Valuable Resources and Links Available on the Tor Network See the directory

Onion Web Pages: Understanding Their Structure

This guide is for tech-savvy users seeking clarity on .onion page structures and v3 addresses.

Date
Last updated
Oct 4, 2026
Editor
Julian Hawthorne
15 min read
researcher studying onion web page structure

Exploring the architecture of .onion web pages and v3 addresses.

What is an Onion Domain and How It Differs from Clearweb

An onion domain, designated by the .onion top-level domain, is a unique identifier for services hosted on the Tor network. This designation is part of the RFC 7684 standard, which outlines how onion services operate without relying on traditional DNS systems. Unlike standard web domains, onion addresses are generated using cryptographic public keys, specifically in the case of version 3 (v3) addresses, which utilize 56-character strings derived from Ed25519 public keys [2, 6].

The architectural difference between standard DNS resolution and Tor's decentralized directory system is significant. In the clearnet, domain names are resolved through a centralized system of servers, where each domain must be registered with ICANN. Conversely, onion services do not require registration; their addresses are automatically created from cryptographic keys, ensuring a higher level of anonymity for both users and service operators (2).

Routing also varies greatly between the two networks. In traditional HTTP/HTTPS routing, user requests travel through various servers, often leaving identifiable traces. In contrast, onion routing obscures users' locations by routing traffic through multiple nodes within the Tor network. Connections are established through a process involving introduction points and rendezvous points, ensuring that traffic never exits the Tor network and remains end-to-end encrypted [3, 8]. This design eliminates the need for exit nodes, which are common in standard web traffic, further enhancing privacy and security (3).

To summarize, onion domains provide a secure and anonymous way to access services on the dark web, fundamentally differing from the clearweb both in construction and routing methods. For those interested in exploring these hidden services, understanding these differences is crucial.


Anatomy of an Onion URL: Decoding v3 Addresses

Understanding the structure of a v3 onion address reveals its cryptographic foundations. A v3 onion address consists of 56 characters, which are not random strings but are derived from a combination of cryptographic components.

The core of a v3 onion address is the Ed25519 public key, which is a 256-bit key used for public-key cryptography. This key is encoded in Base32 format, making it the first part of the address. The use of Ed25519 enhances both the security and efficiency of the encryption process, as it replaces the outdated version 2 format, which was deprecated in October 2021 due to vulnerabilities [4, 2].

Following the public key, the address includes a version byte. This byte indicates the version of the onion service protocol being used. For v3 addresses, this byte is set to a specific value that signifies compliance with the latest security standards. It ensures that users connecting to the service are using the correct protocol version, which is essential for maintaining security and compatibility.

Finally, each v3 onion address contains a checksum. This checksum serves as a validation tool, ensuring that the address has not been altered or corrupted. It is calculated using a secure hashing algorithm, which adds an additional layer of integrity to the address.

To debunk the myth that these addresses are randomly generated: they are systematically created based on the aforementioned cryptographic keys and components. The deterministic nature of their generation means that every v3 address is unique and tied directly to its corresponding hidden service (2).

In summary, a v3 onion address is not just a random string but a carefully constructed identifier rooted in advanced cryptographic principles. Understanding this structure is essential for anyone looking to engage with onion services securely.


How Hidden Services Work Under the Hood

Hidden services on the Tor network operate through a sophisticated architecture involving rendezvous points, introduction points, and blinded public keys. Understanding these components is crucial for grasping how anonymity is maintained in this environment.

When you connect to a .onion service, the Tor client first establishes a circuit to an introduction point. This is a server that the hidden service operator has set up to facilitate connections without revealing their location. After establishing this initial link, the client communicates with the hidden service to negotiate a connection through a rendezvous point. This rendezvous point acts as an intermediary that allows both the user and the hidden service to connect without exposing their IP addresses to each other, ensuring that all traffic remains within the Tor network [3, 8].

