VERIFY / EXACT MATCH

Verify a Torzon Onion Link Before You Connect: PGP Check 2026

A phishing onion looks right and reads right. The only thing it cannot fake is the signature. This page is about the one habit that keeps you safe: check the key, then diff the address down to the last character.

written by Alex Ferran :: checked 2026-08-25

THE CHECKfour gates

The four gates an address passes before it earns your trust

Verification is not one action, it is a short chain. Each gate can fail on its own, and any failure means stop. Fetch the key, confirm it signed the list, diff the exact address, and only then open it. Skip a gate and you are trusting a look, not a signature.

THE CHECKFETCHget canon keySIGcheck signatureDIFFcompare charsTRUSTopen in Tor
01 · fetchImport the published canon PGP key from a source you already trust.
02 · sigRun a signature check on the mirror list. A bad or missing signature ends it here.
03 · diffCompare your address to the signed one, character by character, start to end.
04 · trustOnly a full match earns a connection. Open it in Tor at the Safest level.
CHARACTER DIFFworked example

One wrong character is a different server

A clone swaps a handful of letters deep inside the string, where your eye skips. Below, the canon line and a lookalike differ by a single character. That is enough to route you to someone else entirely. Never eyeball the middle; compare the whole thing.

canontorzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion
clonetorzonguqmlfy2kf15tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion

Illustrative fragment, truncated on purpose. Pull the real string from the signed directory and diff the full length, not a preview.

VERIFICATION CHECKLISTcopy this routine

A Torzon verification checklist worth keeping

Run this short sequence every time a new Torzon address crosses your screen, whether it arrived from a search result, a forum post, or a friend's message. None of the four steps takes more than a minute once the habit is set.

  1. Fetch the canon PGP key from a source you already trust, not from the page claiming to be Torzon.
  2. Confirm the signature on the mirror list is valid and covers the exact address you were given.
  3. Diff the full onion string character by character against the signed canon, not just the first and last few characters.
  4. Only open the address in Tor once every prior step has passed; a single failure anywhere means stop and start over.

What to do when verification fails

Do not proceed, and do not assume the failure is a fluke on your end. Close the tab, return to a source you trust for the canon PGP key and signed mirror list — this page or the home directory — and start the check again from a clean address. If a Torzon link you received from a third party fails the diff, treat that party's link as compromised going forward rather than just the one address; a source that hands out one bad Torzon address may hand out another.

URL VALIDATORlocal only

Paste an address and test it

This tool normalizes harmless spacing and scheme differences, then accepts only an exact match from the embedded canon. A near-miss stays unverified, on purpose.

Runs entirely in your browser. Your input is matched against the embedded canon and is never sent anywhere.

What does the validator actually check?

It compares your string against the canon list baked into this page, character for character, after trimming spaces and a leading scheme. Match or no match, nothing between. It does not touch the network, so a green result means the text is correct, not that the node is live. Uptime is the status grid's job, and authenticity is still the signature's.

Validator vs. manual PGP check: when to use which

The validator on this page is the fast path — paste a Torzon address, get an instant match or no-match against the canon list baked into the page, all client-side with nothing sent anywhere. Use it as a first pass on any new Torzon link before you invest time in anything else. The manual PGP signature check below is slower but covers ground the validator cannot: it confirms the entire signed mirror list is authentic, not just one address you already had in hand. Run the validator for a quick sanity check on a single link; run the full PGP verification when you want to confirm the canon directory itself, or whenever the fingerprint on this page changes and you need to re-anchor trust from scratch.

KEY IMPORTtrust layer

Import the key, then check the signature

Canon key fingerprint:pending (Phase 0)
Show the verification commands
gpg --recv-keys <canon-fingerprint>
gpg --verify torzon-mirrors.sig
# reject any line the signature does not cover

Why is PGP the only proof that a link is official?

Anyone can copy our layout, our wording, and our color. No one can sign the mirror list without the private key that pairs with the fingerprint above. A signature that checks out is the one signal a clone cannot forge. The domain, the design, and the search ranking are all copyable. The key is not.

The fingerprint here reads pending. What does that mean?

The canon key is offline during Phase 0 and has not been published yet, so the fingerprint slot holds a placeholder on purpose. Do not trust a full fingerprint that turns up elsewhere claiming to be ours in the meantime. When the key goes live it will sign the directory, and this field will carry the real value.

