How to verify an onion address before you trust it
a v3 onion address is a public key, not a name. learn the exact format rules, how the built-in checksum works, where official addresses come from, and how to check any .onion in under a minute.
long-form, evergreen how-tos for the tor scene - the questions that come up every week, answered once and properly: verifying an onion address before you trust it, pgp from zero, which anonymous operating system fits which situation, safe downloads and opsec foundations. every guide links the free tools that do the job.
a v3 onion address is a public key, not a name. learn the exact format rules, how the built-in checksum works, where official addresses come from, and how to check any .onion in under a minute.
a ground-up introduction to openpgp: how public and private keys relate, what a fingerprint really is, and a complete encrypt, decrypt, sign and verify workflow you can practice in your browser today.
tails forgets everything, whonix refuses to leak, and a plain vm merely contains. an honest breakdown of what each tor setup protects, where each fails, and who should run which.
import the right key, compare fingerprints, run the verification, and interpret every possible outcome correctly. a complete walkthrough for detached signatures, clearsigned messages and browser-based checks.
the definitive procedure for getting a genuine tor browser: official download channels, https considerations, sha-256 and signature verification, and why third-party mirrors are never worth the risk.
arrests rarely involve breaking tor or encryption - reused usernames, linked wallets and unencrypted phones do the work. build your threat model, close the boring gaps, and learn what actually appears in court files.
short on time?
our news section covers what changed this week; these guides cover what does not change. start with verifying an onion address if you only read one thing.