Helpful Resources and Links within the Tor Network See the directory

Onion Tor Websites: What Are They?

This guide is for beginners and intermediate users seeking to understand onion Tor websites and how to access them safely.

First published: | Last updated: October 9, 2026 | By: Evelyn Hart

A person examining a list of onion websites on their laptop in a cozy living room.
Exploring the world of onion websites from the comfort of home.

Onion Tor websites are services accessible only through the Tor network, identified by addresses ending in .onion instead of standard domains like .com or .org. These addresses are cryptographic keys—56 characters long for version 3 sites[1]—that simultaneously serve as the URL and authenticate the connection without requiring certificate authorities[2]. Key characteristics:

  • Hidden location: The server's IP address remains concealed, protecting operators from censorship and identification[3]
  • End-to-end encryption: All traffic is encrypted by default, making HTTPS technically redundant[3]
  • Self-authenticating: The .onion address itself proves you're connected to the intended service, not an impostor[3]

What Are Onion Tor Websites?

Onion Tor websites, also known as hidden services, are specific types of websites that can only be accessed through the Tor Browser. Unlike traditional websites on the clearnet, which utilize standard domain names like .com or .org, onion sites use addresses that end with the .onion suffix. These addresses are generated from cryptographic keys, specifically a 32-byte ed25519 public key, resulting in version 3 onion addresses that are 56 characters long[1]. The structure of an onion address includes a checksum and a version field, ensuring both security and integrity[4].

One of the primary distinctions between onion sites and regular websites is their anonymity. Both the users accessing these sites and the operators hosting them remain anonymous due to the hidden nature of their IP addresses. This feature makes it significantly more challenging for adversaries to censor the content or identify the individuals behind the services[3].

Traffic between users and onion services is end-to-end encrypted by default, which means that secure connections do not require HTTPS certificates, although some onion services may still use them for additional validation[3]. This built-in encryption ensures that communications remain private and secure from external scrutiny.

The self-authenticating nature of onion addresses adds another layer of security. When a user connects to a .onion site, the address itself serves as proof of authenticity, verifying that the connection is legitimate and not a phishing clone[3]. This mechanism eliminates the need for traditional certificate authorities, as the address corresponds directly to the public key used to establish the connection.

Exploring onion sites can provide access to various services and information not typically available on the clearnet, making them an intriguing aspect of the internet for those interested in privacy and anonymity. However, caution is advised, as navigating these hidden services can come with risks, including link rot and potential exposure to illegal content.


How Onion Addresses Work

.onion addresses are designed as long random strings that function as cryptographic keys rather than traditional domain names. The latest version 3 addresses are 56 characters long, derived from a 32-byte ed25519 public key encoded in base32 format. In contrast, deprecated version 2 addresses were only 16 characters long[1]. This significant length increase enhances security, as longer keys are generally more resistant to brute-force attacks.

The structure of an onion address includes a checksum and a version field, which is critical for maintaining integrity and authenticity. The formula for generating an onion address is: onion_address = base32(PUBKEY | CHECKSUM | VERSION) + ".onion". Here, the PUBKEY is the public key, the CHECKSUM is derived from a SHA3-256 hash, and the VERSION indicates the address type[4]. This self-authenticating feature means that the address itself verifies the connection to the intended service, which reduces reliance on external certificate authorities[3].

For security, all traffic between users and onion services is encrypted end-to-end by default, making HTTPS unnecessary, although some services may still opt for HTTPS certificates for additional validation[3]. The encryption provided by the onion service protocol ensures that users are connected to the correct domain without needing a certificate authority, as the address is linked directly to the public key used for the connection[2].

Vanity addresses, which are custom .onion addresses chosen for their memorability, can be created but are generally limited by the random nature of address generation. This aspect can lead to a trade-off between memorability and security, as more predictable addresses may be easier to attack.

The combination of cryptographic keys, self-authenticating addresses, and built-in encryption contributes to the robustness of onion services, making them a secure option for anonymous communication and information sharing on the Tor network.


