- Home
- Built-in Tools
- Tor Relay Lookup
Last updated: · By Ned Walsch
Tor Relay Lookup: Is This IP a Tor Relay or Exit Node?
Enter an IP address, relay fingerprint, nickname or AS number to see whether it is a Tor relay or exit node in the Tor Project’s current network data: running state, flags, exit policy, operator family, bandwidth, version and contact. The data comes straight from the Tor Project’s Onionoo service, which covers relays seen in the past 7 days; for older dates the page builds a pre-filled ExoneraTor link. A batch mode checks up to 200 IPs at once without sending your list anywhere.
onionoo.torproject.org (no Max Intel server in between). Batch mode downloads the public relay list once and matches your IPs locally, so the list you paste is never sent. ExoneraTor is only linked to, never contacted by this page. Nothing is stored.Was this IP a Tor relay on a specific date?
Onionoo only knows relays that ran in the past week Tor Project: Onionoo protocol specification (read 10 Oct 2026). For any earlier day, the Tor Project’s ExoneraTor checks its archive of relay lists and answers whether a relay was running on that IP address on or within a day of the date, and whether it allowed exiting Tor Project: ExoneraTor (read 10 Oct 2026). ExoneraTor sends no CORS header, so this page builds the link and you open it yourself.
Which of these IPs are Tor relays or exits right now?
Paste up to 200 IP addresses, one per line (ports and IPv6 brackets are fine). The first check downloads the current relay list from Onionoo with only six fields (about 2.3 MB uncompressed on 10 October 2026, less with compression), keeps it in memory for this tab, and matches every address locally, so your list never leaves the browser.
On this page
- The lookup
- Was this IP a Tor relay on a specific date?
- Which of these IPs are Tor relays right now?
- What can you check, at a glance?
- How do I check if an IP is a Tor exit node?
- Can I check whether an IP was a Tor relay in the past?
- What do the Tor relay flags mean?
- How do family, contact and AS fields help an investigation?
- What does a match mean, and what doesn’t it?
- Is it legal and ethical to look up Tor relays?
- How was this tool tested?
- Sources
- Frequently asked questions
What can you check, at a glance?
Everything on this page comes from the Tor Project’s own public network data. Onionoo is the Tor Project’s web service “to learn about currently running Tor relays and bridges” Tor Project: Onionoo protocol specification (read 10 Oct 2026); ExoneraTor is its archive for historical dates Tor Project: ExoneraTor (read 10 Oct 2026).
| Question | Data source | Time window | What you get |
|---|---|---|---|
| Is this IP a Tor relay or exit now? | Onionoo /details?search= | Relays running in the past week | Exact address matches, running state, flags, exit addresses of the last 24 h |
| Who is this relay? | Onionoo /details?lookup= (hashed fingerprint) | Past week (a lookup can return older relays) | Nickname, flags, addresses, country, AS, bandwidth, version, exit policy, family, contact |
| Was this IP a relay on date X? | ExoneraTor (link out) | 2007-10-27 to the day before yesterday | Relays on that IP on or within a day of the date, and whether they allowed exits |
| Which of 200 IPs are relays? | One Onionoo /details?type=relay&fields=… download, matched locally | Past week | Table of exit / relay / not running / not listed, CSV and JSON |
| How reliable is the relay? | Onionoo /uptime and /bandwidth | 1 month, 6 months, 1 year, 5 years | Uptime and read/write bandwidth sparklines |
| Who else does this operator run? | Onionoo family=, as=, contact= | Past week | Mutual family members, all relays in an AS, relays with matching contact text |
Scale check: in the consensus valid from 10 October 2026 12:00 UTC, Onionoo listed 10,314 relays seen in the past week, 9,176 of them running and 2,719 running with the Exit flag, which exited through about 1,200 distinct IPv4 addresses Onionoo /details relay list, consensus of 10 Oct 2026 12:00 UTC (our count).
How do I check if an IP is a Tor exit node?
