All guides
Getting started
VPS
- VPS operating systems
- VPS snapshots and
off-site backups - How to host your own VPN on a VPS with WireGuard
- How to run a Tor relay, bridge or onion service on a VPS
- How to
self-host BTCPay Server on a VPS - How to run a Bitcoin or Monero node on a VPS
Dedicated servers
- Using IPMI and the KVM console on a dedicated server
- Choosing a RAID layout for your dedicated server
Windows RDP
Windows Server 2019 , 2022 or 2025 vsWindows 10 and 11 for RDP- How to connect to a Windows RDP server from any device
GPU servers
Security
On this page
- Before you run a Tor relay on a VPS: pick a role
- Install Tor from the Tor Project's repository
- Run a middle or guard Tor relay on your VPS
- Run a Tor bridge on a VPS
- Run a Tor exit relay responsibly
- Host a Tor onion service (hidden service)
- Keep your Tor relay healthy
- Troubleshooting
- Frequently asked questions
To run a Tor relay on a VPS, install tor from the Tor Project's own repository, write a nickname, a contact and an ORPort into /etc/tor/torrc
The steps use an Offshore VPS on
Before you run a Tor relay on a VPS: pick a role
| Role | What it does | Abuse reports | Tor Project minimum | Plan to start with |
|---|---|---|---|---|
| Middle or guard relay | Relays encrypted traffic; can later serve as a guard, the first hop | Usually none | Sloop: | |
| Bridge | Unlisted entry point for users on censored networks | Unlikely | Dinghy: | |
| Exit relay | The last hop: destinations see your server's IP address | Expect them | Cutter: | |
| Onion service | Your site at a .onion address, reachable only over Tor | Only about your content | What your site needs | Dinghy for a small site |
Every VPS plan includes the dedicated IPv4 address a relay needs, and traffic is unmetered under fair use on our
Our acceptable use policy welcomes relays and bridges and allows exits that follow the Tor Project's guidance. Relay addresses and contact lines are public: if the relay must not lead back to you, read how to buy a VPS anonymously. The location decides which country's law applies, and the network page compares latency.
Install Tor from the Tor Project's repository
The Tor Project recommends its own repository over Debian's LTS version and Ubuntu's universe packages, which "have not reliably been updated". It carries the current stable series, 0.4.9:
apt update
apt install -y apt-transport-https gnupg wget
wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor | tee /usr/share/keyrings/deb.torproject.org-keyring.gpg >/dev/null
. /etc/os-release
cat > /etc/apt/sources.list.d/tor.sources <<EOF
Types: deb deb-src
URIs: https://deb.torproject.org/torproject.org/
Suites: $VERSION_CODENAME
Components: main
Signed-By: /usr/share/keyrings/deb.torproject.org-keyring.gpg
EOF
apt update
apt install -y tor deb.torproject.org-keyring
tor --version
/etc/os-releasetrixienoble
Run a middle or guard Tor relay on your VPS
Replace the contents of /etc/tor/torrc
Nickname myNiceRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort 443
ExitRelay 0
SocksPort 0
- Nickname
- 1 to 19 letters and digits.
- ContactInfo
- How others reach you if the relay misbehaves. It is published, so use an address made for it; it is required if you run several relays.
- ORPort
- The port that clients and relays connect to, on IPv4 and IPv6. Any free port works.
- ExitRelay 0
- Traffic stays inside the Tor network.
- SocksPort 0
- Closes the local client
port 9050 that the package opens by default.
