Dark Web Addresses
A guide for privacy-curious readers and researchers to understand dark web addresses and their usage.
Dark web addresses are identifiers for services on privacy networks rather than ordinary DNS domains. Tor uses 56-character v3 ".onion" addresses[1], I2P uses ".b32.i2p" destinations[2], and Hyphanet uses content or publisher keys[3]; we recommend verifying any address through the service operator’s regular website before opening or sharing sensitive information[4][5].
Dark Web Address Family Matrix
- Address Type
- Tor
- Suffix/Key Format
- 56-character .onion
- Resolution Model
- Client-server relays
- Identifier Target
- Onion services
- Readability
- Moderate
- Registry Status
- No central registry
- Address Type
- I2P
- Suffix/Key Format
- 52-character .b32.i2p
- Resolution Model
- Local address-book
- Identifier Target
- I2P destinations
- Readability
- Low
- Registry Status
- No central authority
- Address Type
- Hyphanet
- Suffix/Key Format
- Keys (CHK, SSK, USK, KSK)
- Resolution Model
- Key-based resolution
- Identifier Target
- Static and dynamic content
- Readability
- Variable
- Registry Status
- No DNS-style registry

What Is a Dark Web Address?
A dark web address serves as an identifier for a service hosted on an overlay network, distinguishing it from any hidden or suspicious URL. These addresses are not indexed by ordinary search engines or resolved by traditional DNS due to their unique operational requirements. The dark web is often confused with the deep web; however, the deep web encompasses all parts of the internet not indexed by standard search engines, while the dark web specifically refers to a subset of the deep web that requires special software, configurations, or authorisation to access.
For instance, Tor uses the ".onion" suffix for its services, which are based on a unique 56-character v3 onion address format. This format is a Base32 encoding of a 32-byte Ed25519 identity public key, followed by a checksum and version field[1]. I2P, another privacy network, employs ".b32.i2p" addresses that represent the full 256-bit SHA-256 hash of a destination, leading to a 52-character identifier[2]. Additionally, Hyphanet addresses are defined by keys rather than traditional DNS names, with various key types identifying different types of content[3].
Because of the architecture of these networks, a complete connection to a standard Tor onion service typically involves six relays, ensuring a level of anonymity and security for users[6]. This is in stark contrast to the way conventional websites operate, where DNS resolves addresses directly. Without the proper software like Tor or I2P, users cannot access these dark web addresses, reinforcing their exclusivity and the need for caution when navigating this part of the internet.
The Main Types of Dark Web Addresses
Understanding the primary types of dark web addresses is essential for navigating these privacy-centric networks. Each address type has its unique structure, purpose, and operational model. Below, we provide a glossary-style comparison of Tor .onion addresses, I2P .i2p hostnames, and Hyphanet content keys, along with private friend-to-friend network identifiers.
Tor .onion Addresses
- Network: Tor
- Naming Format: 56-character Base32 v3 format
- What It Identifies: Onion services, which can host websites, chat services, and more[7].
- Central Registry: No central registry exists; registrars cannot register .onion names[8].
I2P .i2p Hostnames
- Network: I2P
- Naming Format: 52-character Base32 or 56+ character encrypted LeaseSet format[2].
- What It Identifies: I2P destinations, which may include websites and other services.
- Central Registry: No central authority; human-readable names are local mappings[2].
Hyphanet Content Keys
- Network: Hyphanet
- Naming Format: Keys (CHK, SSK, USK, KSK) for identifying content[3].
- What It Identifies: Static and dynamic content, with different keys serving specific functions.
- Central Registry: No DNS-style registry exists.
Private Friend-to-Friend Network Identifiers
- Network: Various decentralised networks
- Naming Format: User-defined identifiers, often not standardised.
- What It Identifies: Peer-to-peer services, typically used within small groups.
- Central Registry: None; identification relies on user agreement and local configurations.
Dark Web Address Family Matrix
| Address Type | Suffix/Key Format | Resolution Model | Identifier Target | Readability | Registry Status |
|---|---|---|---|---|---|
| Tor | 56-character .onion | Client-server relays | Onion services | Moderate | No central registry |
| I2P | 52-character .b32.i2p | Local address-book | I2P destinations | Low | No central authority |
| Hyphanet | Keys (CHK, SSK, USK, KSK) | Key-based resolution | Static and dynamic content | Variable | No DNS-style registry |
| Private P2P | User-defined | Local peer resolution | Peer-to-peer services | Variable | None |
This comparison highlights the differences in naming formats, identification targets, and registry status across various dark web address types. Understanding these distinctions will help users navigate these networks more effectively and securely.
