An open port means a service at that address is accepting network connections. When SubAnalyzer reports one, the service was reachable from the internet during the scan. It may still require authentication before anyone can use it.
Public HTTPS on a website is expected. A database, desktop session or container management API deserves closer attention. The question is whether the service needs public access and how that access is protected.
SubAnalyzer checks 58 TCP ports on every scan. The five categories below match the colored port chips in your results. Labels describe common uses and come from the port number. They do not identify the software or version running there. As the IANA port registry explains, traffic on a registered port can belong to a different service.
Web ports
These 22 ports cover public websites, alternative web listeners, development servers and management interfaces. A public application can legitimately use any of them. An administration page needs tighter access controls, even when its connection is encrypted.
Websites and alternative web ports
| Port | Scan label | Typical use and what to check |
|---|---|---|
| 80 | HTTP | Ordinary web traffic, often redirected to HTTPS. Check that sensitive pages and logins require encryption. |
| 443 | HTTPS | Encrypted web traffic. Expected on a public website, but also used by private applications and administration pages. |
| 8180008081808288809080 | HTTP Alt | Alternative HTTP listeners for applications, proxies and development environments. Identify the application and its intended audience. |
| 8080 | HTTP Proxy | Often a proxy or ordinary HTTP application. If it is a proxy, check that strangers cannot use it to relay traffic. |
| 44438443944310443 | HTTPS Alt | Alternative encrypted web listeners. Check whether they expose a public application or an internal management interface. |
Port 8443 is not dangerous by itself. An authenticated production application there may be intentional. A forgotten administration page on the same port is a different finding. The application and its access controls determine the risk.
Development servers and management interfaces
| Port | Scan label | Typical use and why it matters |
|---|---|---|
| 3000 | HTTP Alt | Common Node.js development applications or Grafana. Check for an unintended development server or exposed dashboard. |
| 5000 | HTTP Alt | Often Flask or a container registry. Flask's development server is unsuitable for production use. |
| 70017002 | WebLogic | WebLogic application and administration traffic. Apply security updates and restrict administrative access. |
| 8161 | ActiveMQ | The ActiveMQ web console. Restrict access and replace default credentials. |
| 8888 | HTTP Alt | Often Jupyter or a proxy console. Unprotected Jupyter access can let someone run code on the machine. |
| 9000 | HTTP Alt | Often SonarQube or MinIO's storage API. Check who can access project information or stored objects. |
| 9090 | HTTP Alt | Often Prometheus. Anyone who reaches it can read every stored time series, and Prometheus says its HTTP endpoints should not be exposed to the internet. |
| 10000 | Webmin | Server administration. A compromised Webmin installation can give an attacker root-level control. |
Defaults vary. Jupyter enables token authentication by default, while ActiveMQ documents default console credentials that should be changed. Check the deployed configuration before concluding that an interface is unprotected.
Database ports
These six ports cover databases, search indexes and caches. They usually belong on private networks or behind rules that allow only the applications and administrators that need them. A public listener increases exposure even when a password is required.
| Port | Scan label | Typical use and exposure risk |
|---|---|---|
| 3306 | MySQL | A relational database. Review allowed clients, account permissions and encryption. |
| 5432 | PostgreSQL | A relational database. Review network access and authentication rules, especially rules that trust clients without a password. |
| 6379 | Redis | An in-memory data store. Unrestricted access can let someone read, change or delete application data. |
| 9200 | Elastic | The Elasticsearch REST API. An unprotected instance can expose entire indexes and allow data changes or deletion. |
| 11211 | Memcached | An application cache. Public access can expose cached data or let outsiders alter it. |
| 27017 | MongoDB | A document database. Missing access controls can expose collections and allow destructive changes. |
Redis has no password configured in a basic default setup, but its protected mode can reject remote commands. Elasticsearch automatically enables security on eligible new installations. Neither an open 6379 nor an open 9200 establishes that data is accessible without authentication. Verify the actual settings using the Redis security guide and Elasticsearch security documentation.
Memcached's documentation explicitly warns against public exposure. Its known traffic amplification problem involves UDP, so a TCP finding on 11211 does not establish that amplification is possible. See the Memcached configuration guide and UDP advisory.