- Enter the IP in the lookup and press Enter. Onionoo’s search matches “the beginning of an IP address” and includes “all known addresses used for onion routing and for exiting to the Internet” Tor Project: Onionoo protocol specification (read 10 Oct 2026). Because that is a prefix search,
185.220.101.3would also match185.220.101.33; this page keeps only exact matches and tells you how many prefix matches it dropped. - Read the role. Each match says whether your IP is the relay’s onion-routing (OR) address, an exit address, or both. Onionoo’s
exit_addressesare “IPv4 addresses that the relay used to exit to the Internet in the past 24 hours”, which can differ from its OR address Tor Project: Onionoo protocol specification (read 10 Oct 2026). - Check the Exit flag and the exit policy. The directory authorities give the Exit flag to relays that allow exits to at least one /8 address space on each of ports 80 and 443 Tor directory protocol spec: assigning flags in a vote (read 10 Oct 2026). The exit policy summary lists the ports a relay accepts or rejects “for most IP addresses”, and the full policy is shown underneath Tor Project: Onionoo protocol specification (read 10 Oct 2026). A relay with a
reject 1-65535summary is not an exit. - Check “Running now”.
runningsays whether the relay was listed in the last consensus;last_seentells you when it was last there Tor Project: Onionoo protocol specification (read 10 Oct 2026).
For many addresses at once, use the batch panel. The IP lookup & triage page also flags Tor relays as one of its many signals; this page is the deep view.
Can I check whether an IP was a Tor relay in the past?
Yes, but not with Onionoo. Onionoo includes by default “all relays and bridges … that have been running in the past week”, and its own documentation notes that filtering for relays last seen 8 or more days ago “will lead to an empty result set” Tor Project: Onionoo protocol specification (read 10 Oct 2026). So a “no” from this page only covers about the last seven days.
ExoneraTor “answers the question whether there was a Tor relay running on a given IP address on a given date”, may store a different exit address than the registration address, and records whether the relay permitted exiting at the time Tor Project: ExoneraTor (read 10 Oct 2026). When we tested it on 10 October 2026 it accepted dates between 2007-10-27 and 2026-10-08 and answered for the date “or within a day” of it; a date of today returned “Date parameter too recent … The latest accepted data is the day before yesterday” Tor Project: ExoneraTor (read 10 Oct 2026). Its form fields are ip, timestamp (YYYY-MM-DD) and lang, which is how the date panel builds its link.
What do the Tor relay flags mean?
Flags are assigned by the directory authorities in each consensus. Meanings are quoted from the consensus format Tor directory protocol spec: consensus formats, “s” router status flags (read 10 Oct 2026); the thresholds are those the authorities use when voting, which the spec says may change, so clients should not depend on the exact details Tor directory protocol spec: assigning flags in a vote (read 10 Oct 2026).
| Flag | Meaning | Typical threshold |
|---|---|---|
Exit | Supports commonly used exit ports and is treated specially in path building. | Allows exits to at least one /8 address space on each of ports 80 and 443. |
BadExit | Believed to be useless as an exit node, for example because its ISP censors it or it sits behind a restrictive proxy. | Set by authorities; clients avoid it as an exit. |
Guard | Suitable for use as an entry guard. | Fast, Stable and “familiar”, weighted uptime at least the median, bandwidth at least 2 MB/s by default or in the top 25%. |
Stable | Suitable for long-lived circuits. | Weighted mean time between failures at least the median, or at least 7 days. |
Fast | Suitable for high-bandwidth circuits. | Bandwidth in the top 7/8 of active relays, or at least 100 KB/s. |
HSDir | Considered an onion-service (hidden-service) directory. | Stable and Fast, and up for at least 96 hours. |
MiddleOnly | Considered unsuitable for anything but the middle position. | Authorities then vote against Exit, Guard, HSDir and V2Dir. |
Running | Currently usable over all its published ORPorts. | An authority connected to it within the last 45 minutes. |
Valid | Has been validated. | Runs a Tor version not known to be broken and is not blocked by the authority. |
V2Dir | Implements the v2 directory protocol or higher. | Has an open directory port or tunnelled directory support. |
StaleDesc | Should upload a new descriptor because the old one is too old. | Descriptor published more than 18 hours ago. |
Authority | Is a directory authority. | — |
How do family, contact and AS fields help an investigation?
