---
title: "How to Run a Tor Relay, Bridge or Onion Service on a VPS"
description: "Run a Tor middle relay, a bridge, an exit or an onion service on a VPS: install from the Tor Project, torrc settings, ports, exit etiquette and checks."
url: https://offshoreserv.com/docs/vps/tor-relay
lang: en
updated: 2026-09-26
source: HTML page at the url above (canonical); this is its Markdown version
---

Knowledge base · VPS

# How to run a Tor relay, bridge or onion service on a VPS

Run a Tor relay on a VPS: install tor from the Tor Project's repository, then set up a middle relay, an obfs4 bridge, an exit relay or an onion service.

Updated 26 September 2026 11 min read

In this guide

- Install tor from the Tor Project's own repository, which carries the current stable release.
- A middle or guard relay needs a nickname, a public contact, an open ORPort and ExitRelay 0.
- A bridge adds the obfs4 transport and stays out of the public relay list.
- An exit needs a tor-exit reverse DNS name, a reduced exit policy, a notice page and a local DNS resolver, and it draws abuse reports.
- An onion service points a.onion address at a site on 127.0.0.1; back up its key.

VPS9 sections

To run a Tor relay on a VPS, install tor from the Tor Project's own repository, write a nickname, a contact and an ORPort into `/etc/tor/torrc`, open that port in the firewall and restart tor. The same tor also runs a bridge with the obfs4 transport, an exit relay, or an onion service for your own site.

The steps use an [Offshore VPS](https://offshoreserv.com/offshore-vps) on Debian 12 or 13 or Ubuntu 22.04 or 24.04 LTS, with root access as in [getting started](https://offshoreserv.com/docs/getting-started). Give each server one role: the Tor Project advises against hosting an onion service on a relay, and a bridge should not reuse a public relay's address.

> Keep your SSH session open while you change the firewall. If a rule locks you out, the console in the client area still reaches your VPS.

## Before you run a Tor relay on a VPS: pick a role

| Role | What it does | Abuse reports | Tor Project minimum | Plan to start with |
| --- | --- | --- | --- | --- |
| Middle or guard relay | Relays encrypted traffic; can later serve as a guard, the first hop | Usually none | 10 Mbit/s each way, 100 GB a month, 512 MB RAM (1 GB above 40 Mbit/s) | Sloop: 2 GB RAM, $3.49 a month |
| Bridge | Unlisted entry point for users on censored networks | Unlikely | 1 Mbit/s each way | Dinghy: 1 GB, $2.39 |
| Exit relay | The last hop: destinations see your server's IP address | Expect them | 1.5 GB RAM recommended | Cutter: 4 GB, $5.49 |
| Onion service | Your site at a.onion address, reachable only over Tor | Only about your content | What your site needs | Dinghy for a small site |

Every VPS plan includes the dedicated IPv4 address a relay needs, and traffic is unmetered under fair use on our 1 Gbps ports. If a busy relay causes a problem on a VPS, we tell you in the client area and suggest a fix first. Cap tor as shown below, or move a fast relay to a [dedicated server](https://offshoreserv.com/offshore-dedicated-servers), which you can use to its stated capacity.

Our [acceptable use policy](https://offshoreserv.com/acceptable-use-policy) welcomes relays and bridges and allows exits that follow the Tor Project's guidance. Relay addresses and contact lines are public: if the relay must not lead back to you, read [how to buy a VPS anonymously](https://offshoreserv.com/blog/buy-a-vps-anonymously). The location decides which country's law applies, and the [network page](https://offshoreserv.com/network) compares latency.

## Install Tor from the Tor Project's repository

The Tor Project [recommends its own repository](https://support.torproject.org/apt/tor-deb-repo/) over Debian's LTS version and Ubuntu's universe packages, which "have not reliably been updated". It carries the current stable series, 0.4.9:

```
apt update
apt install -y apt-transport-https gnupg wget
wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor | tee /usr/share/keyrings/deb.torproject.org-keyring.gpg >/dev/null
. /etc/os-release
cat > /etc/apt/sources.list.d/tor.sources <<EOF
Types: deb deb-src
URIs: https://deb.torproject.org/torproject.org/
Suites: $VERSION_CODENAME
Components: main
Signed-By: /usr/share/keyrings/deb.torproject.org-keyring.gpg
EOF
apt update
apt install -y tor deb.torproject.org-keyring
tor --version
```

`/etc/os-release` supplies your codename, such as `trixie` or `noble`. The keyring package keeps the signing key current, and the last command should print a 0.4.9 version.