Email ports
These seven ports support sending and retrieving email. Public reachability is normal when you operate a mail server. Unexpected mail services on a development or application host are worth investigating.
| Port | Scan label | Typical use |
|---|---|---|
| 25 | SMTP | Receiving and relaying email between mail servers. An open port does not mean the server is an open relay. |
| 110 | POP3 | Retrieving email. Encryption can be negotiated after connecting. |
| 143 | IMAP | Accessing and managing mailboxes. Encryption can be negotiated with STARTTLS. |
| 465 | SMTPS | Client email submission with TLS encryption from the start of the connection. |
| 587 | Submission | Client email submission, commonly using STARTTLS to enable encryption. |
| 993 | IMAPS | IMAP with TLS encryption from the start of the connection. |
| 995 | POP3S | POP3 with TLS encryption from the start of the connection. |
Require encryption for mailbox access and client submission, and authenticate users before accepting their outgoing mail. A service scan does not verify those policies. The email TLS standard explains the distinction between encryption at connection time and an upgrade through STARTTLS.
Remote access ports
These five ports can provide a shell, a desktop or access to a graphical session. Review them promptly when they appear on an unexpected host.
| Port | Scan label | Typical use and exposure risk |
|---|---|---|
| 22 | SSH | Encrypted remote administration. Public access can be intentional, but restrict accounts, use strong authentication and keep the server updated. |
| 23 | Telnet | Obsolete remote administration that ordinarily sends credentials and session data without encryption. Disable public access and replace it with SSH. |
| 3389 | RDP | Windows remote desktop. Public listeners are frequent targets for brute-force attacks. Restrict access through a protected remote-access service. |
| 5900 | VNC | Desktop viewing and control. Weak passwords or missing authentication can give outsiders control of the session. |
| 6001 | X11 | Conventionally X11 display :1. A client the X server trusts can read other windows and capture input. Keep direct access restricted. |
CISA recommends limiting exposed remote desktop services, using multifactor authentication and closing unused access.
Infrastructure ports
These 18 ports cover file sharing, network services, container management, dashboards and messaging. Some are expected on public infrastructure. Others expose services normally intended for trusted clients.
File sharing and network services
| Port | Scan label | Typical use and what to check |
|---|---|---|
| 21 | FTP | Legacy file transfer. Standard FTP sends passwords in clear text, although servers can support TLS. Check whether it is still needed. |
| 53 | DNS | DNS over TCP. Expected on a public authoritative nameserver. Restrict recursive queries to intended clients. |
| 111 | RPC | The Unix RPC portmapper, used to locate services including older NFS services. Restrict it to trusted clients. |
| 113 | Ident | A legacy service that can return the user associated with a connection. It may disclose account information. |
| 139 | NetBIOS | Older Windows file sharing over NetBIOS sessions. Keep it behind restricted network access. |
| 199 | SMUX | A legacy connection between subagents and an SNMP monitoring agent. It normally belongs on a trusted network. |
| 445 | SMB | Windows file sharing. Public exposure creates unnecessary opportunities to attack file shares and their servers. |
| 548 | AFP | Older Apple file sharing, largely replaced by SMB. Restrict access to trusted clients. |
| 1025 | No name shown | The start of the dynamic port range used by older Windows systems, including RPC services. Identify the listener before drawing conclusions. |
| 1720 | H.323 | Call signaling for voice and video conferencing. Public access may be intentional. Confirm that it matches your conferencing setup. |
| 1723 | PPTP | An outdated VPN protocol with known security weaknesses. Replace it with a modern VPN. |
Microsoft documents 1025 at the start of the older Windows dynamic port range. It does not reliably identify the listener. Microsoft also recommends blocking inbound SMB from the internet and replacing PPTP.
Container management
| Port | Scan label | Typical use and exposure risk |
|---|---|---|
| 2376 | Docker TLS | The Docker daemon API over TLS. If the daemon runs as root, unauthorized API access can give an attacker control of the host. |
| 6443 | Kubernetes | The Kubernetes API server. Weak authentication or excessive permissions can expose secrets and allow changes to workloads. |
| 10250 | Kubelet | The kubelet API on a cluster node. Anonymous access combined with permissive authorization can allow commands to run inside containers. |
Encryption alone does not establish that clients are authorized. Check client authentication and permissions using Docker's daemon protection guide and Kubernetes' guidance on API access controls and kubelet authentication and authorization.
