First, What Is a .Onion Version?
A .onion version is an alternative way to reach a website or online service through the Tor network.
A regular website might use an address like:
example.com
Its onion counterpart would instead use a much longer address ending in:
.onion
Having both addresses doesn’t necessarily mean there are two completely different websites. An organization can make the same articles, services, or other content available through its regular website and an onion version. The main difference is how you connect to it.
Unlike a conventional domain, a .onion address isn’t registered through the normal Domain Name System (DNS). It is a special-use domain associated with an onion service and is designed to be reached through Tor.
That distinction matters because when a legitimate organization creates an onion version, it isn’t necessarily trying to hide its website. In many cases, it’s simply providing visitors with another way to reach it—one with different privacy and network properties.

So Why Would a Legitimate Website Want One?
Creating and maintaining an onion version takes additional work, so why would an organization offer one when its regular website already works?
The answer usually isn’t that the organization wants to become “hidden.” Instead, an onion service can provide a different way of connecting to the same organization, with privacy and network properties that a conventional website doesn’t provide on its own.
1. Giving Visitors Another Layer of Privacy
Privacy is one of the clearest reasons.
When you visit an ordinary website, the connection ultimately reaches a publicly accessible server. Even if you use Tor to visit that site, the final connection normally leaves the Tor network through an exit relay before reaching the website.
An onion service works differently. The visitor connects through Tor, and the onion service is also reached through Tor. There is no Tor exit relay between them.
This design provides privacy benefits on both sides of the connection. Tor helps prevent the website from simply seeing the visitor’s real IP address, while an onion service is designed so that its own server location and IP address do not have to be publicly exposed in the usual way.
The connection between the Tor user and the onion service is also end-to-end encrypted within the Tor network. You can learn more about these privacy properties in the Tor Project’s onion services documentation.
That doesn’t mean visiting a .onion address suddenly makes someone completely anonymous. Privacy still depends on factors such as browser behavior, information voluntarily shared with a website, account logins, and how the service itself is operated.
But for organizations whose readers, customers, journalists, or other users may value additional privacy, an onion version provides something useful: another route to the service that reveals less information about the connection itself.
2. Making Censorship Harder
Another reason legitimate organizations offer onion versions is to keep information accessible when their regular websites are difficult or impossible to reach.
A conventional website relies on infrastructure such as DNS and a publicly reachable server. This gives networks and internet service providers several points where access to a domain can potentially be restricted. Onion services work differently because they are reached through the Tor network rather than through the conventional DNS route.
Imagine a reader who can visit a news organization’s regular website today, but tomorrow that domain is blocked on their network. The publication doesn’t necessarily need to create an entirely new website or move its content somewhere else. If it already operates an official onion service, that can provide another route to the information.
This is particularly relevant to journalism and access to information. The Tor Project identifies censorship circumvention and freedom of the press among the legitimate uses of onion services.
An onion address isn’t a guarantee that information will always remain accessible—Tor itself can also face blocking attempts. But it gives publishers another way to make their services available instead of depending entirely on the infrastructure of the ordinary web.

3. Protecting Journalists and Sources
Some organizations use onion services for something more specific than providing another version of their public website.
SecureDrop is a good real-world example.
SecureDrop is an open-source system designed to help news organizations receive information and documents from sources while reducing the amount of identifying information exposed during the process. Its Source Interface is provided as an onion service and is accessed using Tor Browser. The SecureDrop documentation explains that its Source Interface is an onion service that sources access through Tor to communicate with journalists and submit documents.
This is an important distinction.
A newspaper might have a regular website where millions of people read its articles. Separately, it can operate a SecureDrop onion service for people who need a more privacy-focused way to contact journalists or submit material.
In that situation, the .onion address isn’t simply a hidden copy of the newspaper’s homepage. It exists to perform a particular privacy-sensitive function.
Examples like SecureDrop help explain why it can be misleading to think of every onion address as a mysterious website trying to stay out of sight. Sometimes the technology is being used for exactly the opposite purpose: helping established organizations remain reachable while giving certain users a more private way to communicate with them.
