Deep Web and Dark Web

This guide is for anyone seeking to understand the deep web and dark web, their uses, and implications for online privacy.

First published: Updated: October 1, 2026Written by: Samuel Knight16 minute read

The deep web is online content that search engines do not index, including private intranets, subscription databases, and pages generated after submitting a form.[1] The dark web is the intentionally hidden part of the deep web requiring specialised software, configurations, or authorisation; Tor onion services are one example, not the entire dark web.[1][2][3]

Classification of Web Layers and Onion Link Verification

Category
Surface Web
Definition
Search-engine-accessible content
Examples
News sites, blogs
Access Method
Standard web browsers
Category
Deep Web
Definition
Not indexed for technical reasons
Examples
Corporate intranets, databases
Access Method
Requires specific access
Category
Dark Web
Definition
Intentionally hidden segment
Examples
Onion services, hidden networks
Access Method
Specialised software like Tor
Category
Onion Address
Definition
Special-use .onion domain
Examples
Secure chat, file sharing
Access Method
Tor network only
Category
Verification Checklist
Definition
Ensure authenticity
Examples
Check for established sources
Access Method
Beware of changing links and impersonation risks
A researcher analyzing deep web databases in a modern office setting.
Understanding the deep web's significance for privacy-conscious users.

Deep Web and Dark Web Glossary: Key Terms at a Glance

Understanding the terminology related to the deep web and dark web helps clarify the structure of the internet and its various layers. The following definitions focus on discoverability and network architecture rather than legal versus illegal content.

The Internet refers to the global network of interconnected computers that communicate through standardised protocols. The World Wide Web, often simply called the web, is a subset of the internet that includes websites and web pages accessed via browsers. The surface web comprises content that search engines can index, making it easily accessible to users. In contrast, the deep web consists of content not indexed for technical reasons, such as databases and private networks. The dark web is a segment of the deep web that is intentionally hidden and requires specific software, like Tor, for access. The darknet refers to networks that use specific protocols and software to enable anonymous communication. Search indexing is the process by which search engines catalogue web content for retrieval. Onion services are accessible through the Tor network and use the special .onion domain, providing various functionalities beyond illicit activities. An .onion address is a unique identifier for these services, typically consisting of 56 characters followed by the .onion suffix.

Term Definition Example
Surface Web Search-engine-accessible content News sites, blogs
Deep Web Not indexed for technical reasons Corporate intranets, databases
Dark Web Intentionally hidden segment of the deep web Onion services, hidden networks
Darknet Networks using specific protocols for anonymous communication Private chat networks
Search Indexing The process by which search engines catalogue web content Google indexing websites
Onion Service Services accessible only through the Tor network and using the .onion domain Secure chat platforms
.onion Address A special-use domain for onion services, typically containing 56 characters before the suffix example1234567890abcdef.onion

These definitions provide a framework for understanding the different layers of the internet, helping users navigate the complexities of online content.

How the Surface Web, Deep Web, and Dark Web Fit Together

The relationship between the surface web, deep web, and dark web can be visualised as nested sets. The surface web comprises content that is readily accessible through search engines, such as news sites and blogs. In contrast, the deep web includes all web content that is not indexed for technical reasons, which can encompass a wide range of resources like private corporate intranets, subscription databases, and dynamic pages that appear only after a user submits a query or form[1].

The dark web, a specific subset of the deep web, is intentionally hidden and requires special software, configurations, or authorisation to access. While the deep web is significantly broader than the dark web, authoritative sources note that reliable measurements of their respective sizes remain unclear[1]. For example, an online banking dashboard is part of the deep web, as it contains sensitive information not indexed by search engines. In contrast, a Tor onion service, which uses the .onion domain accessible only through the Tor network, exemplifies the dark web[2][4].

It's important to recognise that the popular three-layer model serves as a useful simplification rather than a literal map of the internet's structure. A public news page, accessible to everyone, resides on the surface web, while the online banking dashboard lies within the deep web. Meanwhile, the dark web, with its onion services, offers functionalities such as secure chat and file sharing, which are not limited to illicit activities[5][3]. This layered understanding helps clarify how various online resources fit together, highlighting the distinctions between accessible and hidden content.

What Is the Deep Web?

The deep web consists of online content that is not indexed by search engines for various technical reasons. This unindexed content can include pages that require authentication, such as email inboxes or cloud storage accounts. Paywalls also contribute to deep web content, preventing search engines from accessing subscription-based articles or journals. Additionally, database-generated results appear only after a user submits a search query or form, making them invisible to search engines. Furthermore, some websites use robots directives to instruct search engines not to index their pages.

