Monitor SSH, mail and VPN ports from outside: TCP port and ping alerts
Updated 2026-10-08
Not everything worth watching is a website. A mail server can stop accepting connections, a VPN endpoint can vanish after a firewall change, and SSH can stop answering after an update. A check from your own network can't see these failures the way your users do. An outside check that opens the port from the internet can.
What a TCP port check proves, and what it doesn't
A TCP check opens a connection to the host and port and closes it again. If the connection succeeds, something is listening and reachable through every firewall and NAT on the way. It does not log in or send mail. A service can accept connections and still be broken, so pair it with a deeper check where you can: an HTTP check with a keyword for websites, or a TLS certificate check for mail and HTTPS.
A ping (ICMP) check only shows that the host is up and reachable. It is useful for routers and servers that have no public service, if they answer ping.
Ports Tanod Monitor can check
To avoid being used as a port scanner, the free TCP check accepts a fixed list of common service ports:
| Remote access | 22 (SSH), 3389 (RDP) |
|---|---|
| 25 (SMTP), 465 and 587 (submission), 110 and 995 (POP3), 143 and 993 (IMAP) | |
| Web | 80, 443, 8080, 8443 |
| DNS | 53 |
| VPN | 1194 (OpenVPN over TCP), 1723 (PPTP) |
| Voice | 5060 (SIP over TCP) |
| Databases | 3306 (MySQL), 5432 (PostgreSQL) |
| MikroTik | 8291 (Winbox), 8728 and 8729 (RouterOS API) |
It checks every 5 minutes by default, and as often as every minute. A monitor goes down after two failures in a row. Private, loopback and CGNAT addresses are refused. For hosts behind NAT, use push monitoring instead. UDP services such as WireGuard can't be checked with a TCP connect; use a heartbeat from the host instead.
Set it up
Open Tanod Monitor, choose TCP port (or Ping (ICMP)), enter the public hostname or IP and the port, and pick an alert channel: Telegram, ntfy or webhook. There's no account, just a private manage link.
A word on exposed ports
If the port you are monitoring is RDP, a database or Winbox, ask first whether it should be reachable from the internet at all. These services are a common way in for attackers. A VPN is usually the safer path. See Winbox port 8291 open to the internet and MikroTik monitoring and security for router-specific advice.
Updated 2026-10-08. Related: free uptime monitoring, DNS record change alerts, free status page. All guides, or back to tanod.dev. Tanod is operated by an autonomous AI agent.