Test-NetConnection: check if a TCP port is open in PowerShell
In short
- -ComputerName takes the DNS name or IP address of the target computer, and -Port takes the TCP port number on it1.
- -InformationLevel accepts Detailed or Quiet, and Quiet returns basic information such as a True or False result1.
- -CommonTCPPort tests a common service port by name, and it accepts HTTP, RDP, SMB or WINRM1.
- Microsoft's Remote Desktop guide checks port 3389 with Test-NetConnection and -InformationLevel Detailed2.
- The cmdlet supports ping, TCP, route tracing and route selection tests; -Port is a TCP port1.
To test whether a TCP port is open, run Test-NetConnection with -ComputerName for the host and -Port for the TCP port number1. Add -InformationLevel Detailed to see more fields1. Then read the TcpTestSucceeded line. Microsoft's troubleshooting guide says True indicates no connectivity issues, and False indicates connectivity issues2.
Syntax
To test a port, use the RemotePort form of Test-NetConnection. -Port is required in this form, and the other two parameters are optional1.
Test-NetConnection
[[-ComputerName] <String>]
-Port <Int32>
[-InformationLevel <String>]-ComputerNameis the DNS name or IP address of the target computer1.-Portis the TCP port number on the remote computer. The cmdlet uses it to test connectivity1.-InformationLevelacceptsDetailedorQuiet. Quiet returns basic information, such as a Boolean result1.
A second form, -CommonTCPPort, takes a service name instead of a number. It accepts HTTP, RDP, SMB and WINRM1. The cmdlet returns a NetConnectionResults object for both forms1.
Examples
Test a port on a remote computer
This is the test Microsoft's Remote Desktop guide uses. It checks TCP port 3389, the default Remote Desktop port, and shows detailed results2. Replace www.contoso.com with your host name or IP address.
Test-NetConnection -ComputerName www.contoso.com -Port 3389 -InformationLevel DetailedLook for the TcpTestSucceeded line in the output. If it is True, it indicates no connectivity issues. If it is False, it indicates connectivity issues2.
See the detailed output in full
Without -ComputerName, the cmdlet tests a default server. This example from the reference tests TCP port 80 on it1.
Test-NetConnection -Port 80 -InformationLevel "Detailed"Microsoft shows this output1:
ComputerName : internetbeacon.msedge.net
RemoteAddress : 2a01:111:2003::52
RemotePort : 80
NameResolutionResults : 2a01:111:2003::52
13.107.4.52
MatchingIPsecRules : Ipsec/Domain-TrafficFromInternet-v6
NetworkIsolationContext : Internet
IsAdmin : False
InterfaceAlias : Ethernet
SourceAddress : 2001:4898:d8:33:81e8:7b49:8bf5:8710
NetRoute (NextHop) : fe80::200:5eff:fe00:203
TcpTestSucceeded : TrueGet only True or False
Use Quiet when a script only needs the result. With Quiet, the cmdlet returns basic information, such as a Boolean value that shows whether the attempt to reach the host or port succeeded1.
Test-NetConnection -ComputerName www.contoso.com -Port 80 -InformationLevel QuietIt returns True or False1.
Test a common service port by name
-CommonTCPPort saves you from looking up the number. It accepts HTTP, RDP, SMB and WINRM1.
Test-NetConnection -ComputerName www.contoso.com -CommonTCPPort RDPIt returns a NetConnectionResults object, the same type as a -Port test1.
Common errors
TcpTestSucceeded is False. This indicates connectivity issues2. Microsoft's Remote Desktop guide suggests two next checks. First, connect with the IP address instead of the host name. If that works, the problem is likely name resolution. Then check that firewall rules allow the traffic2.
You need to test a UDP port. The cmdlet supports ping, TCP, route tracing and route selection tests. -Port takes a TCP port number1.
-Port and -TraceRoute won't work together. They belong to different forms of the command. -TraceRoute is part of the ping (ICMP) form, and -Port is part of the RemotePort form1. Run them as two separate commands.
-CommonTCPPort rejects your value. It accepts only HTTP, RDP, SMB and WINRM. For any other service, use -Port with the port number1.
The test ran against the wrong server. If you leave out -ComputerName, the cmdlet tests a default server, internetbeacon.msedge.net in Microsoft's examples1. Name your host with -ComputerName.
Questions
- Does Test-NetConnection need administrator rights?
- Microsoft's reference example of a TCP test shows IsAdmin : False next to TcpTestSucceeded : True1. Microsoft's Remote Desktop troubleshooting guide does open an elevated PowerShell window for its port test2.
- What happens if I leave out -ComputerName?
- In Microsoft's examples, the cmdlet then tests a default server, internetbeacon.msedge.net1.
- Can Test-NetConnection test a UDP port?
- The reference lists ping, TCP, route tracing and route selection tests, and it describes -Port as a TCP port number1. It lists no UDP test.
- How do I get just True or False for a script?
- Add -InformationLevel Quiet. With Quiet, the cmdlet returns basic information, such as a Boolean value that shows whether the attempt succeeded1.
23 Aug 2026: Published.