Everyday examples of deep web content include:

  • Email inboxes: Accessed via personal credentials, these contain private communications that search engines cannot index.
  • Cloud storage: Services like Google Drive or Dropbox allow users to store files securely, but these files are not visible to search engines.
  • Medical portals: Patient records and appointment scheduling systems are often protected by login requirements, ensuring privacy and confidentiality.
  • Company intranets: Internal resources for employees, such as policy documents and project management tools, are not accessible from the public web.
  • Subscription archives: Academic databases like JSTOR or LexisNexis require payment or institutional access, keeping their content hidden from general search engines.
  • Private database results: Information from proprietary databases is only retrievable after specific queries, ensuring that sensitive data remains unindexed.

Most interactions with the deep web are routine and legitimate, serving various practical needs without delving into illegal activities. Understanding the deep web's structure helps clarify the distinction between accessible and hidden content, emphasising that a significant portion of online resources is not indexed for good reasons[1].

What Is the Dark Web?

The dark web refers to the segment of the deep web that is intentionally hidden and requires specialised software, configurations, or authorisation to access. One of the most well-known examples is the Tor network, which provides various services, including onion services that use the unique .onion domain. These onion services are accessible only through the Tor browser, allowing users to engage in activities that prioritise anonymity and privacy[1][2][3].

While the dark web is often associated with illicit activities like illegal marketplaces and fraud, it also serves legitimate purposes. For instance, journalists may use dark web platforms to communicate securely with sources, while whistleblowers can submit sensitive information without fear of retaliation. Additionally, individuals living under oppressive regimes may turn to the dark web to bypass censorship and access information freely. The multifaceted nature of the dark web illustrates that not all activities within this space are illegal or malicious[5][3].

Accessing the dark web necessitates a certain level of operational security. Users must ensure that their identity remains anonymous, as entering personal information can compromise their privacy. It is also crucial to be aware of the risks associated with opening downloaded files, as they may inadvertently expose the user's real IP address if opened outside the secure environment of the Tor network[6].

In summary, the dark web offers a complex landscape of both legitimate and illegitimate activities. It is a part of the deep web that enables users to navigate sensitive communications and information exchange while necessitating careful attention to security practices. Understanding the dark web's dual nature can help users approach it with informed caution and awareness of its potential benefits and risks.

Deep Web vs. Dark Web: The Main Differences

Understanding the distinctions between the deep web and the dark web is crucial for navigating online content effectively. Below is a comparison table that highlights the main differences across various dimensions:

Aspect Deep Web Dark Web
Indexing Not indexed by search engines Intentionally hidden segment of the deep web
Access Requirements Requires specific access, such as credentials or subscriptions Accessible via specialised software like Tor
Addressing Standard web addresses, no special domain Uses special .onion domain names, accessible only through the Tor network[2][4]
Intended Privacy Generally aims for privacy but not anonymity (e.g., corporate intranets, private databases) Prioritises anonymity and encryption for users[7]
Typical Users Everyday users, professionals, researchers accessing databases or private networks Users seeking anonymity, including journalists, whistleblowers, and individuals in oppressive regimes
Common Content Email inboxes, cloud storage, subscription databases, private corporate resources Onion services, illicit marketplaces, secure communication platforms
Legality Mostly legal; includes legitimate services and resources Contains both legal and illegal content; not all activities are illicit[5][3]
Risks Lower risks; primarily related to privacy breaches Higher risks; potential for engaging in illegal activities or encountering scams[8]
Examples Corporate databases, medical portals, academic journals Silk Road (historical), secure chat services, whistleblower platforms

A password-protected page typically resides in the deep web, as it requires authentication for access but does not involve the anonymity features of the dark web. Conversely, a .onion service is a hallmark of the dark web, designed for users seeking to protect their identities while accessing various functionalities[1][2].

Reliable size comparisons between the deep web and dark web are challenging due to the inherent difficulties in measuring content that is not indexed or intentionally hidden. Authoritative sources have indicated that while the deep web is broader, precise metrics remain elusive[1].

Onion Links and Onion Services Explained

An onion link is a web address that uses the .onion domain, which is a special-use domain specifically designed for the Tor network. Unlike standard websites that use normal DNS (Domain Name System) addresses, .onion addresses are not resolvable by traditional DNS servers. This means that to access a .onion site, users must connect through the Tor browser, which routes their traffic through multiple relays to maintain anonymity and privacy[2][4].