## Run a middle or guard Tor relay on your VPS

Replace the contents of `/etc/tor/torrc` with these lines from the Tor Project's [relay guide](https://community.torproject.org/relay/setup/guard/debian-ubuntu/), using your own values:

```
Nickname    myNiceRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort      443
ExitRelay   0
SocksPort   0
```

- **Nickname**: 1 to 19 letters and digits.
- **ContactInfo**: How others reach you if the relay misbehaves. It is published, so use an address made for it; it is required if you run several relays.
- **ORPort**: The port that clients and relays connect to, on IPv4 and IPv6. Any free port works.
- **ExitRelay 0**: Traffic stays inside the Tor network.
- **SocksPort 0**: Closes the local client port 9050 that the package opens by default.

Open the port, restart tor and read the log. If UFW is not active yet, allow SSH first, as in the [hardening guide](https://offshoreserv.com/docs/security/hardening).

```
ufw allow 443/tcp
systemctl restart tor@default
journalctl -e -u tor@default
```

The reachability check can take up to 20 minutes and ends with `Self-testing indicates your ORPort... is reachable from the outside. Excellent. Publishing server descriptor.` About three hours later, find the relay on [Relay Search](https://metrics.torproject.org/rs.html) by the fingerprint in `/var/lib/tor/fingerprint`. Traffic then ramps up over weeks, as the Tor Project's [lifecycle of a new relay](https://blog.torproject.org/lifecycle-of-a-new-relay/) explains.

### Limit the bandwidth (optional)

To cap a relay, add one of these blocks to `torrc` and restart tor:

```
# average and burst rate, in each direction
RelayBandwidthRate  25 MBytes
RelayBandwidthBurst 50 MBytes

# or a monthly quota
AccountingStart month 1 00:00
AccountingMax   4 TBytes
```

Tor counts in powers of two, so 25 MBytes a second is about 210 Mbit/s. At the quota, tor hibernates until the next period, which the [tor manual](https://2019.www.torproject.org/docs/tor-manual.html.en) prefers to a very low rate.

## Run a Tor bridge on a VPS

A bridge is a relay missing from the public directory, so it is harder to block. Users reach it through obfs4, a pluggable transport that transforms Tor traffic to get past censorship. As in the Tor Project's [bridge guide](https://community.torproject.org/relay/setup/bridge/debian-ubuntu/), install it and replace `torrc`:

```
apt install -y obfs4proxy
```

```
BridgeRelay 1
ORPort 8443
ServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy
ServerTransportListenAddr obfs4 0.0.0.0:8080
ExtORPort auto
ContactInfo YOUR_CONTACT_ADDRESS
Nickname PickANickname
```

Use two different free ports above 1024 and avoid 9001, which censors may scan for; lower ports need two extra steps from the guide. Open both and restart:

```
ufw allow 8443/tcp
ufw allow 8080/tcp
systemctl restart tor@default
```

The log should show `Registered server transport 'obfs4'`; if it does not, check the `ServerTransportPlugin` path. The Tor Project now develops obfs4proxy as lyrebird, a [fork with more transports](https://packages.debian.org/sid/lyrebird), but Debian 12 and 13 and Ubuntu 22.04 and 24.04 still package `obfs4proxy`. Where `lyrebird` is packaged instead, install it and use `/usr/bin/lyrebird`.

Your bridge line is in `/var/lib/tor/pt_state/obfs4_bridgeline.txt`: add the IPv4 address, the obfs4 port and the fingerprint from `/var/lib/tor/fingerprint` to get `Bridge obfs4 SERVER_IP:8080 FINGERPRINT cert=... iat-mode=0`. The Tor Project distributes the bridge unless you set `BridgeDistribution none`, and users can take days or weeks to arrive. Keep bridges out of relay families, and do not convert an existing relay.

## Run a Tor exit relay responsibly

Destinations see an exit's IP address as the source of its traffic, so exits draw abuse complaints and, the Tor Project says, "have the greatest legal exposure and liability of all the relays". Our acceptable use policy allows them if you follow the Tor Project's [exit guidance](https://community.torproject.org/relay/setup/exit/) with a reduced exit policy. As the EFF advises, give the exit its own IP address, keep no personal data on it and never route your own traffic through it.

### 1. Request a reverse DNS name

Before you enable exiting, choose **Set the reverse DNS (PTR)** under **Server actions** on your server's page in the client area, with a hostname on a domain you own, such as `tor-exit.example.org`. The Tor Project suggests "tor-exit" in the name, never torproject.org.

### 2. Prepare the exit notice

A page on port 80 tells anyone who checks the address that it is a Tor exit; its authors say this "has proven very effective at reducing abuse complaints". Copy the template that comes with tor:

```
cp /usr/share/doc/tor/tor-exit-notice.html /etc/tor/tor-exit-notice.html
```

Minimized Ubuntu images leave out documentation files. If the file is missing, extract it from the package instead:

```
cd /tmp && apt download tor
dpkg-deb --fsys-tarfile tor_*.deb | tar -xO ./usr/share/doc/tor/tor-exit-notice.html > /etc/tor/tor-exit-notice.html
```

Then edit the parts marked FIXME: your hostname, a contact address, and the US-only section, which non-US operators remove.

