PortSweep.io

External exposure inventory

See what is listening on the network you own.

PortSweep.io is a scheduled, authorized port-exposure service. You configure a small IPv4 list or a CIDR block of /20 or smaller. We scan the 1,000 most common ports with service detection from a dedicated scan node, then file a report you can compare over time.

No payment required during development. A unique DNS TXT record must verify before any scan is runnable.

portsweep report completed
network: 203.0.113.0/24
flags: -T3 --top-ports 1000 -sV -Pn
hosts_scanned: 12
open_ports: 34
203.0.113.10
22/tcp open ssh OpenSSH 9.6
443/tcp open https nginx 1.24
203.0.113.44
3389/tcp open ms-wbt-server

Small targets only

Submit a comma-delimited IPv4 list or a CIDR range of /20 or more specific. A /19 and larger is rejected. Combined size is capped at 4,096 addresses.

DNS TXT first

Every scan gets a unique TXT string. You publish it in DNS we can query. nmap does not run until that lookup succeeds — a checkbox alone is not enough.

Reports, not pentests

We inventory open ports and detected services. We do not run vulnerability scripts, OS fingerprinting, or exploit checks.

Scope

What PortSweep.io is for

IT and security teams use PortSweep to keep an honest picture of internet-facing listeners: forgotten RDP, stray admin panels, database ports that should never have been published, and service versions that drifted since the last review. Recurrence is bi-annual by default so the report is a change record, not a one-off curiosity.

Configure a scan in minutes

PortSweep.io is in private beta. Request an invitation, then configure a /24 or IP list, publish the unique DNS TXT for that scan, and pick the next run date.

Request an invitation