Every server has a public IP address with a set of network doors — ports — that are either open, closed, or filtered.
A server's IP address can run many different services at once — a website, email, a database, remote administration tools — each listening on its own numbered "port." Port 443 is standard HTTPS, port 80 is HTTP, but there are thousands of others, and many are meant to be reachable only internally, not from the public internet at all.
A website only needs 80 and 443 open to the public. If a database port, an admin panel, or a remote-access service is also reachable from the internet — often left open by accident during setup, or because a firewall rule was never tightened after testing — it becomes something an attacker can find and try to exploit, without ever needing to interact with the actual website at all.
Beyond just "is this port open," some scans also check whether the specific software version listening on that port has a publicly known vulnerability (a CVE) already documented against it — the difference between "a door is unlocked" and "a door is unlocked and there's a published guide to picking that specific lock."
A passive lookup like this reflects a snapshot, not a live scan — a port open last week may have been closed since, and a newly opened one might not show up yet. It's also only checking whatever IP address the domain currently resolves to; a site behind a CDN or load balancer shows that edge's exposure, not necessarily every server behind it.
Exposed internal services are rarely intentional — they're almost always leftover from a default configuration, a testing setup nobody locked back down, or a hosting default that was never reviewed. Finding out proactively, rather than after something goes wrong, is the entire value of a check like this.
Want to know where your own domain stands? CBWatch checks this — and eight other categories — in about ten seconds, free, no signup.
Run a free scan →Want CBWatch to catch this automatically going forward? See what monitoring includes →