### 3. Configure the exit

```
Nickname    myExitRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort      443
DirPort     80
DirPortFrontPage /etc/tor/tor-exit-notice.html
ExitRelay   1
ReducedExitPolicy 1
SocksPort   0
```

The reduced policy accepts about 65 ports, among them the web, secure mail and SSH, but not port 25, which our network also closes by default. `ExitPolicy` lines apply first, so `ExitPolicy reject *:22` would drop SSH too; `IPv6Exit 1` adds IPv6. The DirPort still serves the notice, though relays no longer publish it.

### 4. Run a local DNS resolver and start

Exits resolve names for Tor users, so the Tor Project asks for a local caching, DNSSEC-validating resolver; its [Debian and Ubuntu steps](https://community.torproject.org/relay/setup/exit/debian-ubuntu/) use Unbound. Our added `rm` matters on Ubuntu, where `/etc/resolv.conf` is a systemd-resolved link: systemd-resolved only reads a plain file put in its place, as its [manual](https://manpages.ubuntu.com/manpages/noble/en/man8/systemd-resolved.service.8.html) describes.

```
apt install -y unbound
systemctl enable --now unbound
cp /etc/resolv.conf /etc/resolv.conf.backup
rm -f /etc/resolv.conf
echo nameserver 127.0.0.1 > /etc/resolv.conf
chattr +i /etc/resolv.conf
ufw allow 443/tcp
ufw allow 80/tcp
systemctl restart tor@default
```

Unbound answers on localhost only by default; keep it that way, since an open resolver breaks our acceptable use policy. Then `http://SERVER_IP/` should show the notice.

### How we handle complaints about your exit

Reports about traffic that Tor users send through your exit go through our normal [complaints process](https://offshoreserv.com/dmca-policy), not an automatic suspension. Each is checked against the law where the server runs; foreign notices, including US DMCA notices, are answered, not enforced, and we can pass the substance on in your client area. On a dedicated or GPU server, tell us by ticket before you start the exit, so we can route reports to you quickly.

> This is not immunity. A valid court order from the server's country, or in our EU locations a notice that meets the Digital Services Act's requirements, can still require action; you are informed and can respond first, unless a court forbids it. What you run yourself, such as attacks, spam or scans, falls under the zero-tolerance rules.

## Host a Tor onion service (hidden service)

An onion service, or Tor hidden service as tor's settings call it, publishes a site at a.onion address that works only through Tor. It needs no open ports, because tor only connects outward, so the site listens on 127.0.0.1 alone. Install nginx, remove its default site, which answers on every address, and serve your pages locally:

```
apt install -y nginx
rm /etc/nginx/sites-enabled/default
mkdir -p /var/www/onion
echo 'Hello from my onion site' > /var/www/onion/index.html
cat > /etc/nginx/conf.d/onion.conf <<'EOF'
server {
    listen 127.0.0.1:8080;
    root /var/www/onion;
    server_tokens off;
}
EOF
nginx -t
systemctl reload nginx
```

Add two lines to `torrc` from the Tor Project's [onion service guide](https://community.torproject.org/onion-services/setup/), restart tor and read your address:

```
HiddenServiceDir /var/lib/tor/my-website/
HiddenServicePort 80 127.0.0.1:8080
```

```
systemctl restart tor@default
cat /var/lib/tor/my-website/hostname
```

Open it in Tor Browser. Keep the directory under `/var/lib/tor`, where the tor service may write. Its `hs_ed25519_secret_key` file is your address, since the.onion name is its public key: whoever copies it can impersonate the service, and losing it loses the address, so back it up as shown below.

### Do not leak the server's address

- Keep ports 80 and 443 closed, so the pages cannot be found on the server's public IP.
- Hide version banners, error details, status pages and debug output such as PHP's `phpinfo()`, which can reveal the server's real name and address.
- Mind outgoing connections, such as DNS lookups, mail or fetching URLs for visitors: they come from your real IP, as Riseup's [onion service guide](https://riseup.net/en/security/network-security/tor/onionservices-best-practices) explains. The Tor Project's [operational security page](https://community.torproject.org/onion-services/advanced/opsec/) covers the rest.