What a signed mirror list actually is, in plain terms

A signed mirror list is a plain text file — the onion addresses, one per line — with a PGP signature attached that proves the holder of a specific private key produced that exact file. Change one character in the list after signing, and the signature stops matching; that mismatch is what your verification tool flags as a failure. This is the same mechanism software projects use to prove a downloaded file has not been tampered with in transit, applied here to a Torzon onion directory instead of a binary release. The signature does not prove the list is correct or complete; it proves only that whoever holds the canon key produced these exact bytes, which is precisely the guarantee a Torzon visitor needs before trusting an address.

Comparing PGP verification to other trust signals

A padlock icon in a clearnet browser tells you a connection is encrypted to somewhere, not that the somewhere is legitimate — a phishing site can hold a valid TLS certificate for its own domain just as easily as a real business can. A high search ranking tells you a page paid for placement or gamed an algorithm, not that it is authentic. A familiar-looking layout tells you someone copied a design, which costs nothing. A verified PGP signature is different in kind: it requires possession of a private key that has never been exposed, and it cannot be purchased, gamed, or approximated. That is why this page treats the signature as the only gate that matters and everything else — load speed, layout, ranking — as noise.

VERIFY NOTESbefore you trust

How to tell a verified Torzon link from a good fake

What makes a link a verified Torzon link?

Two things at once. It sits in the signed directory, and its full string matches the address the canon key vouches for. Miss either half and it stays unverified, however right it looks. A verified link is not the one that ranks first in a search. It is the one the signature covers.

Where do clones usually hide the swap?

In the middle of the string, where the eye slides past. The first few characters and the tail often match on purpose, so a glance approves it and the click lands on someone else. Diff the whole length, not the ends. That is the entire reason the character check exists.

Do I need to validate again if the address worked yesterday?

Check the fingerprint each session, at least briefly. A link you trusted can be swapped in the source you copied it from, and a saved bookmark can point at a stale address after a rotation. The habit costs seconds. Being routed to a clone costs the whole session.

What if two Torzon sources disagree on the address?

Trust neither until you resolve the conflict against the signed canon key, never by majority vote of forum posts. A clone campaign can flood several channels with a matching wrong address faster than the real operator can correct one. The PGP signature is the tie-breaker precisely because it cannot be forged the way a forum thread can be astroturfed — verify the signature, and let that answer settle the disagreement.

COMMON MISTAKESverification, done wrong

The most common Torzon verification mistakes

Eyeballing the start and end of the string instead of the whole thing

A clone operator knows the first and last characters are what people glance at, so those are usually left matching on purpose. The swap sits buried in the middle. Diff the entire 56-character string, not the parts that are easy to read at a glance.

Trusting a mirror because it "looks like" the real Torzon page

Visual design is the cheapest thing to copy. A byte-for-byte clone of the real Torzon layout, with only a wallet address or an onion string changed underneath, will look completely correct. The signature is the only part a clone cannot replicate.

Skipping verification because the last visit "worked fine"

An address that worked yesterday is not a guarantee it is still the canon one today. Mirrors rotate, phishing campaigns spin up new lookalikes constantly, and a saved bookmark does not know the difference. Re-check the fingerprint every session.

Treating a fast-loading page as proof of authenticity

Load speed measures server response time, nothing about who runs the server. A well-resourced clone can load faster than the real Torzon mirror on a bad day. Speed is not a trust signal; the PGP signature is.

Assuming a Torzon link shared inside a "trusted" community is pre-verified

A forum reputation or a vouching system says nothing about whether the specific string pasted into that thread matches the signed Torzon canon. Community trust and cryptographic verification are two different things; the second one is the only one a clone cannot forge, so run the diff yourself even when the source feels reliable.

Copy-pasting a Torzon address from a search engine result

Search engines index whatever a page claims about itself, including a clone's own metadata calling itself the official Torzon market. No ranking signal checks a PGP fingerprint. Treat a Torzon link found through a search engine as unverified by default and run the same character-diff routine you would run on any other unknown source.

Verifying once and reusing the result indefinitely

A signature check is a snapshot, not a standing guarantee. If the canon mirror list gets updated with a new PGP signature, an address that passed verification last month can be superseded without warning. Re-pull the current signed list from the home directory before a Torzon session that matters, rather than relying on a stale memory of "it checked out before."

SIGNED CANON

Pull the addresses to diff

The full onions and the fingerprint live on the home directory. Start there, then run each address through the check above.

Open directory