Types of Websites Available on Tor

Onion Tor websites encompass a wide range of categories, catering to various needs and interests. Some notable legitimate categories include:

News Sites

Several reputable news organizations maintain onion versions of their websites. For instance, ProPublica and the BBC provide access to their journalism through .onion domains, ensuring that users can access critical information while remaining anonymous.

Privacy Tools

There are numerous tools designed to enhance user privacy on the internet available on Tor. These tools often include encrypted messaging services and secure file-sharing platforms, allowing users to communicate and share data without compromising their anonymity.

Forums

Many forums exist on the Tor network, where users can discuss a variety of topics, from technology to political activism. These platforms often emphasize user privacy and free speech, creating a space for open dialogue without fear of censorship.

Whistleblowing Platforms

Onion services also host platforms designed for whistleblowers to share sensitive information securely. These services emphasize anonymity and provide secure channels for individuals to report misconduct or corruption without revealing their identities.

While the Tor network hosts legitimate services, it is important to acknowledge the existence of illegal marketplaces. These sites often facilitate the sale of prohibited goods and services. Accessing such marketplaces carries significant legal risks and ethical considerations.

Certain types of websites cannot be accessed through Tor. For example, many mainstream websites block Tor exit nodes to prevent anonymous access. This limitation means that users may face difficulties accessing popular services like social media or banking websites while using the Tor network. Consequently, the experience on Tor is distinct from navigating the clearnet, requiring users to adapt to the unique offerings available in this space.


How to Access Onion Tor Sites

Accessing onion sites requires the use of the Tor Browser, a specialized web browser designed to facilitate anonymous browsing. Installation of the Tor Browser is necessary, but specific steps for installation are not detailed here. Once installed, users can enter .onion URLs directly into the browser’s address bar. It is important to note that regular web browsers, such as Chrome or Firefox, cannot access these sites due to the unique nature of the .onion domain.

When using the Tor Browser, visiting a .onion address connects users to hidden services on the Tor network. This connection is secured through end-to-end encryption, ensuring that communications remain private and protected from external scrutiny[3]. The self-authenticating feature of .onion addresses further enhances security, as the address itself verifies the legitimacy of the service being accessed[3]. Users should be cautious, as link rot may occur, causing some addresses to become inactive over time.

For mobile users, there are options available to access onion sites. The Onion Browser is a popular choice for iOS devices, while Android users can utilize Orbot to route their internet traffic through the Tor network. Both options facilitate the anonymous browsing experience similar to that provided by the Tor Browser on desktop systems.

Exploring onion sites can lead to various resources and services not found on the regular internet, but users must proceed with caution to avoid potential risks associated with the deep web.


Finding Legitimate Onion Sites

Google does not index .onion sites due to their unique nature and the privacy-focused design of the Tor network. Search engines typically rely on web crawlers to gather information from the clearnet, but .onion sites are hidden services that cannot be accessed without specific software like the Tor Browser. As a result, users must rely on alternative methods to find legitimate onion sites.

Onion directories and link lists serve as resources for discovering these hidden services. However, users should be cautious of link rot, where links become inactive over time. Many directories may not be regularly updated, leading to dead links or outdated information. It is important to verify the authenticity of any onion address before accessing it.

Specific onion search engines, such as Ahmia and Torch, have been developed to help users find .onion sites. These search engines index onion services and provide a more structured way to search for content within the Tor network. However, the accuracy and comprehensiveness of these engines can vary, and they may not cover all available services.

To avoid phishing clones, users should verify the authenticity of onion addresses before connecting. One way to do this is by checking whether the address matches the expected format of a v3 onion address, which is 56 characters long[1]. Additionally, utilizing well-known and reputable onion services can help minimize the risk of encountering malicious sites. Always ensure that the connection is established with the correct .onion address, as the self-authenticating nature of these URLs provides a layer of security against impersonation[3].


Safety and Security Considerations

Navigating onion sites presents various risks, including phishing clones, malware, and scams. Phishing clones are deceptive sites that mimic legitimate onion services, potentially tricking users into revealing personal information. Malware can be embedded in downloads or links, leading to compromised devices. Scams are prevalent, with fraudulent services promising access to exclusive content or products that do not exist.