4. Avoiding the Traditional DNS Route
Another important difference between a regular website and an onion service is how its address works.
A conventional domain such as example.com is registered through a domain registrar and relies on the Domain Name System (DNS) to help browsers find the server behind it.
A .onion address doesn’t work that way.
Onion addresses aren’t ordinary domain names that someone simply purchases from a registrar. They are generated as part of setting up an onion service, and modern onion addresses contain cryptographic information connected to that service.
This serves an important purpose. The cryptography associated with the address allows Tor to verify that a user is communicating with the onion service corresponding to that particular address. In other words, the unusual-looking address isn’t random decoration — its structure is part of how the service establishes its identity.
It’s also one reason modern onion addresses are so long and difficult to memorize. Their appearance makes much more sense once you understand that they’re doing more than the familiar name of a traditional website.
5. Keeping the Connection Inside Tor
There’s another difference that’s easy to overlook: where the connection travels.
Suppose you open an ordinary .com website using Tor Browser. Your traffic travels through the Tor network, but the destination website exists on the regular internet. To reach it, the traffic normally leaves Tor through an exit relay before continuing to the website.
A simplified version looks like this:
You → Tor Network → Exit Relay → Regular Website
An onion service works differently.
The visitor enters Tor from one side, while the onion service communicates through Tor from the other. The two establish a connection within the Tor network, so an exit relay isn’t required. The Tor Project specifically notes that onion-service traffic never leaves the Tor network.
A simplified version would look like:
You → Tor Network ← Onion Service
This difference is one of the reasons an official .onion version can offer something that simply opening the organization’s regular website through Tor cannot fully replicate.
The regular website still has value, of course. It’s easier for most people to access and works with conventional browsers. But an onion version gives an organization the option to provide a Tor-native route, where both the visitor and the service connect through Tor rather than relying on an exit relay to bridge the connection back to the ordinary web.

An Onion Version Doesn’t Mean the Website Is Hiding
The word “hidden” has probably contributed to one of the biggest misconceptions about .onion websites.
Onion services were historically known as “hidden services.” Tor now generally uses the term “onion services,” which better describes what the technology actually provides.
Why does that distinction matter?
Because using an onion service doesn’t necessarily mean an organization is trying to hide who it is.
A legitimate organization can openly operate a regular website, publish its company or organization name, maintain public social accounts, and tell visitors:
“This is our official onion address.”
There’s no contradiction there.
What the onion service can protect is different. Its design can hide the physical network location of the server and provide a Tor-based connection with particular privacy properties. That is very different from an organization attempting to conceal its identity from the public.
A useful way to think about it is:
Privacy technology ≠ secrecy of identity.
A news organization, privacy service, or other public institution may have no reason to hide who operates the website. What it may want is to give visitors another way to reach its services without relying entirely on the traditional web infrastructure.
In fact, an organization can deliberately advertise its onion address on its regular website so visitors can verify that the onion service actually belongs to it.
So seeing a .onion address shouldn’t automatically raise the question, “What is this website trying to hide?”
Sometimes a better question is:
“What privacy or accessibility benefits is this organization trying to provide?”
How Can You Know an Onion Version Is Official?
Finding a .onion address is one thing. Knowing whether it actually belongs to the organization it claims to represent is another.
You shouldn’t assume an onion website is authentic simply because it uses a familiar name, copies the design of a well-known website, or looks professionally made. Just like on the regular web, convincing copies and misleading addresses can exist.
One of the simplest ways to verify an onion address is to start with the organization’s normal, official website.
If an organization operates a legitimate onion version, it may publish the .onion address on its regular website, documentation, or another official channel. Following an address provided directly by the organization is much more reliable than trusting one copied from an unknown directory, forum, or social media post.
This matters because old directories and articles can continue circulating addresses long after an onion service has moved or disappeared, which is one reason the dark web has so many dead links.
Tor also provides a useful feature called Onion-Location.
A regular website can use Onion-Location to tell Tor Browser that an official onion counterpart is available. When properly configured, Tor Browser can display a “.onion available” indication, giving visitors a direct route from the regular website to its onion service.
