How Tor works
Most people use Tor through the Tor Browser, a modified version of Firefox. When it connects, it picks a path of three relays from thousands run by volunteers around the world: an entry or guard relay, a middle relay and an exit relay. The browser wraps each request in three layers of encryption, one per relay, like the layers of an onion.
Each relay removes one layer and only learns the next hop. The guard knows who you are but not where you are going. The exit knows where you are going but not who you are. The website sees only the exit relay's IP address. Paths are changed regularly, and the Tor Browser is designed to make all its users look as alike as possible.
Tor also hosts onion services, websites with addresses ending in .onion that are reachable only inside the network. Traffic to them never leaves Tor through an exit relay. For a regular website, though, only exit traffic matters: every Tor visitor arrives from one of the published exit relays, alongside everyone else using that relay at the same time.
Tor vs VPN
VPN
- One company runs the server and sees your traffic
- Fast enough for streaming and gaming
- Paid subscription, easy apps
- Exit IPs are provider servers, partly known
Tor
- Three separate volunteer relays, none sees everything
- Noticeably slower because of the extra hops
- Free and open source
- Exit relay list is public and easy to check
Tor in real traffic
For most consumer businesses, Tor traffic is a small share of visits, and it is mixed. Some visitors are people in countries with censorship or surveillance, security researchers, or users who care strongly about privacy. Others are probing login pages, testing stolen cards, creating throwaway accounts or scanning for weaknesses while hiding their origin.
Because the list of exit relays is published by the Tor Project, Tor is one of the easiest anonymizers to recognize by IP. That also makes it a poor tool for large fraud campaigns: many sites challenge it by default, and exit IPs are shared by everyone on the network. Serious operators prefer residential proxies and VPNs. Tor tends to show up in low-volume, high-privacy attempts, and in reconnaissance before an attack.
What Tor traffic means at different touchpoints
| Touchpoint | How much it matters | A reasonable response |
|---|---|---|
| Reading content | Low | Allow |
| Signup | Medium, especially for rewards | Allow or verify, based on other evidence |
| Login to an established account | High if the owner never used Tor | Step up verification |
| Payment or card entry | High | Verify, or block if other signals agree |
| Withdrawal or payout change | Very high | Hold for verification |
How to detect and handle Tor
Checking the visitor's IP against the current list of Tor exit relays catches most Tor traffic. The harder part is policy: decide per action instead of blocking the whole network, so a privacy-minded reader is not treated like an attacker at checkout. Kavra flags Tor exits on every visit as part of its network analysis and combines that with device, behavior and account history, so the recommendation reflects the full picture. See VPN and Tor detection and how it applies to card testing.