How Tor Onion Addresses Are Structured
Current Tor onion addresses, known as v3 addresses, consist of 56 Base32 characters followed by the ".onion" suffix. This format is derived from a service's public key, checksum, and a version byte, ensuring a unique identifier for each onion service[1]. The v3 addresses replaced deprecated v2 addresses, which used a 16-character format based on 80 bits of a SHA-1 digest. These v2 addresses are no longer functional in the current Tor network[9].
When discussing onion addresses, it is important to differentiate between several components. An onion address refers specifically to the unique identifier (the 56-character string) assigned to a service. A full onion URL includes the protocol (http or https) along with the onion address and potentially a path, providing a complete link to access the service. For instance, an example of a full onion URL might look like "exampleaddress.onion/path".
Paths in onion services are similar to traditional web URLs, directing users to specific resources or pages within the service. Subdomains can also be a part of the structure, allowing for further categorisation of services under a primary onion address. Lastly, human-readable labels often appear in directories, enabling users to identify services more easily without needing to remember complex addresses.
This understanding of the structure and components of Tor onion addresses is crucial for anyone looking to navigate the dark web safely and effectively. Knowing the differences between these terms helps users avoid confusion when accessing or discussing various onion services.
I2P, Hyphanet, and Other Non-Onion Address Formats
Not every dark web address ends in ".onion". I2P, for instance, uses ".i2p" names and Base32 destinations, while Hyphanet employs key-based identifiers such as CHK, SSK, USK, and KSK. Each of these formats operates within its own network, meaning addresses from one network generally cannot be resolved natively by another.
I2P addresses typically follow a Base32 format, containing a full 256-bit SHA-256 hash of a destination. This results in 52-character identifiers ending with ".b32.i2p". For example, a sanitized I2P address might look like "exampleaddress.b32.i2p"[2]. Importantly, I2P lacks a central naming authority; human-readable names are local mappings in users' address books. This decentralised structure can lead to potential risks, as users may be redirected to incorrect destinations by malicious jump services[2].
Hyphanet addresses differ significantly, as they are based on unique keys instead of traditional DNS names. CHK keys identify static content, while SSK keys support signed publisher namespaces. USK keys track updated editions, and human-readable KSK keys, though convenient, are vulnerable to spam and name hijacking[3]. An example of a Hyphanet identifier could be a CHK key formatted as "CHK-1234567890abcdef", showcasing its key-based resolution model.
Understanding these non-onion address formats is essential for navigating the dark web effectively. Users should remain cautious, as accessing addresses from different networks without the appropriate software may lead to connectivity issues or security risks.
Types of Services Found Behind Dark Web Addresses
The dark web hosts a variety of services, each serving distinct purposes. Below, we categorise these services to provide a clearer understanding of what users can find behind dark web addresses.
News and Publishing
Some services focus on delivering news, particularly in regions with heavy censorship. ProPublica operates a .onion site, allowing users to access investigative journalism without government interference. This is crucial for readers in oppressive regimes seeking unbiased information.
Whistleblower Platforms
SecureDrop is a well-known platform that facilitates secure communication between whistleblowers and journalists. It allows sources to share sensitive information without exposing their identities. Users should verify the onion address against the organisation's official website to ensure authenticity[4].
Search and Directories
Search engines like DuckDuckGo offer users the ability to search for .onion sites without tracking their activity. These search tools are essential for navigating the vast array of hidden services available, helping users find what they need while maintaining privacy.
Private Communication
Onion services support metadata-resistant chat applications, enabling users to communicate without revealing their identities. These services are particularly valuable for activists and journalists operating in hostile environments.
Institutional Mirrors
Some legitimate institutions, including the CIA and Facebook, maintain .onion versions of their websites. These mirrors provide a secure way for users to access information while enhancing privacy. However, users must confirm these addresses to avoid phishing attempts.
Archives
The dark web features various archives that store information, including historical data and documents not readily available elsewhere. These archives can serve as valuable resources for researchers and journalists.
Forums
Forums on the dark web allow users to discuss sensitive topics, share information, and connect with like-minded individuals. While some forums are focused on legal topics, others may facilitate illicit discussions, so users should exercise caution.
Marketplaces
Dark web marketplaces offer a range of goods and services, some of which may be illegal. While these marketplaces can be enticing, engaging in illegal transactions can lead to severe legal repercussions.
Leak Sites
Leak sites are platforms where sensitive information is published, often without the consent of the involved parties. They can expose wrongdoing but also raise ethical concerns regarding privacy and consent.
Each service category does not inherently establish legality, legitimacy, or safety. Users should approach these services with caution, verifying addresses and understanding the risks associated with dark web activities.