This creates an important connection between the two versions:
Official website → verified onion counterpart
rather than:
Unknown source → random onion address
Of course, Onion-Location isn’t the only way an organization can publish its onion address, and not every legitimate onion website uses it. But the broader principle remains the same: verify the address through a source controlled by the organization whenever possible.

Are .Onion Versions Automatically Safer?
Not necessarily.
An onion service has specific privacy and security properties, but that shouldn’t be confused with the trustworthiness of the website itself.
For example, onion services are designed to keep connections within the Tor network, provide end-to-end encryption between the visitor and the onion service, and avoid exposing the service’s IP address in the same way as a conventional public website.
Those are meaningful technical protections. But they don’t magically make everything behind a .onion address safe or reliable.
A .onion address does not guarantee that:
- The website operator is trustworthy.
- The information published on the site is accurate.
- Files offered for download are safe.
- A website won’t attempt to collect information from visitors.
- Users cannot reveal information about themselves through their own actions.
The Tor Project’s own documentation discusses operational-security considerations for running onion services, reinforcing an important point: privacy technology still has to be used and configured appropriately.
It’s helpful to separate two ideas that are often mixed together:
Privacy of the connection is about how information travels between you and the service.
Trustworthiness of the website is about who operates it, what it provides, and how it handles its users.
An onion service can strengthen the first without guaranteeing the second.
That’s why an official onion website operated by an organization you already recognize is fundamentally different from assuming that an unfamiliar site is trustworthy simply because its address ends in .onion.
The technology can provide a more private way to connect. Trust still has to be earned.
Why Not Just Use HTTPS?
At this point, you might wonder: if modern websites already use HTTPS, why would they need an onion version at all?
The answer is that HTTPS and onion services solve overlapping, but different, problems.
HTTPS encrypts the connection between your browser and a website. It also uses the public certificate system to help your browser verify that it is communicating with the domain it intended to reach. That’s an essential part of security on the modern web.
But HTTPS doesn’t change the basic architecture of the regular internet. The website still has a conventional domain, relies on normal internet infrastructure, and connects through a publicly reachable server.
An onion service adds different properties.
The service can operate without publicly exposing its server location in the usual way, and visitors reach it through Tor rather than through the normal route used to access a public website. Onion-service connections also remain within the Tor network and are end-to-end encrypted between the Tor client and the onion service.
So it isn’t particularly useful to think of this as:
HTTPS vs. .onion — which one is better?
For a legitimate organization, the more relevant question is:
Why offer both?
The regular HTTPS website provides the familiar, convenient route that almost anyone with a browser can use.
The onion version provides an alternative for people who specifically want the privacy and routing properties offered by Tor.
That’s why the two can exist side by side. An onion service doesn’t have to replace a normal HTTPS website—it can complement it.

Why Don’t More Websites Offer Onion Versions?
If onion services can provide additional privacy, censorship resistance, and a Tor-native way to reach a website, there’s an obvious question:
Why doesn’t every major website have one?
The simple answer is that an onion service isn’t necessary for every website or every audience.
Running one means maintaining another access route alongside the regular website. That can involve additional configuration, monitoring, Tor-specific administration, security considerations, and ongoing maintenance. Organizations also have to make sure their onion address is published correctly so visitors can distinguish the official service from an imitation.
When that infrastructure is no longer maintained, the service may become unreachable or disappear entirely. We explored why onion websites disappear and why some can eventually return in a separate guide.
There’s also the question of who will actually use it.
Most internet users still access websites through conventional browsers and ordinary domains. Someone checking the weather, reading a recipe, or shopping online may have little reason to look for an onion version of the same service.
Performance expectations can be different as well. Onion-service connections travel through multiple relays and are designed primarily around privacy rather than providing the shortest possible route between a visitor and a server. As a result, the experience may not always feel identical to visiting the regular website.
So offering an onion version is ultimately a trade-off.
For a news organization serving readers in places where information may be restricted, a platform dealing with privacy-sensitive communications, or an organization whose audience already uses Tor, the additional work may make sense.