Dashboards and messaging
| Port | Scan label | Typical use and exposure risk |
|---|---|---|
| 5601 | Kibana | A web interface for Elasticsearch data. An unprotected dashboard can expose logs and other sensitive records. |
| 5672 | AMQP | Messaging, typically RabbitMQ. Review authentication, permissions and transport encryption. |
| 9091 | No name shown | Often Prometheus Pushgateway or Transmission's web interface. Identify the application and restrict its write or management access. |
| 9092 | Kafka | Usually a Kafka broker. Weak access controls can let unauthorized clients read or publish messages. |
Prometheus Pushgateway and Transmission both use 9091 by default. The number alone cannot distinguish a metrics endpoint from a torrent client's management interface.
How to read your scan results
Each subdomain lists its open ports as colored chips, such as 443 HTTPS and 22 SSH. The Services tile counts distinct open port numbers across the scan. If 20 subdomains all expose 80 and 443, the tile counts two distinct ports.
Use the Services filter to find subdomains with one or several selected ports open.
For subdomains with an open web port, SubAnalyzer captures a screenshot and page title. TLS checks also read certificates on all five HTTPS ports: 443, 4443, 8443, 9443 and 10443. Names on those certificates can reveal additional subdomains, which are then scanned too.
How SubAnalyzer confirms an open port
The service scan starts with a fast pass that sends the opening packet of a TCP connection. A reply alone is insufficient because firewalls and protective services can answer for ports with no application behind them. Before showing a result, SubAnalyzer requires a completed TLS handshake on its HTTPS ports, a real HTTP response on its designated HTTP ports, or, on other ports, a connection that holds without being reset. If an address answers a control check on port 2, its fast-pass results are discarded. Ports 80 and 443 are always tried.
The scan checks up to eight public IPv4 addresses per host, with no more than about 25 probes per second to any one address. It scans TCP only. UDP services, including SNMP on 161/udp, are outside its scope. IPv6 addresses are recorded but are not scanned for services. SubAnalyzer never logs in, identifies software versions or tests for vulnerabilities.
For the full process, read how our subdomain scanner works.
What to do about an unexpected port
- Identify the service and its owner. Check which application is listening and why it needs network access. Use the port label as a starting point.
- Restrict unnecessary public access. Update firewall or cloud network rules, bind the service to a private interface, or disable it if it is unused. Check dependencies before making changes.
- Review access controls. Require appropriate authentication, limit permissions, enable encryption and install security updates. If sensitive data may have been exposed, investigate access logs and affected credentials.
- Re-scan and monitor. Verify the change from outside your network, then watch for the port returning.
This follows CISA's internet exposure reduction guidance: identify exposed services, decide which need public access and protect those that remain.
SubAnalyzer can re-scan a monitored domain daily, weekly or monthly and send one email when something changes. Newly opened or closed ports are among the changes it reports. One monitored domain is free, and paid plans monitor up to 10.
Scan your domain to see which of these services are reachable across your subdomains.
Sources
- IANA service names and port numbers
- Flask development server guidance
- ActiveMQ web console
- Jupyter Server security
- MinIO AIStor console and API ports
- Prometheus security model
- Prometheus default port allocations
- Webmin security advisories
- Oracle WebLogic security advisory
- PostgreSQL client authentication rules
- Redis security
- Elasticsearch networking settings
- Elasticsearch automatic security setup
- Memcached configuration
- Memcached UDP amplification advisory
- RFC 8314, TLS for email submission and access
- CISA StopRansomware Guide
- RFC 4248, telnet URI scheme (security considerations)
- RFC 6143, VNC protocol and security
- X.Org security documentation
- RFC 2577, FTP security considerations
- RFC 4217, FTP over TLS
- RFC 1227, SMUX
- Microsoft Windows service and port requirements
- Microsoft SMB security guidance
- Microsoft VPN protocol guidance
- Docker daemon protection
- Kubernetes API access controls
- Kubelet authentication and authorization
- Prometheus Pushgateway documentation
- Transmission configuration
- CISA internet exposure reduction guidance