list of onion sites

List of Onion Sites: Directory of Active .onion Addresses

A list of onion sites comprises verified .onion addresses and mirrors hosted on the Tor network, each assigned a unique v3 address that routes traffic through multiple encrypted relays. This directory helps users locate legitimate onion services while avoiding phishing clones and fraudulent mirrors that mimic authentic sites.

List of Onion Sites: Verified .onion Addresses & Mirrors

What Are Onion Sites and How Do They Work

Onion sites are services accessible only through the Tor network via .onion addresses. These addresses are cryptographic hashes derived from the site's public key, making them difficult to forge or intercept. When you connect to an onion site, your traffic is encrypted and routed through a series of Tor relays, with each relay removing one layer of encryption—similar to peeling an onion, hence the name. The final relay (the exit node) never learns your real IP address because the connection terminates at the onion service itself, not on the clearnet. This architecture provides both anonymity to the user and protection to the service operator. Onion sites can host any type of content: news outlets, privacy-focused email services, discussion forums, documentation repositories, and marketplaces. The .onion domain is reserved by IANA specifically for use with Tor and cannot be accessed through standard browsers or clearnet infrastructure.

V3 Addresses vs. V2 Addresses: Why the Upgrade Matters

Tor transitioned from v2 to v3 onion addresses to address security and usability concerns. V2 addresses are 16 characters long and use 80-bit encryption, which became vulnerable to computational attacks as hardware improved. V3 addresses are 56 characters long and use 256-bit encryption, providing significantly stronger security against brute-force and cryptographic attacks. V3 addresses also include built-in protections against certain types of denial-of-service attacks and improve the integrity of the address itself. Since the Tor Project deprecated v2 support, most legitimate onion sites now operate on v3 addresses. When reviewing a list of onion sites, verify that addresses are v3 format—a long alphanumeric string followed by .onion. V2 addresses should be treated with caution, as they may be outdated or abandoned services. The transition to v3 was completed in 2021, and any active onion site should have migrated by now.

How to Identify Legitimate Onion Sites vs. Phishing Clones

Phishing clones are fraudulent mirrors designed to steal credentials, private keys, or personal data by mimicking legitimate onion sites. Several techniques help distinguish genuine addresses from fakes. First, verify the onion address against multiple trusted sources—official project documentation, PGP-signed announcements, or established directories. Legitimate sites often publish their v3 address on their clearnet homepage or in official social media accounts. Second, check for HTTPS and valid SSL certificates; while onion sites can use self-signed certificates, legitimate services typically implement proper TLS. Third, examine the site's behavior: phishing clones often have broken links, missing pages, or slightly different layouts designed to capture login attempts. Fourth, use PGP signature verification if the site publishes signed announcements—this cryptographically proves the announcement came from the site operator. Never assume an address is correct based on appearance alone. If you arrive at an onion site through a search result or link, independently verify the address by typing it directly into your browser or cross-referencing it against official sources. Bookmark verified addresses to avoid repeated searches that might lead to clones.

Common Onion Site Categories and Their Functions

Onion sites serve diverse purposes across legal and illegal domains. News organizations operate onion mirrors to provide uncensored access in countries with internet censorship. Privacy-focused email and messaging services use onion addresses to protect user communications from surveillance. Whistleblowing platforms like SecureDrop accept anonymous submissions via onion services. Documentation repositories, forums, and wikis host information on privacy, security, and technical topics. Libraries and archives preserve books and research papers. Some onion sites function as marketplaces—some legal, some illegal. Discussion communities cover topics ranging from technology to activism. Cryptocurrency services, VPN providers, and privacy tools often maintain onion mirrors. Government agencies in some countries operate onion sites for transparency. Educational institutions and researchers use onion infrastructure for secure communication. Understanding the category of an onion site helps assess its legitimacy and purpose. Legitimate sites typically have clear descriptions of their function, transparent operators, and consistent uptime. Sites that are vague about their purpose, frequently change addresses, or lack any public information should be treated with suspicion.