For an ordinary website whose visitors have little need for those protections, it may not.
The Bigger Picture: .Onion Doesn’t Automatically Mean “Illegal”
The .onion ending tells you how a service is reached, not whether the people behind it are doing something legal or illegal.
That’s an important distinction because onion addresses are often discussed only in connection with the dark web’s criminal side. While illegal services do exist, the technology itself isn’t limited to any particular type of content or activity.
An onion service is simply a service made available through the Tor network. What matters is what that service actually does.
The Tor Project documents several legitimate uses of onion services, including anonymous publishing, file sharing, communication between journalists and sources, and more private ways to reach popular websites.
This is why the presence of a .onion address alone tells you very little about the purpose of a website.
A news organization might use one to make its reporting available through another route. A whistleblowing platform might use onion technology to reduce identifying information exposed during communication. Another organization might simply want to offer privacy-conscious visitors an alternative to its regular website.
None of this means every onion website should automatically be trusted. As we’ve already covered, the privacy properties of the technology and the trustworthiness of the people using it are two separate questions.
And that is perhaps the most useful way to understand legitimate .onion websites.
Rather than asking whether the dark web itself is “good” or “bad,” look at the individual service: who operates it, what purpose it serves, and whether its onion address can be verified through an official source.
A .onion address describes the route.
What exists at the end of that route is what determines its purpose.
Frequently Asked Questions
Are .onion websites illegal?
No. A .onion address is simply part of Tor’s onion-service system. Using one does not automatically make a website illegal.
Just like websites on the regular internet, what matters is what the service does, what content or activity it provides, and the laws that apply in the relevant jurisdiction. Legitimate organizations can operate onion services for privacy, journalism, censorship resistance, or other lawful purposes.
Can a normal website also have a .onion address?
Yes. A public website can operate both a conventional domain and an official .onion counterpart.
The regular website might serve most visitors, while the onion version provides another way to access the organization’s content or services through Tor. The two versions can offer substantially the same content, although an onion service can also be created for a specific purpose, such as private communication.
Do .onion websites need HTTPS?
Onion services already provide end-to-end encryption between the Tor client and the onion service, so HTTPS isn’t required to provide that particular encryption property.
Some onion services may still use HTTPS for additional reasons, but seeing http:// at the beginning of an onion address doesn’t have exactly the same meaning as encountering an unencrypted HTTP website on the ordinary web.
The important distinction is that onion-service traffic receives encryption and authentication properties from the onion-service protocol itself.
Can Google index .onion websites?
Google’s normal search index is built primarily around websites accessible on the public web. .onion services require access through Tor and aren’t handled like ordinary .com, .org, or other publicly reachable websites.
That is one reason finding onion services works differently from searching the regular web. Specialized directories, official website references, and other discovery methods play a much larger role.
We’ve explained this in more detail in [How Search Engines Cannot Index the Dark Web], including why conventional crawlers struggle with onion services and why dark-web search works differently.
A Different Way to Think About .Onion Websites
Seeing a familiar organization behind a long, unfamiliar .onion address can look strange at first. We’re used to simple domains ending in .com or .org, while onion addresses seem to belong to an entirely different part of the internet.
But an onion address doesn’t necessarily mean the organization behind it is trying to disappear.
In some cases, the purpose is almost the opposite. A news organization may want readers to have another route to its reporting. A newsroom may want sources to have a more private way to communicate. Another service may simply want to offer users an alternative that doesn’t depend entirely on the infrastructure of the ordinary web.
That doesn’t make every onion service trustworthy, nor does it make Tor the right choice for every website. It simply shows why legitimate organizations sometimes decide that maintaining an onion version is worthwhile.
The long address, unusual routing, and absence of traditional DNS can make an onion service look mysterious from the outside. Underneath, however, it’s still a way for one computer to provide a service to another — just using a network designed around a different set of privacy assumptions.
And perhaps that’s the easiest way to understand why legitimate .onion websites exist:
Sometimes an onion address isn’t about hiding a website. It’s about changing what the connection reveals.

