Glossary

What is Tor?

Tor (short for The Onion Router) is a free, volunteer-run network that hides a user's identity by passing their traffic through three relays, each adding a layer of encryption. The website only sees the last relay, called the exit node. Tor is used by journalists, activists and privacy-minded people, and also by attackers who want to hide their origin.

How Tor works

Most people use Tor through the Tor Browser, a modified version of Firefox. When it connects, it picks a path of three relays from thousands run by volunteers around the world: an entry or guard relay, a middle relay and an exit relay. The browser wraps each request in three layers of encryption, one per relay, like the layers of an onion.

Each relay removes one layer and only learns the next hop. The guard knows who you are but not where you are going. The exit knows where you are going but not who you are. The website sees only the exit relay's IP address. Paths are changed regularly, and the Tor Browser is designed to make all its users look as alike as possible.

Tor also hosts onion services, websites with addresses ending in .onion that are reachable only inside the network. Traffic to them never leaves Tor through an exit relay. For a regular website, though, only exit traffic matters: every Tor visitor arrives from one of the published exit relays, alongside everyone else using that relay at the same time.

Tor vs VPN

VPN

  • One company runs the server and sees your traffic
  • Fast enough for streaming and gaming
  • Paid subscription, easy apps
  • Exit IPs are provider servers, partly known

Tor

  • Three separate volunteer relays, none sees everything
  • Noticeably slower because of the extra hops
  • Free and open source
  • Exit relay list is public and easy to check

Tor in real traffic

For most consumer businesses, Tor traffic is a small share of visits, and it is mixed. Some visitors are people in countries with censorship or surveillance, security researchers, or users who care strongly about privacy. Others are probing login pages, testing stolen cards, creating throwaway accounts or scanning for weaknesses while hiding their origin.

Because the list of exit relays is published by the Tor Project, Tor is one of the easiest anonymizers to recognize by IP. That also makes it a poor tool for large fraud campaigns: many sites challenge it by default, and exit IPs are shared by everyone on the network. Serious operators prefer residential proxies and VPNs. Tor tends to show up in low-volume, high-privacy attempts, and in reconnaissance before an attack.

What Tor traffic means at different touchpoints

TouchpointHow much it mattersA reasonable response
Reading contentLowAllow
SignupMedium, especially for rewardsAllow or verify, based on other evidence
Login to an established accountHigh if the owner never used TorStep up verification
Payment or card entryHighVerify, or block if other signals agree
Withdrawal or payout changeVery highHold for verification

How to detect and handle Tor

Checking the visitor's IP against the current list of Tor exit relays catches most Tor traffic. The harder part is policy: decide per action instead of blocking the whole network, so a privacy-minded reader is not treated like an attacker at checkout. Kavra flags Tor exits on every visit as part of its network analysis and combines that with device, behavior and account history, so the recommendation reflects the full picture. See VPN and Tor detection and how it applies to card testing.

FAQ

Frequently asked questions

Something else? Talk to our team.

Is using Tor illegal?

In most countries, no. Tor is legal open-source software, originally developed with support from the U.S. Naval Research Laboratory and now maintained by the nonprofit Tor Project. A few governments restrict or block it. What is illegal is the activity, not the tool, although some websites limit what Tor users can do because of abuse.

Can websites see that I use Tor?

Yes, in most cases. The Tor Project publishes the list of exit relays, so a site can compare your IP with it. The Tor Browser also has a recognizable profile. What the site cannot see is your real IP address or which relays you used before the exit, which is the privacy Tor is designed to provide.

Why does Tor trigger so many CAPTCHAs?

Because many unrelated people share the same exit IPs, and some of them abuse sites. IP-based security tools see high volumes and mixed behavior from each exit, so they challenge everyone on it. Systems that look at the device and behavior of each session, rather than just the IP, can let legitimate Tor users through with less friction.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.