Whitelisted Port Scanner
Scans 15 standard ports for open services to avoid security risks.
Guide & best practices
Port Scanner for open ports and exposure risks
Find out which ports of a domain are reachable and spot risky exposed services like databases or RDP.
Typical use cases
Helps with attack-surface reviews, firewall audits, server hardening and finding accidentally exposed services.
How Balou scans ports
Balou probes selected ports of the target domain and reports their status plus, where available, service/banner information.
Best practices against exposure
Expose only necessary ports, protect management and database services via VPN/allowlist and monitor changes regularly.
Frequently asked questions
What do open, closed and filtered mean?
open: service reachable; closed: port reachable but no service; filtered: dropped by a firewall with no clear answer.
Which ports should not be open to the internet?
Database and management ports such as 3306 (MySQL), 5432 (Postgres), 3389 (RDP) and 6379 (Redis) – only via VPN or allowlist.
Which ports are typical?
22 SSH, 25 SMTP, 80/443 HTTP(S), 3306 MySQL, 5432 Postgres and 3389 RDP are commonly checked.
Is scanning my own domain legal?
You may scan your own systems; third-party systems only with explicit permission.