How to Access Onion Sites Safely Using Tor Browser

Accessing onion sites requires the Tor Browser, which is the official, recommended tool for connecting to the Tor network. Download Tor Browser only from the official Tor Project website to avoid compromised versions. After installation, launch Tor Browser and wait for it to establish a connection to the Tor network—this typically takes 10-30 seconds. Once connected, open a new tab and enter the .onion address in the address bar. The browser will route your connection through Tor relays and connect to the onion service. Do not maximize your browser window to full screen, as this can reveal your screen resolution to websites, potentially compromising anonymity. Disable JavaScript if you are connecting to an untrusted site, as malicious scripts can leak your IP address. Do not open multiple tabs to different onion sites simultaneously on your first visit; test each site individually to understand its behavior. Keep Tor Browser updated to the latest version to receive security patches. Do not install additional browser extensions, as they can interfere with Tor's anonymity protections. If a site requests you to disable Tor Browser security features, close the connection immediately—legitimate sites do not make such requests.

Verifying Onion Addresses Using PGP Signatures

PGP (Pretty Good Privacy) signatures provide cryptographic proof that an onion address announcement came from the site operator and has not been tampered with. Many legitimate onion sites publish their v3 address alongside a PGP signature on their clearnet homepage or in official communications. To verify a signature, you need the site operator's public key, which is typically published on their website or in a key server. Import the public key into a PGP tool such as GnuPG. Download the signed announcement and the signature file. Run the verification command to confirm the signature matches the announcement and the key. If verification succeeds, you can trust that the address is authentic. If verification fails, the announcement has been modified or the signature is invalid—do not use the address. This process requires some technical familiarity but provides the strongest assurance of address authenticity. Not all onion sites publish signed announcements, but high-security services, news organizations, and whistleblowing platforms typically do. Learning PGP verification is a valuable skill for anyone regularly accessing onion services.

Common Mistakes That Compromise Anonymity on Onion Sites

Several behavioral mistakes can leak your identity or location even while using Tor and onion sites. Maximizing your browser window reveals your screen resolution, which can be used to fingerprint you. Logging into personal accounts (email, social media) while connected to Tor defeats anonymity because you are voluntarily linking your real identity to your Tor session. Torrenting over Tor is ineffective and can leak your IP address because BitTorrent clients often bypass Tor. Enabling plugins like Flash or Java can bypass Tor entirely. Typing personal information into forms on untrusted onion sites can lead to social engineering attacks. Visiting onion sites through clearnet search engines or links can expose your interest in those sites to your ISP. Using the same username across multiple onion sites allows correlation of your activity. Connecting to onion sites from a network with identifying characteristics (corporate, university, home) can link your sessions to your real location. Disabling security features in Tor Browser to access a site that demands it exposes you to attacks. Keeping Tor Browser outdated leaves you vulnerable to known exploits. Treat onion site access with the same operational security discipline you would use for any sensitive activity.

Frequently asked questions

Are all onion sites illegal?

No. Many onion sites serve legal purposes: news outlets provide uncensored reporting, privacy services protect communications, whistleblowing platforms receive anonymous tips, and educational repositories share information. Some onion sites host illegal content or services, but the .onion infrastructure itself is neutral technology. Legality depends on the specific site's content and the laws of your jurisdiction.

Can I access onion sites without Tor Browser?

No. Onion sites are only accessible through the Tor network. Standard browsers cannot resolve .onion addresses. Tor Browser is the official, recommended tool for accessing onion services. Using other Tor clients or VPNs with Tor may work technically but exposes you to security risks and is not recommended.

How do I know if an onion address is real?

Verify the address against multiple trusted sources: official project websites, PGP-signed announcements, or established directories. Check for HTTPS and examine the site's behavior for signs of phishing. Legitimate sites typically have consistent uptime, clear descriptions of their function, and transparent operators. Never assume an address is correct based on appearance or a single source.

What is the difference between a v3 and v2 onion address?

V2 addresses are 16 characters and use 80-bit encryption; v3 addresses are 56 characters and use 256-bit encryption. V3 is significantly more secure against computational attacks and includes protections against denial-of-service. The Tor Project deprecated v2 in 2021. Any active onion site should now use v3 addresses.

Can my ISP see that I am accessing onion sites?

Your ISP can see that you are connecting to the Tor network, but cannot see which onion sites you visit or what data you transmit. The connection to Tor is encrypted. However, if you are on a monitored network (corporate, university), administrators may detect Tor usage. Using Tor from a home network is generally less conspicuous than from institutional networks.