The hidden service's address is derived from a blinded public key. In version 3 onion services, these addresses are based on a 256-bit Ed25519 public key, ensuring high security and integrity. This key is encoded into a 56-character string that becomes the onion address [2, 9]. The use of Ed25519 enhances the efficiency and security of the encryption process, providing a robust framework against potential attacks.

The multi-layered encryption process employed by the Tor protocol involves a three-hop circuit. This means that your data is encrypted in layers, similar to the layers of an onion. When you send a request to a hidden service, your data is first encrypted and sent through three randomly selected nodes in the Tor network before reaching its destination. Each node decrypts a layer of encryption, allowing the data to flow securely while keeping your identity hidden (3). This design effectively prevents any single node from knowing both the origin and destination of the traffic, which is a fundamental principle of Tor's privacy model.

In conclusion, the combination of introduction points, rendezvous points, and a three-hop circuit, along with the use of advanced cryptographic keys, ensures that hidden services on the Tor network provide a high level of anonymity and security. Understanding these mechanisms is essential for anyone engaging with .onion services.


Why v2 Onion Sites No longer Work

The deprecation of v2 onion sites stems from significant cryptographic vulnerabilities inherent in their architecture. Version 2 onion addresses utilized a 16-character format that was based on SHA-1 hashing, a cryptographic standard that has been deemed insecure due to its susceptibility to collision attacks (5). As a result, the Tor Project phased out v2 onion services entirely in October 2021, when stable versions of the Tor Browser adopted the more secure Tor 0.4.6.x architecture (5).

The transition from v2 to v3 onion addresses reflects a fundamental shift towards enhanced security and privacy. V3 addresses, which are 56 characters long, are derived from the Ed25519 public key cryptography system (1). This change not only improves the strength of the addresses but also mitigates the risks associated with the SHA-1 vulnerabilities. Ed25519 offers better performance and security, making it the preferred choice for modern cryptographic applications (1).

In practical terms, the vulnerabilities of v2 onion services meant that operators and users were at risk of targeted attacks. Attackers could exploit weaknesses in SHA-1 to potentially identify or manipulate hidden services, compromising the anonymity that the Tor network aims to provide. With the complete phase-out of v2 addresses, users must now utilize v3 services to ensure their communications remain secure and protected from such vulnerabilities [4, 10].

For users accessing hidden services, this means that any attempt to connect to a v2 address will result in failure, as these sites are no longer reachable. You should ensure that you are using the latest version of the Tor Browser, which only supports v3 onion addresses, to maintain your privacy and security while exploring the dark web.


Common Misconceptions About Onion Web Pages

Many believe that a .onion address represents an internet browser, but this is misleading. A .onion address is a domain suffix specifically designed for services accessed via the Tor network. The Tor browser, a specialized tool, is required to navigate these hidden services, which operate under strict privacy protocols (1).

The legal status of visiting .onion sites is generally clear. In the United States and most democratic countries, accessing these sites through the Tor browser is legal, as Tor is recognized as a legitimate tool for privacy and anti-censorship (1). However, hosting illegal content on .onion sites can lead to legal consequences, as the nature of the content, rather than the medium, determines legality. Always verify the content you are engaging with to avoid potential legal issues.

Safety myths also abound regarding the perception that merely viewing static text pages on .onion sites poses no risk. While it is true that viewing a static text page does not inherently expose your identity, you must still exercise caution. The Tor network encrypts your connection, ensuring that traffic does not leave the network (3). However, downloading files or interacting with dynamic content can expose you to malware or other security threats. To mitigate these risks, always download the Tor browser from the official torproject.org site to avoid malicious versions (1).

In summary, understanding the true nature of .onion addresses, the legal implications of your actions, and the safety measures necessary when exploring these sites is crucial for a secure experience on the dark web.


