The Badge Says OFFLINE, the Site Works Fine: Inside Onion Status Whiplash
You refresh the onion status checker and a red badge stares back: OFFLINE. You open Tor Browser anyway, paste the address, and the site loads instantly. So which is it?
The honest answer is that both readings were true, just seconds apart. On Tor, availability is not a switch. It is a probability that shifts with every circuit your client builds.Six hops before the first byte
Tor is not a straight wire. As the Tor Project's rendezvous protocol specification describes, an onion service builds long-lived circuits to a handful of relays acting as introduction points, then publishes a signed descriptor listing them to hidden service directories (rend-spec, protocol overview). To connect, your client fetches that descriptor from the HSDir nodes, picks its own rendezvous relay, and contacts an introduction point. The service then dials back to the rendezvous point and the two circuits are spliced together - roughly six hops before your first page loads. That design delivers mutual anonymity: neither side learns the other's network location. It also means any single hop can time out once and work perfectly seconds later.The network rebuilds itself all day
Tor replaces circuits roughly every ten minutes by default; the MaxCircuitDirtiness setting governs this rotation, and entry guards are swapped only slowly under strict rules designed to limit churn (guard selection spec). A busy introduction point may also rate-limit or shed connections during a traffic spike. None of this means the service is gone. It means this particular path to the service failed for a moment. Congestion makes it worse. Documented denial-of-service campaigns against onion services have repeatedly degraded introduction and rendezvous handling across the network, pushing ordinary connection times well past normal limits (USENIX Security 2025). The Tor Project itself ships rate-limiting and proof-of-work defenses for exactly this reason. A single timeout tells you very little. That is the core problem with naive monitoring.Reading a badge honestly
So how should anyone interpret a status page? A few rules of thumb:- One failed probe is noise, not news.
- Repeated failures across separate circuits start to mean something.
- Sustained failure over hours usually means the service is genuinely down.
Why mirrors amplify the confusion
That discipline matters most for mirrors. Legitimate operators rotate onion addresses after takedown attempts or DDoS pressure, and scammers exploit the resulting confusion by posting "new official" links that are anything but. If a mirror flips between states across sweeps, treat it as congestion. If it stays dark for many hours, check our how-to guide for verifying fallback addresses against signed announcements. Never trust an unverified "mirror" that appears only after an outage.A status badge measures one observer's route through Tor at one moment in time. It was never meant to be a verdict.