Open the port, restart tor and read the log. If UFW is not active yet, allow SSH first, as in the hardening guide.
ufw allow 443/tcp
systemctl restart tor@default
journalctl -e -u tor@default
The reachability check can take up to Self-testing indicates your ORPort ... is reachable from the outside. Excellent. Publishing server descriptor. About three hours later, find the relay on Relay Search by the fingerprint in /var/lib/tor/fingerprint
Limit the bandwidth (optional)
To cap a relay, add one of these blocks to torrc
# average and burst rate, in each direction
RelayBandwidthRate 25 MBytes
RelayBandwidthBurst 50 MBytes
# or a monthly quota
AccountingStart month 1 00:00
AccountingMax 4 TBytes
Tor counts in powers of two, so 25 MBytes a second is about
Run a Tor bridge on a VPS
A bridge is a relay missing from the public directory, so it is harder to block. Users reach it through obfs4, a pluggable transport that transforms Tor traffic to get past censorship. As in the Tor Project's bridge guide, install it and replace torrc
apt install -y obfs4proxy
BridgeRelay 1
ORPort 8443
ServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy
ServerTransportListenAddr obfs4 0.0.0.0:8080
ExtORPort auto
ContactInfo YOUR_CONTACT_ADDRESS
Nickname PickANickname
Use two different free ports above 1024 and avoid 9001, which censors may scan for; lower ports need two extra steps from the guide. Open both and restart:
ufw allow 8443/tcp
ufw allow 8080/tcp
systemctl restart tor@default
The log should show Registered server transport 'obfs4'; if it does not, check the ServerTransportPluginobfs4proxylyrebird/usr/bin/lyrebird
Your bridge line is in /var/lib/tor/pt_state/obfs4_bridgeline.txt: add the IPv4 address, the obfs4 port and the fingerprint from /var/lib/tor/fingerprintBridge obfs4 SERVER_IP:8080 FINGERPRINT cert=... iat-mode=0. The Tor Project distributes the bridge unless you set BridgeDistribution none
Run a Tor exit relay responsibly
Destinations see an exit's IP address as the source of its traffic, so exits draw abuse complaints and, the Tor Project says, "have the greatest legal exposure and liability of all the relays". Our acceptable use policy allows them if you follow the Tor Project's exit guidance with a reduced exit policy. As the EFF advises, give the exit its own IP address, keep no personal data on it and never route your own traffic through it.
1. Request a reverse DNS name
Before you enable exiting, choose Set the reverse DNS (PTR) under Server actions on your server's page in the client area, with a hostname on a domain you own, such as tor-exit.example.org
2. Prepare the exit notice
A page on
cp /usr/share/doc/tor/tor-exit-notice.html /etc/tor/tor-exit-notice.html
Minimized Ubuntu images leave out documentation files. If the file is missing, extract it from the package instead:
cd /tmp && apt download tor
dpkg-deb --fsys-tarfile tor_*.deb | tar -xO ./usr/share/doc/tor/tor-exit-notice.html > /etc/tor/tor-exit-notice.html
Then edit the parts marked FIXME: your hostname, a contact address, and the
3. Configure the exit
Nickname myExitRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort 443
DirPort 80
DirPortFrontPage /etc/tor/tor-exit-notice.html
ExitRelay 1
ReducedExitPolicy 1
SocksPort 0
The reduced policy accepts about ExitPolicyExitPolicy reject *:22IPv6Exit 1
4. Run a local DNS resolver and start
Exits resolve names for Tor users, so the Tor Project asks for a local caching, DNSSEC-validating resolver; its Debian and Ubuntu steps use Unbound. Our added rm/etc/resolv.conf
apt install -y unbound
systemctl enable --now unbound
cp /etc/resolv.conf /etc/resolv.conf.backup
rm -f /etc/resolv.conf
echo nameserver 127.0.0.1 > /etc/resolv.conf
chattr +i /etc/resolv.conf
ufw allow 443/tcp
ufw allow 80/tcp
systemctl restart tor@default
Unbound answers on localhost only by default; keep it that way, since an open resolver breaks our acceptable use policy. Then http://SERVER_IP/
How we handle complaints about your exit
Reports about traffic that Tor users send through your exit go through our normal complaints process, not an automatic suspension. Each is checked against the law where the server runs; foreign notices, including
Host a Tor onion service (hidden service)
An onion service, or Tor hidden service as tor's settings call it, publishes a site at a .onion address that works only through Tor. It needs no open ports, because tor only connects outward, so the site listens on 127.0.0.1 alone. Install nginx, remove its default site, which answers on every address, and serve your pages locally:
apt install -y nginx
rm /etc/nginx/sites-enabled/default
mkdir -p /var/www/onion
echo 'Hello from my onion site' > /var/www/onion/index.html
cat > /etc/nginx/conf.d/onion.conf <<'EOF'
server {
listen 127.0.0.1:8080;
root /var/www/onion;
server_tokens off;
}
EOF
nginx -t
systemctl reload nginx
Add two lines to torrc
HiddenServiceDir /var/lib/tor/my-website/
HiddenServicePort 80 127.0.0.1:8080
systemctl restart tor@default
cat /var/lib/tor/my-website/hostname
Open it in Tor Browser. Keep the directory under /var/lib/torhs_ed25519_secret_key
Do not leak the server's address
- Keep ports 80 and 443 closed, so the pages cannot be found on the server's public IP.