Technical Structure and Limitations of Onion Pages

The backend architecture of .onion services significantly impacts how connections are handled within the Tor network. When you access a hidden service, your Tor client initiates a connection through a series of carefully orchestrated steps. Initially, it builds a circuit to an introduction point established by the hidden service operator, ensuring that the service's actual location remains concealed. This connection is then used to negotiate a path through a rendezvous point, which allows communication without exposing the identities of either party [3, 8].

Performance bottlenecks are a crucial consideration in this setup. The reliance on multiple node relays can introduce latency, as data must traverse through several nodes before reaching its destination. Each node adds a layer of encryption, which, while enhancing security, can slow down the connection. For example, if a user's request passes through three nodes, each node's processing time and network conditions can cumulatively affect the overall latency experienced by the user. This is particularly evident during peak usage times when network congestion can exacerbate delays.

JavaScript is often restricted or disabled on onion pages for security reasons. Many hidden services aim to minimize the risk of exposing user information through scripts that could potentially leak data or exploit vulnerabilities in the Tor browser. By limiting JavaScript execution, services reduce the attack surface that could be exploited by malicious actors. This practice aligns with the Tor Project's recommendations, which emphasize the importance of maintaining user privacy and security while accessing hidden services.

Understanding these technical structures and limitations is essential for effectively navigating the dark web. When engaging with .onion services, be prepared for potential delays and recognize the security implications of the technologies involved. Always ensure that you are using the latest version of the Tor browser to maintain a secure browsing environment.


Cryptographic Verification of Onion Sites

Verifying the authenticity of an onion service is essential to avoid phishing and spoofed addresses. Use the following technical checklist to ensure secure connections.

Check the Address Format

Ensure that the onion address is a valid v3 address, which consists of 56 characters and is encoded from a 256-bit Ed25519 public key. This format replaced the deprecated v2 addresses, which are no longer accessible [2, 4].

Fetch the Service Descriptor

When connecting to a .onion site, your Tor client retrieves the hidden service descriptor. This descriptor contains the public key and other essential information about the service. Verify that the descriptor is fetched securely through the Tor network, which encrypts traffic end-to-end (3).

Validate the Public Key

The hidden service's public key is a crucial element for verification. Compare the public key embedded in the fetched descriptor with the one derived from the onion address. If they match, the service is authentic. If not, it could indicate a phishing attempt or a spoofed address.

Use Onion-Location Header

Some onion services implement the Onion-Location HTTP header to advertise their .onion counterpart. When you visit a .onion service, check for this header to ensure that it redirects you correctly. This practice can help confirm the authenticity of the site (2).

Avoid Unofficial Tor Browser Versions

To mitigate risks of malware, always download the Tor Browser from the official torproject.org site. Using unofficial builds can expose you to malicious versions that may lead to interception or spoofing attempts (1).

Monitor Connection Behavior

After establishing a connection, observe any unusual behaviors. If the service requests unnecessary permissions or behaves differently than expected, consider it a potential red flag. Always exercise caution with any interactions on onion services.

By following this checklist, you can enhance your security while navigating the dark web and interacting with onion services.

Common Mistakes and Misconceptions

Assuming Legacy Version 2 Addresses Still Function

Why do some users still attempt to access deprecated v2 links using outdated configurations? Version 2 services were officially rendered completely unreachable in October 2021 when stable versions of the Tor Browser adopted the 0.4.6.x architecture due to severe cryptographic vulnerabilities (5). Attempting to load these legacy 16-character SHA-1 based addresses will result in connection failures. Always update your software and utilize current 56-character v3 addresses built on modern cryptographic standards [2, 4].

Confusing Domain Registrations with Cryptographic Addresses

Why do administrators waste time searching for ICANN registrars when setting up hidden services? Unlike standard clearnet websites, onion services do not require operators to purchase a domain name or register with ICANN because their addresses are automatically generated from cryptographic public keys (2). This decentralized generation process uses an Ed25519 public key, a version field, and a checksum encoded in Base32 format (4). Check your configuration scripts to ensure you rely on local key generation rather than external registry services.