To enhance safety while exploring onion sites, several practices are advisable. Verifying URLs through official channels is critical; users should cross-reference addresses with trusted sources before accessing them. Avoiding downloads from unknown sources reduces the risk of malware infections. Disabling JavaScript is also recommended unless necessary, as it can be exploited by malicious actors to execute harmful scripts.

While the Tor network provides anonymity by hiding IP addresses, it does not guarantee protection from malicious content. Users can still encounter harmful sites that may compromise their security. The built-in cryptographic features of onion addresses help ensure authenticity, but they do not replace the need for cautious browsing.

Using a VPN in conjunction with the Tor Browser can add an extra layer of privacy. However, it is essential to select a reputable VPN that does not log user activity. This combination can help obscure user data from potential surveillance, although it is not a foolproof solution against all threats.

Practicing these safety measures can significantly mitigate risks associated with onion sites, enabling a more secure experience while exploring the deep web.


Why Onion Links Break and Disappear

Onion links can become inactive for several technical reasons, primarily due to link rot. This phenomenon occurs when websites go offline, often due to the lack of persistent hosting solutions. Unlike traditional websites on the clearnet, .onion sites do not rely on Domain Name System (DNS) services. Instead, they use a distributed hash table to locate services, which can lead to challenges in maintaining consistent uptime[5]. When a site’s operator decides to take it down or the server hosting the service becomes unavailable, the link can break.

Directories of onion sites often become outdated quickly. Many rely on user submissions or community contributions, which may not be regularly updated. As a result, links that were once functional may lead to dead ends. For example, it is not uncommon for directories to have a significant proportion of inactive links, reflecting the transient nature of many onion services[6]. The dynamic environment of the Tor network means that even reliable services can change their addresses or go offline without notice.

There is a difference between temporary downtime and a permanent shutdown. Temporary issues may arise from server maintenance or network problems, allowing sites to become accessible again after a brief period. In contrast, a permanent shutdown often indicates that the operator has ceased service altogether, which can happen for various reasons, including legal pressures or a loss of interest.

Realistic expectations for link longevity are essential for users exploring the Tor network. While some services may remain operational for extended periods, others might only be available for a few weeks or months. Regularly checking the status of links and relying on updated directories can help mitigate frustrations associated with link rot. Users should be prepared for the possibility that many onion links may not remain active indefinitely.


Common Technical Questions About Onion Sites

Do onion sites need HTTPS?

Onion sites do not require HTTPS for security because the Tor protocol provides built-in encryption. All traffic between Tor users and onion services is end-to-end encrypted by default. This means that communications remain private and protected from external scrutiny without needing additional protocols like HTTPS[3]. Some onion services may still opt to use HTTPS certificates for added validation purposes, but this is not a necessity for secure communication[7].

Can two sites share the same address?

No, two onion sites cannot share the same address. Each onion address is uniquely generated using a cryptographic formula that includes a public key and a checksum[4]. This makes it cryptographically impossible for two different services to have the same .onion address. With version 3 onion addresses being 56 characters long, they incorporate a full 32-byte ed25519 public key, ensuring uniqueness and security[1].

Is there DNS on Tor?

The Tor network does not use traditional DNS. Instead, it utilizes a method called onion routing, which allows for anonymous communication without revealing the user’s location or the service’s IP address[3]. When a client wants to connect to an onion service, it retrieves the service's descriptor from a distributed hash table, which contains the necessary information to establish a connection[5]. This system differs significantly from DNS, as it does not rely on centralized domain name resolution. Consequently, users should be aware that accessing onion services involves different mechanisms compared to standard web browsing on the clearnet.