- Hide version banners, error details, status pages and debug output such as PHP's
, which can reveal the server's real name and address.phpinfo() - Mind outgoing connections, such as DNS lookups, mail or fetching URLs for visitors: they come from your real IP, as Riseup's onion service guide explains. The Tor Project's operational security page covers the rest.
Announce it from a public site (optional)
If the site also runs publicly over HTTPS, this line in its HTTPS server block lets Tor Browser offer the onion address, as the
add_header Onion-Location http://YOUR_ONION_ADDRESS.onion$request_uri;
Keep your Tor relay healthy
Automatic updates
Let the unattended-upgrades from the hardening guide update tor too. Per the Tor Project's update guide, add the first line inside the Unattended-Upgrade::Origins-Pattern block of /etc/apt/apt.conf.d/50unattended-upgrades on Debian, or the second inside Unattended-Upgrade::Allowed-Origins on Ubuntu, then test with unattended-upgrade --debug --dry-run.
"origin=TorProject";
"TorProject:${distro_codename}";
Backups
/var/lib/torpt_statetar -xzf tor-backup.tar.gz -C /var/lib as root, which keeps owners and permissions.
tar -czf /root/tor-backup.tar.gz -C /var/lib tor
Monitoring with nyx
nyx, the Tor Project's terminal monitor, shows bandwidth, connections and events live. The tor package already opens the control socket it uses, so run it as root:
apt install -y nyx
nyx
Several relays: set a family
Declare your relays a family, so that clients never use two of them in one circuit. Since tor 0.4.9 a family shares a secret key, as the Tor Project's FamilyId guide describes; its MyFamilymyrelays.secret_family_keyFamilyIdtorrc
tor --keygen-family myrelays
install -o debian-tor -g debian-tor -m 600 myrelays.secret_family_key /var/lib/tor/keys/
systemctl reload tor@default
Troubleshooting
tor does not start
Check the configuration the way the service does before each start. It prints what it rejects, such as a mistyped option, an invalid nickname or a port already in use, which ss -tlnp
tor --defaults-torrc /usr/share/tor/tor-service-defaults-torrc -f /etc/tor/torrc --verify-config
The ORPort is not reachable
Your server has not managed to confirm reachability for its ORPort(s) means the port is blocked from outside, and the relay publishes nothing until it is reachable. Compare ufw statusORPortORPort 443 IPv4Only
Frequently asked questions
Can I run a Tor relay on a VPS?
Yes. A relay needs an IPv4 address, a reachable TCP port and, for a middle or guard relay, at least
Is running a Tor relay legal?
It depends on the country, both yours and the server's. For the United States, the EFF's legal FAQ for relay operators knows of no one sued, prosecuted or convicted for running a relay, and believes relays, exits included, are legal under US law. Exits carry the most legal exposure.
Will I get abuse complaints for a Tor relay?
Rarely for a middle, guard or bridge relay: the Tor Project says guard and middle relays usually get none, and bridges are unlikely to. Exits do, because destinations see their IP address. We handle those reports under our complaints process, not by automatic suspension.
How much bandwidth does a Tor relay need?
The Tor Project's relay requirements ask for at least
Can I run an onion service and a normal site on the same VPS?
Yes: one web server can serve the public site on the server's IP address and the onion site on 127.0.0.1, as long as neither answers for the other's host name. An
Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under