Believing Traffic Exits the Tor Network to Reach Onion Pages

Why do operators worry about conventional exit node surveillance when hosting hidden services? When visiting a .onion service, traffic never leaves the Tor network and there is no exit node, meaning connections are end-to-end encrypted between the user and the hidden service through a rendezvous point (3). This architecture ensures that intermediate nodes cannot intercept or decrypt your application layer data during transmission. Verify that your connection status relies purely on internal circuit paths without expecting traditional exit routing.

Downloading Tor Browser Packages from Third-Party Mirrors

Why do researchers risk compromising their systems by grabbing installation binaries from random file-sharing forums? The Tor Project explicitly highlights that the single most important safety rule for accessing onion pages is to download the Tor Browser exclusively from the official torproject.org site to avoid malware-laced fake builds (1). Unofficial distributions frequently inject malicious payloads designed to compromise your cryptographic keys and deanonymize your browsing sessions. Always verify your installation source before deploying the browser on your workstation.

Ignoring Descriptor Metadata Protection Mechanics

Why do legacy scraping scripts fail against modern hidden service architectures? Unlike legacy v2 addresses that uploaded hidden service descriptors in plaintext to centralized distributed hash tables, v3 services use key derivation and encryption to protect directory metadata and prevent mass scraping (6). This prevents malicious actors from easily indexing and mapping hidden service directories en masse. Ensure your data collection tools account for encrypted v3 descriptor retrieval protocols rather than expecting plaintext hash tables.

Summary and Actionable Takeaways

  • Prioritize 56-character v3 addresses built on modern cryptographic standards, as legacy v2 links are completely unreachable.
  • Verify hidden service authenticity by checking public keys and avoiding unofficial browser builds from third-party mirrors.
  • Account for performance latency and restricted JavaScript execution when navigating internal Tor circuit paths.
  • Read more about address syntax and formatting in Onion URLs: What They Are and How to Use Them.

Straight answers

How can I access a .onion website?

To establish a connection without leaking locations, a Tor client first builds a circuit to an introduction point, contacts the hidden service, and negotiates a mutual connection via a mutually chosen rendezvous point (7). When visiting a .onion service, traffic never leaves the Tor network and there is no exit node, meaning connections are end-to-end encrypted between the user and the hidden service through a rendezvous point (3).

Is the onion web illegal?

In the United States and most democratic countries, downloading and using a dark web browser to access .onion websites is completely legal, as Tor is recognized as a legitimate privacy and anti-censorship tool (1).

Is onion a dark web Browser?

The Tor Project explicitly highlights that the single most important safety rule for accessing onion pages is to download the Tor Browser exclusively from the official torproject.org site to avoid malware-laced fake builds (1).

Is it safe to visit onion sites?

When visiting a .onion service, traffic never leaves the Tor network and there is no exit node, meaning connections are end-to-end encrypted between the user and the hidden service through a rendezvous point (3). The Tor Project explicitly highlights that the single most important safety rule for accessing onion pages is to download the Tor Browser exclusively from the official torproject.org site to avoid malware-laced fake builds (1).

I can't access some .onion websites. Any help?

Version 2 onion services were officially deprecated and rendered completely unreachable in October 2021 when stable versions of the Tor Browser adopted Tor 0.4.6.x due to severe vulnerabilities against targeted attacks (5). Under the hood, current onion services use version 3 architecture, which relies on 56-character addresses built on an ed25519 public key, replacing the deprecated and insecure version 2 format (1).

Explore more

researcher at home office studying onion site directories

Dark Web Onion Sites: A Comprehensive Overview

Explore dark web onion sites to understand their purpose, risks, and how to navigate this hidden part of the internet safely.

person browsing onion URLs in a cafe

Onion URLs: What They Are and How to Use Them

Discover what onion URLs are, how they function, and learn safe methods to access them without prior dark web experience.