Comparison of Clearnet Domains vs Onion Addresses

Type
Clearnet Domain
Structure
.com, .org, etc.
Length
Varies
Authentication Method
15-63 characters
Indexability
Certificate Authorities
Persistence
Indexed by search engines
Depends on hosting
Type
Onion Address
Structure
.onion
Length
Base32 encoded
Authentication Method
56 characters (V3)
Indexability
Self-authenticating
Persistence
Not indexed
Link rot common

Common Mistakes and Misconceptions

Assuming HTTPS is required for onion site security

Many users believe that onion sites need HTTPS to ensure secure communication, similar to clearnet websites. This assumption stems from standard web browsing practices where HTTPS indicates encrypted connections. However, all traffic between Tor users and onion services is end-to-end encrypted by default, making HTTPS unnecessary for security[3]. The Tor protocol itself provides peer-to-peer encryption, which means no additional certificates are needed for secure communication[7]. Some onion services still implement HTTPS for additional validation purposes, but this does not enhance the fundamental security already provided by the Tor network[2].

Treating onion addresses like regular domain names

Users often expect onion addresses to function similarly to clearnet domains, assuming they can be registered, transferred, or managed through traditional domain registrars. In reality, onion addresses are automatically generated using a cryptographic formula that includes a public key and checksum[4]. The address itself is derived from the service's ed25519 master public key, making it impossible to choose a custom address or purchase one like a .com domain[3]. This self-authenticating mechanism means the address verifies the legitimacy of the service without requiring external certificate authorities[3]. Attempting to "register" or "buy" an onion address through third-party services typically leads to scams.

Believing all onion links are permanent

A widespread misconception is that once an onion address is published, it will remain accessible indefinitely. Users frequently bookmark onion links expecting them to work months or years later, only to find them inactive. Onion services rely on the operator maintaining the server and keeping it online, and many services shut down without notice due to technical issues, legal pressures, or loss of interest. The distributed hash table system used to locate services does not guarantee persistent hosting[5]. Directories tracking onion services often contain a significant proportion of inactive links, reflecting the transient nature of many hidden services[6]. Users should verify link status regularly and expect that many onion addresses will eventually become unreachable.

Confusing anonymity with immunity from malicious content

Some users assume that because the Tor network provides anonymity by hiding IP addresses, they are automatically protected from all threats while browsing onion sites. This belief can lead to careless behavior, such as downloading files from unknown sources or entering personal information on unverified sites. While the cryptographic features of onion addresses ensure authenticity of the connection[3], they do not prevent exposure to phishing clones, malware, or scams. The end-to-end encryption protects the communication channel but does not filter or sanitize the content being transmitted[3]. Users must still exercise caution, verify site authenticity, and avoid risky actions regardless of the anonymity provided by Tor.

Expecting search engines to index onion content

Users familiar with clearnet browsing often attempt to find onion sites using Google or other mainstream search engines, assuming these services index all web content. This approach fails because .onion addresses exist outside the traditional DNS system and cannot be crawled by standard search engine bots. The privacy-focused design of the Tor network intentionally prevents such indexing to protect service operators and users[3]. While specialized onion search engines like Ahmia and Torch exist, they provide limited coverage compared to clearnet search engines and may contain outdated or inactive links. Relying solely on these tools without verifying addresses through trusted sources increases the risk of encountering phishing clones or dead links.

Misunderstanding address collision risks

Some users worry that two different onion services might accidentally generate the same address, leading to confusion or security vulnerabilities. This concern reflects a misunderstanding of how onion addresses are created. Each version 3 onion address is 56 characters long and incorporates a full 32-byte ed25519 public key encoded in base32 format[1]. The address is generated using a cryptographic formula that includes the public key, checksum, and version field[4]. This makes it cryptographically impossible for two different services to share the same .onion address. The mathematical probability of a collision is so astronomically low that it represents no practical risk to users or service operators.

Key Takeaways

  • Onion addresses are self-authenticating cryptographic identifiers, not traditional domain names that can be registered or purchased through third parties.
  • All traffic between Tor users and onion services is end-to-end encrypted by default, making HTTPS unnecessary for security purposes.
  • Link rot is common on the Tor network due to lack of persistent hosting, meaning many onion addresses become inactive without notice.
  • Anonymity provided by Tor does not protect against malicious content, phishing clones, or malware hosted on onion sites.
  • Mainstream search engines cannot index .onion addresses because they exist outside the traditional DNS system and require specialized Tor search tools.