- Effective family lists “relays that are in an effective, mutual family relationship with this relay” and “always contains the relay’s own fingerprint”; alleged family lists relays this one names that do not name it back Tor Project: Onionoo protocol specification (read 10 Oct 2026). Mutual family is the strongest public sign that relays share an operator. Use “List family members by nickname” on a result card to query Onionoo’s
familyparameter. - Contact is the operator’s free-text “contact address” Tor Project: Onionoo protocol specification (read 10 Oct 2026). It is self-reported and unverified, and because anyone can write anything there, this page renders it as plain text and never turns it into a link.
- AS and country come from GeoIP and AS databases resolved on the relay’s first onion-routing address Tor Project: Onionoo protocol specification (read 10 Oct 2026). Click “all relays in AS…” to see who else runs relays on that network, then pivot to the cloud IP check or bgp.he.net.
- Host names are split into verified (the PTR name’s A record points back to the IP) and unverified PTR results Tor Project: Onionoo protocol specification (read 10 Oct 2026). Operators of large exits often publish reverse DNS such as
tor-exit-….names. - Version status says whether the relay’s Tor version is recommended, experimental, obsolete, new in series or unrecommended by the directory authorities Tor Project: Onionoo protocol specification (read 10 Oct 2026).
What does a match mean, and what doesn’t it?
- A match means the address belonged to a public Tor relay in the stated window. If it is an exit, traffic you saw from it most likely came from a Tor user. The Tor Project puts it plainly: “if you see traffic from a Tor relay, this traffic usually originates from someone using Tor, rather than from the relay operator”, and operators “have no records of the traffic” Tor Project: ExoneraTor (read 10 Oct 2026).
- No match does not mean “not Tor”. The relay may have been offline for more than a week, the exit may have left from another address, or the address may be a bridge. Bridge addresses in Onionoo are sanitized (you will see private-range placeholders), so an IP search never finds a real bridge. The bridge search on this page works by nickname or hashed fingerprint only Tor Project: Onionoo protocol specification (read 10 Oct 2026).
- Times are UTC.
relays_publishedis “when the last known relay network status consensus started being valid” Tor Project: Onionoo protocol specification (read 10 Oct 2026); every result shows it so you can record exactly what the data said and when.
For context on where Tor relay checks fit in a wider dark-web investigation, see the Dark Web OSINT guide 2026.
Is it legal and ethical to look up Tor relays?
This tool reads public network metadata that the Tor Project publishes for anyone, including relay operators, researchers and network defenders. It never connects to Tor, onion services or any relay. As our dark web OSINT guide stresses, stay on public information and document your method. Remember that relay operators are volunteers providing infrastructure, not the users of it: do not treat an operator’s contact details as a suspect’s, and use the abuse contacts they publish for abuse reports. This page is information, not legal advice.
How was this tool tested?
- Real Onionoo responses captured on 10 October 2026 (protocol version 8.0 in the responses) were replayed in headless Chromium: an exit IP with two relays on one address (
185.220.101.33, ForPrivacyNET), an exit that leaves from a different address than it listens on (23.151.8.10), a guard (96.9.98.148, masterp), a non-relay IP (8.8.8.8, empty result), a fingerprint lookup using the SHA-1-hashed fingerprint, an AS query with 271 truncated results, uptime and bandwidth documents, and the full six-field relay list for batch mode. - IPv6 canonicalisation (RFC 5952 zero compression, embedded IPv4), fingerprint clean-up with
$and spaces, CIDR rejection, prefix-match filtering, CSV formula escaping and hostile strings in nickname, platform and contact fields (rendered as text, no script execution). - Network failure, HTTP 500 and timeout paths, keyboard use (Enter to search, Ctrl/⌘+Enter for batch), deep links via
?q=and#q=, and no horizontal scrolling at 375 px.
