sockets would be closed immediately. Nothing about a scan is stored or logged.
Exact limitation: this diagnostic would need to originate TCP probes from the edge, because browsers cannot open inbound connections. Raw outbound TCP sockets are a Cloudflare Workers runtime capability that the $0 Free tier this product targets does not provide; Cloudflare also blocks outbound sockets to Cloudflare IP ranges and prohibits outbound connections to port 25 (which is in the allowlist). The Free tier budgets (10 ms CPU, 6 simultaneous outgoing connections) would make multi-port probing impractical regardless. No VPS was added to fake this capability. The safe alternative today is a manual, local check of the same allowlist from a trusted device you control, or — if the operator later moves to a paid Workers plan — a narrowly gated probe limited to the requesting visitor’s own CF-Connecting-IP.
Results are ephemeral and produced locally by the shared engine. No scan history, IP, hostname or result is stored, sent to third parties, or used for analytics or fingerprinting.