you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / tor network
26 November 2024 tor network 4 min read

Exit Policy Myths: What Tor Exit Relays Actually Do (and What They Never Touch)

Few corners of the Tor network are as misunderstood as the exit relay. It is blamed for content it never carried, mistaken for a router of onion traffic it can never see, and treated by some hosts as radioactive.

The last hop, not the whole path

A standard Tor circuit consists of three relays: a guard, a middle, and an exit. The Tor Project's own documentation describes how the client builds this circuit one encrypted hop at a time, with each relay knowing only its neighbors (Tor support portal). Only the final relay, the exit, sends traffic onto the public internet. That makes the exit the only relay whose IP address appears to destination websites. It is also the only position where traffic leaves the network at all. Everything before that point stays wrapped in layers of encryption that no single relay can unwrap. Exit relays are a doorway out, not the network's spine.

Onion traffic never touches an exit

The most persistent myth is that visiting an onion site somehow involves an exit node. It does not. The Tor Project is explicit: communication between a client and an onion service happens entirely inside the Tor network, all the time (Onion Services properties). Onion connections use a six-relay design instead: three hops chosen by the client and three by the service, meeting at a rendezvous point. No exit relay participates anywhere in that path. As the project's overview puts it, onion services avoid exit relays completely, making users immune to malicious-exit attacks (Tor community portal). If you are new to this design, our primer on onion service routing walks through introduction points and rendezvous in more detail.

What an exit policy actually controls

An exit policy is simply a list of ports and addresses an operator chooses to allow or reject on outbound connections. The default policy rejects mail ports like SMTP outright, precisely because they attract spam complaints. Policies vary widely. Some operators run reduced policies that allow only web browsing ports; others run full exits that forward nearly everything. The choice belongs to the operator alone, which is why two exits with identical bandwidth can behave completely differently toward your connection.
  • Default policy: rejects common abuse magnets such as port 25.
  • Reduced policy: allows only a handful of browsing ports.
  • Full policy: permits most outbound TCP traffic.

The abuse burden exits carry

Because exits wear the IP address of every user passing through, they inherit the blame. The Tor Project's expectations page lists what operators should anticipate: DMCA notices from movie downloads, angry ISPs after Usenet spam, and even FBI inquiries that end with an explanation and no further action (Relays FAQ). To cope, the community maintains template letters covering scenarios from brute-force login attempts to copyright claims (Tor Abuse Templates). The EFF has published a DMCA response explaining why ISPs hosting exits fall under the safe harbor of Section 512(a) (EFF legal FAQ).
The Tor Project's philosophy: abuse should be handled proactively by site administrators rather than chasing ghosts through shared infrastructure.

Misconceptions worth retiring

One recurring error is treating "exit node" and "Tor" as synonyms. Exits make up roughly 20 percent of the roughly 7,000 relays on the network, and guard and middle relays never forward anything to the open internet at all. Another myth holds that exit operators can read everything users do. They cannot decrypt HTTPS or end-to-end encryption, and onion circuits bypass them entirely. A third claims running any relay invites police raids; the EFF notes bridges and middle relays carry minimal risk in most countries (EFF Legal FAQ). The exit is the network's lightning rod, not its brain.

Why accuracy matters

Misplaced blame shapes real decisions: hosters refuse all relays because of exit horror stories, and journalists misattribute crimes to operators who merely forwarded encrypted cells. For readers checking onion service status lists, knowing that onion paths skip exits entirely changes how you evaluate any claim about where traffic went. Follow more coverage in our tor network notes.

more notes

all news ›