Current version 3 onion addresses consist of 56 characters, including a combination of letters and numbers, followed by the .onion suffix. Older version 2 addresses, which contained only 16 characters, are no longer functional on the current Tor network[5]. It's crucial to understand that an onion address identifies the service, while the content hosted there can vary widely, ranging from secure communication platforms to illicit marketplaces. This distinction highlights that not all activities associated with onion services are illegal[3].

Due to the dynamic nature of onion addresses, unofficial directories can often contain stale or impersonated links. We advise users to verify onion addresses through the service's official public channels rather than relying on unverified link lists or access instructions. This practice significantly reduces the risk of encountering fraudulent sites, as many users have reported difficulties in discovering and authenticating onion services[9]. Engaging with verified addresses ensures a safer experience while navigating the complexities of the dark web.

Legality, Risks, and Traceability

Accessing the dark web is not inherently illegal in many jurisdictions; however, laws can vary significantly by region. While the act of accessing the dark web might be legal, any illegal activity conducted remains illegal regardless of the network. Users should be aware that engaging in illicit activities, such as purchasing illegal items or services, can lead to serious legal consequences.

The risks associated with the deep web primarily involve credential theft and data exposure. For example, accessing sensitive information through unsecured platforms can lead to unauthorised access to personal accounts. In contrast, the dark web presents a different set of risks, including phishing attacks, malware distribution, scams, impersonation, and the potential encounter with illegal material. Research indicates that users engaging with the dark web may be more susceptible to these threats due to the anonymous nature of the environment, which can attract malicious actors[8].

Anonymity on the dark web is not absolute. Law enforcement agencies have developed sophisticated methods to trace users and operators. Investigative work, technical vulnerabilities, and seized infrastructure can all contribute to identifying individuals engaging in illicit activities. For instance, financial trails can reveal transactions linked to illegal purchases, while operational-security mistakes, such as using identifiable information, can lead to exposure. The Tor network, while designed to provide anonymity, does not guarantee perfect privacy—users can inadvertently compromise their anonymity by entering personal details or by opening downloaded files in external applications[6].

In summary, while both the deep web and dark web present unique risks, understanding the legal context and the limitations of anonymity is crucial. Users must approach both environments with caution, ensuring they do not engage in illegal activities while maintaining awareness of the potential risks.

How to Classify a Web Page: A Practical Decision Checklist

To effectively classify a web page, we can use a three-question decision tree. The questions are:

  1. Can a normal search engine index it?
  2. Is access restricted?
  3. Does it use a deliberately hidden overlay network or special address?

By answering these questions, we can determine whether a web page belongs to the surface web, deep web, or dark web.

Scenarios

  1. Gmail Inbox

    • Indexing: No, it cannot be indexed by search engines.
    • Access: Yes, access is restricted (requires authentication).
    • Overlay Network: No, it does not use a hidden overlay network.
    • Classification: Deep web.
  2. Netflix Account Page

    • Indexing: No, it cannot be indexed by search engines.
    • Access: Yes, access is restricted (requires subscription).
    • Overlay Network: No, it does not use a hidden overlay network.
    • Classification: Deep web.
  3. University Database

    • Indexing: No, it cannot be indexed by search engines.
    • Access: Yes, access is restricted (requires credentials).
    • Overlay Network: No, it does not use a hidden overlay network.
    • Classification: Deep web.
  4. Unlisted Public Page

    • Indexing: Yes, it can be indexed by search engines but is not easily discoverable.
    • Access: No, access is not restricted.
    • Overlay Network: No, it does not use a hidden overlay network.
    • Classification: Surface web.
  5. Private Intranet

    • Indexing: No, it cannot be indexed by search engines.
    • Access: Yes, access is restricted (internal use only).
    • Overlay Network: No, it does not use a hidden overlay network.
    • Classification: Deep web.
  6. .onion News Service

    • Indexing: No, it cannot be indexed by search engines.
    • Access: Yes, access is restricted (requires Tor browser).
    • Overlay Network: Yes, it uses a hidden overlay network.
    • Classification: Dark web.

Common Mix-ups

It's important to clarify common misconceptions. Not every unindexed page is part of the dark web; many are simply part of the deep web, which is not indexed for technical reasons[1]. Additionally, using incognito mode does not provide access to the dark web; it merely prevents your browsing history from being stored locally, but does not anonymise your traffic like Tor does[3]. Understanding these distinctions helps users navigate online content more effectively while recognising the differences between these web layers.

Common Mistakes and Misconceptions

Treating the Web as Three Separate Layers

People often describe the surface, deep, and dark web as stacked locations, which suggests users move between entirely separate systems. We use a set relationship instead: the dark web is an intentionally hidden subset of the broader deep web, while the surface web contains indexable material[1]. This model prevents misleading comparisons that treat the categories as equivalent in scope.

