Last updated August 14, 2026. Machine-readable contact details: /.well-known/security.txt
If you are looking at a log entry and trying to work out what connected to your network, this page is meant to answer that quickly. If it does not, write to help@testmyfirewall.com and a person will read it.
TestMyFirewall.com is a firewall and open-port test. Someone on your network opened the site and pressed a button, and our server made a single TCP connection back to the public address their browser was connecting from, so they could see whether that port was reachable from outside.
There is no field on the site where anyone can type in an address to test. The only address we will ever connect to is the one the request itself came from, which is a deliberate design limit rather than a policy we apply after the fact.
Each connection follows a person pressing a button, so someone working through several ports will produce several connections. They arrive at human speed and each one is a separate deliberate action on their part. Requests from a single address are also rate limited at our edge, which puts a hard ceiling on how fast this can happen even if it is scripted.
This runs on Cloudflare Workers, and outbound connections from Workers leave through Cloudflare's shared infrastructure. The address you see is not ours, it is not stable, and it is shared with a very large amount of unrelated Cloudflare traffic.
We would rather say that plainly than publish a number that would be wrong. Blocking the address you happened to observe would block far more than us, and would probably stop working the next day. If you need the full picture of Cloudflare's ranges, they are published at cloudflare.com/ips, but please be aware that filtering those affects a large share of the web.
If you are responsible for a network and you do not want it tested, we will honour
that. Email help@testmyfirewall.com
with the ranges in CIDR form, for example 198.51.100.0/24 or
2001:db8::/32, and enough context for us to see that the ranges are
yours — a message from an address in the domain that holds them, a WHOIS or
RIR contact, or an abuse-desk address already published for them.
Once a range is excluded, the tool refuses to test any address inside it for everyone, including people on that network who ask it to. They are shown a message saying the operator of their network has asked us not to run tests against it.
This site is run by one person alongside a full-time job. Requests are reviewed promptly, and we would rather tell you that than promise a response time we cannot keep. If a request is urgent, say so in the subject line.
Some networks are refused before any connection is attempted, because a result there would not mean anything useful and the connection is more likely to be unwelcome:
Port 25 is never tested, and only TCP is ever used. We cannot send UDP.
The service itself stores nothing. Test results are computed, returned to the browser that asked for them, and not written down — there is no database, no log of results, and no record of which address tested which port. Cloudflare, which serves the site, keeps its own operational and security logs under its own retention policy, and we cannot make that claim on its behalf. See the Terms of Use for the full statement.
For a security issue in the site itself, or any other abuse concern, the same address reaches us: help@testmyfirewall.com. Please include timestamps with time zone, the destination address and port, and a log excerpt if you have one. That is usually enough to confirm or rule out that a connection came from here.