For practical guidance on locating active onion services and avoiding outdated links, see List of Onion Sites: What You Need to Know.

Things readers ask

What is an onion link?

An onion link is a special web address ending in .onion that can only be accessed through the Tor Browser. The address itself is a cryptographic identifier generated from the service's ed25519 public key, encoded in base32 format[4]. Version 3 onion addresses are 56 characters long and serve as both the location and authentication mechanism for the hidden service[1]. Unlike regular domain names, onion addresses cannot be purchased or registered through traditional registrars because they are automatically generated by the cryptographic protocol[3].

Why are onion addresses so long and random?

Version 3 onion addresses are 56 characters long because they contain a full 32-byte ed25519 public key encoded in base32 format[1]. The address is generated using the formula: onion_address = base32(PUBKEY | CHECKSUM | VERSION) + ".onion", where PUBKEY is the 32-byte master public key, VERSION is a one-byte version field, and CHECKSUM is derived from a SHA3-256 hash[4]. This length ensures cryptographic security and makes it impossible for two services to share the same address. The seemingly random appearance reflects the mathematical output of the public key encoding process rather than human-readable naming conventions.

What is an onion search engine?

An onion search engine is a specialized tool that indexes .onion addresses and allows users to search for hidden services within the Tor network. Unlike mainstream search engines such as Google, which cannot crawl .onion sites due to their existence outside traditional DNS[3], onion search engines operate within the Tor network to catalog accessible services. Examples include Ahmia and Torch, though their coverage remains limited compared to clearnet search engines. These tools often contain outdated or inactive links because many onion services shut down without notice, and the distributed nature of the network makes comprehensive indexing difficult[6].

Why do onion links keep dying?

Onion links frequently become inactive because they rely entirely on operators maintaining servers and keeping them online, with no centralized hosting infrastructure to ensure persistence. Many services shut down due to technical issues, legal pressures, loss of interest, or intentional closure without public announcement. The distributed hash table system used to locate services does not guarantee persistent hosting[5], and directories tracking onion services often contain a significant proportion of inactive links reflecting this transient nature[6]. Unlike clearnet domains with stable hosting providers, onion services can disappear immediately when the operator stops running the server.

How do I know an onion site is real?

The Onion Service protocol validates that the user is connected to the correct domain name without requiring a certificate authority, because the name of the service is the actual public key used to authenticate the underlying connection[2]. The cryptography involved in .onion URLs lets Tor ensure that it is connecting to the right location and that the connection is not being tampered with[3]. However, this only confirms the connection matches the address entered, not whether the address itself belongs to the intended service. Users must verify addresses through trusted sources, official announcements, or secure channels, as phishing clones can create legitimate-but-different onion addresses to impersonate popular services.

Is there DNS on Tor?

The Tor network does not use traditional DNS for resolving .onion addresses. Instead, when a client wants to contact an onion service, it downloads the descriptor from a distributed hash table, which contains the set of introduction points and the public key needed to establish connection[5]. This system operates independently of centralized domain name resolution and does not reveal the service's IP address or location[3]. The distributed hash table replaces DNS functionality by storing service descriptors across multiple relays, allowing clients to retrieve connection information without exposing either party's network identity.

Do onion sites need HTTPS certificates?

Onion sites do not require HTTPS certificates for security because all traffic between Tor users and onion services is end-to-end encrypted by default[3]. The Onion Service protocol provides peer-to-peer encryption, meaning no additional certificates are needed for secure communication[7]. Some onion services still implement HTTPS for additional validation purposes, though most Certificate Authorities do not support issuing X.509 certificates for .onion addresses because it is a special top level domain[2]. The built-in encryption of the Tor protocol makes HTTPS redundant for protecting communication channels.

Explore More About Onion Sites

Discover additional resources and deepen your understanding.

Learn More