hostcloak.com · defensive only · guides

Check if my VPS ports are open

From inside the VPS, listening sockets tell one story. From the public internet, the story that matters for easy radar is: which ports actually answer strangers?

Firewalls, security groups, and “I bound that to localhost” mistakes mean the two views diverge. An outside-in check on a host you own closes that gap without asking for a root password.

Run a free surface scan Sample report

Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.

Hetzner VPS — which ports answer strangers?

Hetzner security groups / cloud firewalls are powerful, but the view from inside the VM and the view from the public internet can diverge. If you own a Hetzner VPS, HostCloak’s outside-in read checks which ports actually answer strangers on that public IP — then ranks what to quiet first. Authorized hosts only.

What HostCloak does

HostCloak Surface Guard:

  1. Takes a DNS name or public IP you control
  2. Reads public presence — including loud / unexpected ports, TLS, headers, obvious admin exposure
  3. Returns a posture grade and a severity-ranked fix order

Presence only. No exploit kits. Free: $0 · 1 host · 1 successful scan/day.

Run a free surface scan

What’s not included

If something looks reachable that should not be, typical defensive moves: bind to localhost/private net, tighten firewall/security groups, put admin UIs behind VPN or authenticated reverse proxy.

Compared to header-only tools

SecurityHeaders and Observatory-style graders answer how your HTTP headers look. They generally will not tell you a database or admin port is answering on the same public IP. HostCloak overlaps on headers, then covers the wider host surface and ranks fixes.

FAQ

Private IPs?

Rejected — along with loopback and cloud-metadata addresses. Public targets you own only.

Same as running nmap myself?

Different product. HostCloak is a defensive report with grade + fix order for authorized hosts, not a general-purpose port scanner for arbitrary targets.

Pricing?

Free $0 (1 host, 1 successful scan/day). Pro $19/mo. Agency $49/mo.

Run a free surface scan Sign in

Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.

Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.

Guides