Open port monitoring that shows what changed
A port scanner shows what is open now. SurfaceDiff shows which ports appeared, disappeared or changed since the previous scan.
Monitor verified domains for new public services, changed service fingerprints and unexpected exposure. No agent required.
A one-time port scan is already out of date
A scanner tells you what's open right now - a single point-in-time read. It doesn't tell you when a port appeared, because it never saw the "before". It doesn't show you the previous state to compare against. And it gives you no process for reviewing what you found or any record of the decisions made about it - run it again next month and you're starting from zero.
What SurfaceDiff detects
What changed - not the same scan again
You do not need another full list of ports. You need to know what changed.
Review incidents without hiding future changes
Acknowledge, Ignore, Resolve
These apply to one incident - the specific change that was detected. They record how that single event was handled. They don't change how future scans behave.
Mute
A separate mechanism for a specific, expected finding or exposure you've reviewed - for example, a port you intentionally keep open. Muting that stops it from re-alerting until it actually changes again.
Reviewing one incident never automatically silences a different future change - there is no single, catch-all "Accept" button that quietly mutes things you never looked at.
Shared infrastructure without duplicate noise
SurfaceDiff recognizes when monitored domains share the same server. A change on that server becomes one incident, not one repeated for every domain that happens to point at it.
Evidence and audit trail
Every incident keeps the previous state, the new state, when it was detected, its severity, who reviewed it, how it was handled, and an optional reason for the decision - a real record, not just today's dashboard view.
How it works
Verify a domain
SurfaceDiff creates a baseline
Recurring scans create new snapshots
Real changes become incidents and alerts
Who it's for
- Small infrastructure teams
- Hosting providers
- MSPs
- Agencies managing customer domains
- Companies maintaining several internet-facing services
FAQ
Is this the same as an online port scanner?
No. An online port scanner shows the current state of a target when you run it. SurfaceDiff runs on a recurring schedule against domains you've verified, and compares each scan to the previous one - so what you see is what changed, not just a fresh snapshot every time.
Does SurfaceDiff scan the full TCP port range?
Yes, scans cover the full 1-65535 TCP port range, not just a common-ports shortlist.
Can it detect a service change on an existing port?
Yes. An already-open port gets its service fingerprinted, and a change there - for example a different service or version responding on the same port - becomes its own incident, separate from the port simply opening or closing.
Will an expected open port alert every day?
No. Mark it as an expected exposure once, with a reason, and it stays quiet on future scans until it actually changes again.
Do I need to install an agent?
No. Monitoring is entirely external - nothing to install on your servers.
Why must I verify the domain?
SurfaceDiff only ever scans domains an account has explicitly added and proven ownership of via a DNS record. This is a scope boundary, not a formality - it's what keeps this a monitoring tool for infrastructure you manage, not a scanner of infrastructure you don't.
Does SurfaceDiff detect vulnerabilities or CVEs?
No. SurfaceDiff detects changes in public exposure. It does not currently perform CVE or vulnerability matching.
Related reading
- How to Monitor for New Open Ports on Your Domain
- A Real Incident: Getting Proof That a Port Closure Actually Worked
- A Real Incident: How Service Fingerprinting Triggered a fail2ban Ban
Managing this for many client domains on shared servers? See the hosting-provider setup. For the broader picture beyond ports, see external attack surface monitoring.
See what's open on your own domain, not a demo
Run a free scan on a domain you own, or create an account for ongoing monitoring.