# TCP port checks

A TCP port check connects to a port on a host and alerts when the connection fails.

:::tip[New to Uptime?]
Start with [Get started with Uptime](/docs/uptime/).
:::

## Adding a TCP port check

In **Add check**, choose **Host doesn't respond at a TCP port** under **Alert us when…**, then fill in **Host to monitor** and **TCP port** (1–65535). If you type `host:port` into the host field, the port is filled in for you. If you leave the name blank, the check is named `host:port`.

## Watching a TLS certificate

For a TLS service, such as HTTPS, turn on **Use TLS and watch the certificate**. It's off by default. With it on, the check also opens a TLS connection and verifies the certificate against the host you entered, and it warns before the certificate expires, at 21, 14, and 7 days. The days left also show on the check's card.

:::caution[Self-signed certificates fail]
With TLS on, an invalid, expired, self-signed, or mismatched certificate makes the check down, with the message "TLS connection failed: …". Port checks can't skip verification, so leave TLS off for servers with self-signed certificates, which many VPN servers use.
:::

Check frequency, the confirmation period, and the request timeout are described in [Working with checks](/docs/uptime/checks/#settings).