Sources
- Tor Project: Onionoo protocol specification (read 10 Oct 2026)
- Tor Project: ExoneraTor (read 10 Oct 2026)
- Tor directory protocol spec: consensus formats, “s” router status flags (read 10 Oct 2026)
- Tor directory protocol spec: assigning flags in a vote (read 10 Oct 2026)
- Tor Metrics: Relay Search (URL routes read from its router.js, 10 Oct 2026)
- Onionoo /details relay list, consensus of 10 Oct 2026 12:00 UTC (our count)
Shodan and bgp.he.net links on result cards go to third-party sites, which receive the IP or AS number you open there.
Frequently asked questions
How do I check if an IP address is a Tor exit node?
Type the IP into the lookup box and press Enter. The page asks the Tor Project’s Onionoo service for relays that use that address, keeps only exact matches, and shows whether the relay is running in the latest consensus, whether it has the Exit flag, and whether the address is one the relay used to exit to the Internet in the past 24 hours. Onionoo only covers relays seen in roughly the past week, so for an older date use the ExoneraTor link on the same page.
Why does the tool say “not a relay in Onionoo’s current data” instead of “not Tor”?
Because absence from Onionoo proves very little. Onionoo only lists relays that have been running in the past week, an exit can leave the network from a different address than the one it registered, bridges are deliberately unlisted and their addresses are sanitized, and the person behind traffic may simply be a Tor user whose own IP never appears anywhere. A “no” here only means the address is not a relay in the current data set.
Can I check whether an IP was a Tor relay on a past date?
Yes, with the Tor Project’s ExoneraTor service. Enter the IP and a date in the “specific date” panel and the page builds a pre-filled ExoneraTor link. ExoneraTor answers whether a Tor relay was running on that address on or within a day of the date, and whether it allowed exiting. On 10 October 2026 it accepted dates from 2007-10-27 up to the day before yesterday. ExoneraTor does not send CORS headers, so this page links to it rather than fetching it.
What is the difference between effective family and alleged family?
A relay family is a set of relays run by the same operator, which Tor clients avoid using twice in one circuit. Onionoo’s effective_family lists relays that name this relay and are named by it in return, so the relationship is mutual and always includes the relay itself. alleged_family lists relays this relay names that do not name it back. Mutual family is a strong sign of common operation; an alleged family entry is only a one-sided claim.
Is the contact information of a Tor relay verified?
No. The contact line is free text that the operator puts in the relay’s configuration, and Onionoo publishes it as is. Anyone can write any name, email address or URL there, so treat it as an unverified lead. This page shows it as escaped plain text and never turns it into a clickable email or web link.
Does a Tor exit IP in my logs mean the relay operator did it?
Usually not. Tor exit relays forward traffic for many anonymous users, so traffic from an exit address normally comes from someone using Tor, not from the person running the relay. The Tor Project states that relay operators keep no records of the traffic that passes through them. Treat a Tor match as a reason to change your investigative approach, not as an identification.
What does a lookup send to the Tor Project, and is batch mode private?
A single lookup sends your query, such as the IP address or nickname, from your browser directly to onionoo.torproject.org; nothing goes through Max Intel servers. Batch mode works differently: it downloads the whole public relay list once per session, about 2 MB, and matches your pasted IPs inside your browser, so the list of IPs you paste is never sent anywhere.
Why do some exit relays exit from a different IP address than they listen on?
A relay registers in the network with its onion-routing address, but its operating system may send outgoing connections from another address on the same machine or network. Onionoo therefore reports exit_addresses separately: the IPv4 addresses the relay actually used to exit to the Internet in the past 24 hours. The lookup matches both kinds of address and tells you which one your IP matched.