Directories, Gateways, Mirrors, and Look-Alike Addresses
Navigating the dark web involves understanding various address types, including directories, mirrors, gateways, and look-alike addresses. Each plays a distinct role, but they come with specific risks that users should be aware of.
Onion Directories serve as listings of .onion addresses, often providing a user-friendly way to discover services. However, just because an address is listed does not guarantee its legitimacy. Phishing attempts can occur, with malicious actors creating look-alike addresses that mimic legitimate services. For example, a directory may list several addresses for the same service, making it crucial to verify the address through official channels before engaging with it[4].
Mirrors refer to duplicate sites that host the same content as an original .onion service. While mirrors can provide redundancy and access when the primary site is down, they can also confuse users about which is the official address. Always check for consistency with the service's official communications to ensure the address is accurate.
Gateways allow users to access .onion services through the clearnet, such as Tor2web. While convenient, these gateways reduce anonymity and security since they do not route traffic through the Tor network properly[10]. Users should avoid submitting sensitive information when using such services.
Reverse Proxies offer an additional layer of anonymity by acting as intermediaries between users and onion services. However, their use can introduce vulnerabilities if not configured correctly, potentially exposing users to risks.
Look-Alike Addresses are a significant concern. Malicious actors can create addresses that closely resemble legitimate services, leading to phishing attacks. For example, an address might change a single character or use a different domain to deceive users. Always verify addresses against official sources before interacting with them.
| Address Type | Description | Main Verification Risk |
|---|---|---|
| Onion Directory | Listings of .onion addresses | Not all listed addresses are legitimate |
| Mirror | Duplicate site for an existing service | Confusion over which is the official address |
| Gateway | Access .onion services via clearnet | Reduced anonymity and potential data exposure |
| Reverse Proxy | Acts as an intermediary for onion services | Misconfiguration can lead to privacy breaches |
| Look-Alike Address | Phishing attempts using similar addresses | Users may be misled into providing sensitive info |
This table summarises the different types of addresses and their associated risks, aiding users in making informed decisions while navigating the dark web. Understanding these distinctions is key to maintaining security and privacy.
How to Verify Whether a Dark Web Address Is Authentic
Verifying the authenticity of a dark web address is crucial to avoid phishing and other malicious activities. Here’s a checklist to help ensure that the onion service you are accessing is legitimate:
Confirm on Official Clearnet Site: Always verify the onion address against the organisation’s official website. If the address differs, do not engage with it[4].
Compare Multiple Sources: Look for the onion address in several first-party announcements. If multiple reputable sources report the same address, it increases the likelihood of its authenticity.
Inspect the Complete String: A legitimate v3 onion address is a 56-character string ending in ".onion". Ensure it follows the Base32 encoding rules and includes a valid checksum[1].
Avoid Copied Directory Entries: Many users rely on directory listings which may not be up-to-date or could contain malicious entries. Always cross-reference addresses with official communications.
Beware of HTTPS and Padlocks: Just because a site uses HTTPS or shows a padlock symbol does not guarantee the site’s legitimacy. These indicators can be spoofed, and they do not prove ownership of the onion service.
Warning Signs to Watch For
Recognising warning signs can help you identify potentially fraudulent onion services. Here are some common indicators:
Character Substitutions: Malicious actors often use look-alike characters or slight variations in the address to deceive users. For example, they might replace "o" with "0" or "l" with "1".
Unsolicited Redirects: If a service redirects you to another site unexpectedly, it could be a sign of a phishing attempt. Legitimate services typically do not engage in unsolicited redirects.
Requests for Credentials or Cryptocurrency: Be wary of any service that asks for sensitive information, such as passwords or cryptocurrency payments, especially if this is not standard practice for the service.
Unusual URL Lengths or Formats: If the onion address does not conform to the expected length or format, it could be a sign of a fraudulent site.
Inconsistent Branding: If the branding or content of the site does not match what you would expect from the organisation, it may be a fake.
Poor Quality Content: Websites with low-quality content, misspellings, or broken links can indicate a lack of legitimacy. Always look for professionalism in presentation.
By following this verification checklist and being vigilant for warning signs, we can greatly reduce the risk of falling victim to fraudulent onion services.
Are Dark Web Addresses Legal and Safe?
The legality of dark web addresses, including those ending in .onion, varies significantly based on jurisdiction and the content accessed or actions taken by users. While using privacy networks like Tor is legal in many countries, the activities conducted on these networks may not be. It's crucial to understand that simply accessing a .onion site does not shield users from legal consequences if they engage in illegal activities, such as buying illicit goods or sharing prohibited content[11].
Common risks associated with dark web addresses include phishing, malware, scams, and exposure to illegal material. Users may encounter malicious sites designed to steal personal information or deliver harmful software. Additionally, there is always a risk of surveillance, as law enforcement agencies monitor activities on the dark web. For instance, the FBI has successfully tracked users through techniques that exploit vulnerabilities in user behaviour, even within the Tor network[11].
