Practical Guide

How to Access Tor Hidden Services

A step-by-step overview of installing Tor Browser, understanding how .onion addresses work, and following the security practices recommended by the Tor Project when visiting hidden services.


Getting Started

Tor hidden services, also called onion services, are websites and other network resources that are reachable only through the Tor network. Unlike ordinary websites, they do not have a public IP address or a conventional domain name. The standard and recommended way to reach them is Tor Browser, a modified version of Mozilla Firefox ESR maintained by the Tor Project. It bundles the Tor client, routes all browser traffic through the Tor network, and applies a set of hardening patches designed to make users look as alike as possible.

Tor Browser should only be downloaded from the official website, torproject.org, or from the Tor Project's official distribution channels such as its GetTor email service and its listings in official app stores. Third-party mirrors, forum links, and repackaged installers are a common vector for tampered builds that silently remove the privacy protections the browser is meant to provide.

Because the download itself can be intercepted or replaced, the Tor Project signs every release with an OpenPGP key and publishes a signature file alongside each installer. Verifying that signature confirms that the file you received is byte-for-byte identical to the one the developers produced. This step is often skipped, but it is the only reliable way to detect a modified installer before it is run.

Tor Browser is available for Windows, macOS, Linux, and Android. The desktop versions behave almost identically across platforms, and the same configuration guidance applies to each. On iOS, the Tor Project recommends Onion Browser, a separate open-source project, because platform restrictions prevent a full port of Tor Browser.

  1. Download Tor Browser from the official torproject.org website. Choose the build for your operating system and language. Avoid any link that does not point to a torproject.org domain.
  2. Verify the cryptographic signature of the download. Download the matching .asc signature file, import the Tor Browser Developers signing key, and check the signature with GnuPG or an equivalent tool following the instructions on the Tor Project support site.
  3. Install and launch the browser. On desktop systems Tor Browser is self-contained and can run from a folder without a system-wide installation. Launching it starts the bundled Tor client automatically.
  4. Set the security level to "Safest". Open the shield icon in the toolbar and select Safest. This disables JavaScript on all sites and blocks several media and font features that have historically been used in browser exploits.
  5. Connect to the Tor network. Click Connect. If Tor is blocked on your network, the connection assistant can configure a bridge, which disguises the fact that Tor is being used.

Understanding Onion Addresses

An onion address is the identifier of a hidden service. Current addresses use the version 3 format: a string of 56 characters followed by the .onion suffix, for example xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.onion. Older 16-character version 2 addresses were retired in 2021 and are no longer reachable through current Tor releases.

The defining property of a v3 address is that it is self-authenticating. The address is derived directly from the service's Ed25519 public key, together with a checksum and version byte, encoded in base32. When Tor Browser connects to an onion service, it verifies that the service can prove ownership of the private key matching that address. There is no certificate authority involved, and no third party can issue or revoke an address. If the address is correct, the connection is guaranteed to reach the operator who holds the key.

Onion addresses are not part of the Domain Name System. They are never resolved by a DNS server, and no registry exists that maps them to IP addresses. Instead, Tor uses a distributed hash table of hidden service directories to locate introduction points, and the connection is built through rendezvous circuits inside the Tor network. As a result, a .onion address cannot be opened in a standard browser and does not leak a lookup to any external resolver.

Because both the client and the service communicate only through Tor circuits, neither party learns the other's network location. Traffic is end-to-end encrypted within Tor even without HTTPS, although services may also use TLS certificates.

Feature Clearnet Tor Hidden Service
Privacy Low High
Anonymity None Strong
Censorship resistance Low High
Speed Fast Moderate

Security Checklist

Tor Browser provides strong protections by default, but most of them depend on the user not undermining them. The following practices are drawn from the Tor Project's own documentation and represent the minimum baseline for using hidden services safely.

  • Keep Tor Browser updated — Security fixes for Firefox and Tor are shipped through browser updates. Running an outdated version exposes known, patched vulnerabilities. Enable automatic updates and restart when prompted.
  • Do not maximize the window — Tor Browser uses letterboxing to round the viewport to common sizes. Resizing or maximizing the window can expose your exact screen dimensions, which is a useful fingerprinting signal.
  • Do not install extra add-ons — Additional extensions change how the browser behaves and make it distinguishable from other Tor Browser users. The Tor Project explicitly advises against installing any add-ons beyond the bundled NoScript.
  • Keep the security level high — Set the security level to Safest and avoid lowering it site by site. JavaScript is the most common vector for browser exploits and for deanonymization techniques.
  • Never enter personal or identifying information — Names, email addresses, phone numbers, and reused usernames link your Tor activity to your real identity regardless of how strong the network-level anonymity is.
  • Be cautious with downloads — Documents such as PDF and Office files can contain resources that load from the internet outside Tor when opened. If you must open a downloaded file, do so on a machine that is offline or in an isolated virtual machine.
  • Verify .onion addresses from trusted sources — Because addresses are long and random, phishing clones are easy to create. Obtain addresses from the service operator's official clearnet site, signed announcements, or another channel you already trust.
  • Avoid logging into personal accounts — Signing into an account created outside Tor ties the session to your identity and often triggers security alerts or account locks from the service provider.

Common Mistakes

Most compromises of Tor users are the result of user error rather than weaknesses in the network. These four mistakes account for a large share of them.

Downloading from unofficial sources

Installers obtained from mirrors, torrents, or links posted in forums may be modified to log activity or disable protections. Download only from torproject.org or the Tor Project's official channels, and verify the OpenPGP signature before running the installer.

Enabling scripts or lowering the security level

Lowering the security level to make a site work re-enables JavaScript and other features that have been used in real-world deanonymization attacks. Keep the level at Safest, and if a site does not function without scripts, consider whether it is worth visiting at all.

Revealing identity through accounts or metadata

Logging into personal accounts, reusing usernames, or uploading files with embedded metadata such as EXIF data or document author fields defeats network anonymity. Use separate identities for Tor activity and strip metadata from any file before sharing it.

Trusting unverified onion links

Onion addresses cannot be recognized by eye, which makes phishing clones effective. Links from search results, wikis, or unsolicited messages may lead to impostor sites. Confirm every address against a source you already trust, and bookmark it once verified.