Sends real packets. Use it only on hosts you run or have permission to test.
Only that protocol makes this reply: WireGuard handshake response, OpenVPN hard-reset, IKEv2 SA_INIT or notify, completed TLS handshake.
Nothing answered. A hardened WireGuard server, OpenVPN with tls-crypt, and a closed firewall look identical. Consistent with a VPN, consistent with nothing.
ICMP port unreachable, or a refused TCP connect. The address is reachable, nothing listening there.
Only the four ports in the bar were probed: a VPN elsewhere, behind port knocking, or behind a CDN stays invisible. Silence is never upgraded to a detection; no packet separates a hardened WireGuard peer from a dropped datagram. UDP probes are not retransmitted, so one lost packet reads as silence. Run it twice. The 443 certificate is read unvalidated, since an invalid one is itself the finding.