Assuming "Unlisted" Always Means Deep Web

A public page does not become deep-web content merely because few people know its address or search results omit it temporarily. We classify it by whether ordinary search engines can technically index it; pages produced only after submitting a query or form are deep-web examples[1]. This distinction is useful for unlisted documents, searchable databases, and pages without inbound links.

Assigning One Category to an Entire Website

Readers sometimes classify a whole service from one page, although different sections can have different access and indexing conditions. A public landing page may belong to the surface web, while its authenticated account area or query-generated results belong to the deep web[1]. We recommend classifying the specific page or endpoint rather than the organisation operating it.

Calling All Tor Browsing "Dark Web Access"

Using Tor Browser does not automatically mean someone is visiting the dark web. Public-web traffic normally leaves Tor through an exit relay, whereas an onion-service connection keeps both the user and service within the Tor network[10]. We classify the destination and access method together, recognising that hidden networks beyond Tor can also fall within the dark web[3].

Treating Address Authentication as Proof of Legitimacy

An onion service cryptographically confirms that the connection reached the service associated with the requested address, but this does not prove who operates it or whether its claims are honest[7]. A fraudulent operator can control and authenticate its own onion address correctly. We therefore verify the operator through first-party channels and save the confirmed address rather than judging trust from a successful connection[9].

Assuming Tor Corrects Unsafe User Behaviour

Tor Browser cannot preserve anonymity when users disclose identifying details or route other applications unsafely[6]. BitTorrent may reveal a real IP address, while additional browser extensions can create a distinctive fingerprint, leak data, or expand the attack surface[11][12]. We advise keeping the standard browser configuration and separating anonymous activity from identifiable accounts and personal information.

Before you go

What is the difference between dark web and deep web?

The deep web covers content that search engines cannot index for technical reasons, including intranets, subscription databases and pages generated after form submissions[1]. The dark web is the intentionally hidden part of the deep web that requires specialised software, configuration or authorisation[1][3].

What are the top 5 dark web sites?

There is no reliable universal list of the "top 5" dark-web sites, and untrusted rankings may contain outdated or impersonated addresses. Onion services can host websites, chats, file sharing, software updates and journalist-source systems, so we advise obtaining addresses from each operator's verified public channel[2][9].

Can the FBI track the dark web?

The FBI and other law-enforcement bodies can identify some dark-web operators and users through technical investigation, seized infrastructure and mistakes that connect activity to a real identity. Tor does not guarantee perfect anonymity, and a coordinated operation reported in March 2026 identified 440 customers while shutting down more than 373,000 fraudulent sites[6][8].

Is the deep web safer than the dark web?

The deep web is not automatically safe, but much of it consists of routine restricted content such as private intranets and subscription databases[1]. Dark-web services add discovery and authentication difficulties, while safety in either category depends on the specific operator, content and user's actions[9].

Which is bigger, the dark web or the deep web?

The deep web is necessarily broader because the dark web is one segment within it[1]. We cannot provide a reliable size ratio because authoritative sources caution that measurements of both areas remain unclear[1].

Are onion links the same thing as the dark web?

No. A .onion address identifies a service available through Tor, while the dark web also includes hidden networks that require other specialised software, configurations or authorisation[2][3].

Conclusions

  • We should first classify the individual page, checking search-engine visibility, access controls, and whether it depends on a hidden network.
  • Ordinary account portals, private databases, and internal systems are generally deep-web resources rather than dark-web destinations[1].
  • A .onion address indicates a Tor-hosted service, but it does not confirm the operator’s identity, honesty, or legality[7][9].
  • Tor can reduce direct exposure, but personal disclosures, external applications, extensions, and unsafe downloads can still undermine privacy[6][11][12].
  • We advise using verified first-party addresses, retaining the standard Tor Browser configuration, and leaving any service involving suspicious or unlawful activity.

As a next step, read Tor Link Onion to learn how onion addresses work and how to assess them before visiting.

Where this comes from

  1. Dark Web
  2. What are .onion sites and onion services?
  3. Audit of the Federal Bureau of Investigation’s Strategy and Efforts to Disrupt Illegal Dark Web Activities
  4. RFC 7686: The .onion Special-Use Domain Name
  5. Onion services - Features - Tor Browser
  6. Tor Browser best practices
  7. How do Onion Services work?
  8. Global cybercrime crackdown: over 373,000 dark web sites shut down
  9. How Do Tor Users Interact with Onion Services?
  10. What is Tor Browser and how does it work?
  11. Can I use Tor with Torrent?
  12. Can I use plugins, add-ons, or extensions in Tor Browser?