While Tor enhances privacy by obscuring a user's IP address, it does not guarantee complete anonymity. If a user inadvertently opens a downloaded file in a non-Tor application, their real IP address can be exposed[12]. Furthermore, engaging with unverified onion services can lead to deanonymization through behaviour patterns that are traceable back to the user.
To mitigate these risks, we recommend cautious navigation of the dark web. Always verify the authenticity of onion addresses, especially when they are linked to sensitive activities. Using resources like SecureDrop for secure communication is advisable, but users must ensure they are accessing the correct onion address to avoid phishing attempts[4].
In summary, while dark web addresses can provide legitimate avenues for privacy and free expression, users should remain vigilant. Understanding both the legal implications and the inherent risks is essential for a safer experience on the dark web.
Common Mistakes and Misconceptions
Treating Every Dark Web Address as a .onion Domain
People often use ".onion address" and "dark web address" interchangeably, which leads them to apply Tor-specific rules to other networks. Tor uses .onion names, I2P uses hashed .b32.i2p destinations and local address-book mappings, while Hyphanet identifies content through CHK, SSK, USK, or KSK keys[2][3]. We recommend identifying the network and address type before choosing software or assessing whether a string is valid.
Reading a v3 Onion Address Like a Conventional Hostname
A current v3 onion address encodes a 32-byte Ed25519 public key, a two-byte checksum, and a one-byte version field into 56 Base32 characters before ".onion"[1]. Unlike an ordinary domain, it cannot be shortened, corrected by intuition, or separated from the service identity without producing another address. We advise comparing the complete string exactly rather than trusting a recognisable prefix.
Trying to Use Legacy v2 Addresses
Old articles and abandoned directories may still display 16-character onion identifiers, encouraging readers to treat them as shorter alternatives. These v2 addresses were based on 80 bits of a SHA-1 digest and stopped working after v2 services were removed in Tor 0.4.5.11[9]. We should treat any 16-character onion identifier as deprecated, not as a mirror or fallback address.
Assuming a Human-Readable I2P Name Is Globally Authoritative
Readers may interpret a memorable .i2p name as the equivalent of a centrally registered web domain. I2P has no central naming authority: readable names are local address-book mappings, and a malicious jump service can redirect a name towards the wrong destination[2]. Where identity matters, we advise checking the underlying .b32.i2p destination through a trusted first-party source rather than relying on the label alone.
Expecting a Complete Dark Web Directory
Directory lists appear comprehensive because they organise many entries on one page, but no DNS-style repository contains every onion service. RFC 7686 requires ordinary DNS resolvers to return NXDOMAIN for .onion and prevents registrars from registering these names[8]. We should treat every directory as a curated snapshot and use first-party publication methods, including an organisation’s Onion-Location prompt where available[5].
Conclusions
- We should first identify whether an address belongs to Tor, I2P, Hyphanet, or another privacy network, as each requires different software and validation methods.
- Current onion services use full 56-character v3 addresses; 16-character v2 identifiers are obsolete and should be discarded[1][9].
- A familiar name, polished design, HTTPS indicator, or directory listing does not establish who operates a hidden service.
- Before entering credentials, downloading files, or sending cryptocurrency, we advise matching the entire address with a first-party publication and stopping if anything differs.
- Tor improves network privacy but cannot prevent exposure caused by unsafe downloads, identifiable behaviour, malicious pages, or unlawful activity[11][12][11].
Next, read our Tor Link Onion guide to organise the correct software and address-checking process.
Where this comes from
- Encoding onion addresses [ONIONADDRESS] - Tor Specifications
- Naming and Address Book - I2P
- Hyphanet Documentation
- Before You Submit - SecureDrop Documentation
- Understanding and using onion services in Tor Browser - Tor Project
- How do Onion Services work? - Tor Project
- Understanding .onion addresses and how onion services work - Tor Project
- RFC 7686: The “.onion” Special-Use Domain Name
- Historical special hostnames - Tor Specifications
- Tor2web: Browse the Tor Onion Services
- Audit of the Federal Bureau of Investigation’s Strategy and Efforts to Disrupt Illegal Dark Web Activities
- Tor Browser best practices - Tor Project
Dark Web Video Sites ListExplore our curated list of dark web video sites, ensuring safe access to verified content while protecting your privacy.
Dark Web Names ListExplore our curated dark web names list to discover verified onion services and enhance your online privacy with trusted resources.
Darknet AI LinkDiscover essential darknet AI links for privacy-conscious users and researchers seeking secure resources in the dark web.