### Announce it from a public site (optional)

If the site also runs publicly over HTTPS, this line in its HTTPS server block lets Tor Browser offer the onion address, as the [Onion-Location guide](https://community.torproject.org/onion-services/advanced/onion-location/) shows. It links the two addresses: fine for a public mirror, wrong for an anonymous service.

```
add_header Onion-Location http://YOUR_ONION_ADDRESS.onion$request_uri;
```

## Keep your Tor relay healthy

### Automatic updates

Let the unattended-upgrades from the [hardening guide](https://offshoreserv.com/docs/security/hardening#updates) update tor too. Per the Tor Project's [update guide](https://community.torproject.org/relay/setup/guard/debian-ubuntu/updates/), add the first line inside the `Unattended-Upgrade::Origins-Pattern` block of `/etc/apt/apt.conf.d/50unattended-upgrades` on Debian, or the second inside `Unattended-Upgrade::Allowed-Origins` on Ubuntu, then test with `unattended-upgrade --debug --dry-run`.

```
"origin=TorProject";
"TorProject:${distro_codename}";
```

### Backups

`/var/lib/tor` holds the relay's identity keys, a bridge's `pt_state` and your onion service's key; without them, a reinstalled server starts as a new relay. Archive it, as the Tor Project suggests, and keep the file encrypted off the server. To restore, stop tor and run `tar -xzf tor-backup.tar.gz -C /var/lib` as root, which keeps owners and permissions.

```
tar -czf /root/tor-backup.tar.gz -C /var/lib tor
```

### Monitoring with nyx

[nyx](https://nyx.torproject.org/), the Tor Project's terminal monitor, shows bandwidth, connections and events live. The tor package already opens the control socket it uses, so run it as root:

```
apt install -y nyx
nyx
```

### Several relays: set a family

Declare your relays a family, so that clients never use two of them in one circuit. Since tor 0.4.9 a family shares a secret key, as the Tor Project's [FamilyId guide](https://community.torproject.org/relay/setup/post-install/family-ids/) describes; its post-install guide calls the older `MyFamily` list removed. Run the first command once, on one relay: it writes `myrelays.secret_family_key` and prints a `FamilyId` line, and running it again overwrites the key. On every relay, install the key, add that line to `torrc` and reload. Keep the key secret.

```
tor --keygen-family myrelays
install -o debian-tor -g debian-tor -m 600 myrelays.secret_family_key /var/lib/tor/keys/
systemctl reload tor@default
```

## Troubleshooting

### tor does not start

Check the configuration the way the service does before each start. It prints what it rejects, such as a mistyped option, an invalid nickname or a port already in use, which `ss -tlnp` shows:

```
tor --defaults-torrc /usr/share/tor/tor-service-defaults-torrc -f /etc/tor/torrc --verify-config
```

### The ORPort is not reachable

`Your server has not managed to confirm reachability for its ORPort(s)` means the port is blocked from outside, and the relay publishes nothing until it is reachable. Compare `ufw status` with the `ORPort` line. If only the IPv6 address fails, fix IPv6 or use `ORPort 443 IPv4Only`.

## Frequently asked questions

### Can I run a Tor relay on a VPS?

Yes. A relay needs an IPv4 address, a reachable TCP port and, for a middle or guard relay, at least 10 Mbit/s each way. Every Offshore VPS is a KVM machine with full root and a dedicated IPv4 address, and our acceptable use policy allows relays, bridges and exits.

### Is running a Tor relay legal?

It depends on the country, both yours and the server's. For the United States, the EFF's [legal FAQ for relay operators](https://community.torproject.org/relay/community-resources/eff-tor-legal-faq/) knows of no one sued, prosecuted or convicted for running a relay, and believes relays, exits included, are legal under US law. Exits carry the most legal exposure.

### Will I get abuse complaints for a Tor relay?

Rarely for a middle, guard or bridge relay: the Tor Project says guard and middle relays usually get none, and bridges are unlikely to. Exits do, because destinations see their IP address. We handle those reports under our complaints process, not by automatic suspension.

### How much bandwidth does a Tor relay need?

The Tor Project's [relay requirements](https://community.torproject.org/relay/relays-requirements/) ask for at least 10 Mbit/s each way for a middle or guard relay, 16 recommended, and 100 GB of traffic a month, ideally 2 TB. A bridge needs 1 Mbit/s. Our 1 Gbps ports are unmetered under fair use.

### Can I run an onion service and a normal site on the same VPS?

Yes: one web server can serve the public site on the server's IP address and the onion site on 127.0.0.1, as long as neither answers for the other's host name. An Onion-Location header then points Tor Browser users to the onion address. That links the two, so an anonymous service needs its own server.

**Stuck on a step?**

Dedicated and GPU customers can open a ticket from the [client area](https://offshoreserv.com/account/support) with the server’s IP address and what they tried. First reply target: under 12 hours. For every other server, use the Server actions on its page, the [guides](https://offshoreserv.com/docs) and the [network status](https://offshoreserv.com/status) page.

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
