ONION 101 / BACKGROUND
What Is an Onion Link? Tor Routing Explained for Torzon Access in 2026
An onion link ends in .onion and points at a service that lives inside the Tor network. It has no clearnet address and no normal DNS entry, so a regular browser simply cannot find it. Here is what the address is and why the routing works the way it does.
written by Alex Ferran :: checked 2026-08-25
How a .onion request travels, and why no ordinary browser can follow it
A .onion is not a domain a normal resolver knows. There is no public DNS record and no exit to the open web. The Tor Browser builds an encrypted path through several relays to a meeting point, and the service answers there. Neither end learns the other address, which is the whole point.
Why does Tor open a .onion when Chrome cannot?
Tor speaks the rendezvous protocol these addresses need, and it carries the directory logic to look up the service key. A normal browser has neither, so it treats the address as a dead name and gives up. Install the Tor Browser and the same string that failed everywhere else resolves in one step.
A worked example: what happens when you paste a Torzon onion
Say you paste a verified Torzon address into the Tor Browser's address bar and press enter. Here is the walkthrough, hop by hop, of what actually happens before the page renders.
Step one — the client builds a circuit. Before Tor even looks at the address, it has already built a three-hop circuit through the public Tor network: a guard relay it trusts for this session, a middle relay chosen at random, and an exit-adjacent relay that in this case will not exit anywhere, because the destination is not on the open web.
Step two — the address is decoded, not resolved. A .onion address is not looked up in a directory the way a normal hostname is. The string itself encodes a public key belonging to the service. Tor derives the service's current descriptor location from that key and fetches a small signed document from the distributed hash table that Tor relays maintain among themselves. That descriptor lists the introduction points the service has chosen to announce itself at.
Step three — introduction, not direct contact. Your client builds a second circuit to one of the service's introduction points and asks it to pass along a message: "meet me at this rendezvous point." Crucially, the introduction point never sees your traffic and never learns who is asking. It just relays a short introduce cell.
Step four — the rendezvous. Your client separately picks a rendezvous relay and tells the service, via the introduction point, to meet it there. The Torzon server then builds its own circuit to that same rendezvous relay. Neither your circuit nor the service's circuit ever touches the other's real relays directly — the rendezvous point is the only shared node, and even it cannot see who either party is, only that two circuits have joined.
Step five — the page loads. From this point on, your browser and the Torzon server exchange encrypted cells through the joined circuit exactly as if it were a normal HTTPS connection, except every hop in between is Tor relays, and the .onion's own address already provides end-to-end authentication because the address is derived from the service's public key — so a mismatched key simply fails to connect rather than silently serving the wrong content.
An onion address is a public key, not a hostname
Those 56 characters before .onion are not a brand name someone picked. They are derived from the service own key. That is why the string looks random and why a single wrong character points somewhere else. There is no registrar to appeal to and no way to guess a shorter version. You either have the exact key or you have nothing.
What is an onion link, in one line?
It is a web address that resolves only inside Tor, ending in .onion, tied to a service key rather than a registered name. No company sells it and no DNS server knows it. That is why an onion url reads like noise, and why it cannot be trimmed into something friendlier without becoming a different address.
Why the address is 56 characters, specifically
Current-generation onion addresses (Tor's v3 format) encode a 32-byte Ed25519 public key, a 2-byte version field, and a 2-byte checksum, all base32-encoded. That fixed-size input is what produces a fixed-size output: 56 characters, always, whether the service is a one-page blog or a market the size of Torzon. Base32 was chosen over base64 because it avoids mixed-case ambiguity — every character is unambiguous when read aloud or copied by hand, which matters when the string itself is the only thing standing between you and a clone.
Vanity onions and why they do not make an address more trustworthy
You can grind a custom onion address that starts with a chosen prefix, such as "torzon," by brute-forcing keys until one produces the right leading characters — tools like mkp224o do this routinely, and it is exactly how the addresses on this site were generated. But a prefix is cosmetic. Anyone can grind a vanity string with "torzon" at the front; the prefix says nothing about who controls the rest of the key. This is precisely why the verification steps elsewhere on this site call for matching the full 56-character string against a signed record, not eyeballing the first few characters and assuming a match.
Why the same URL behaves so differently
Clearnet host
Public DNS resolves the name, your ISP sees the destination, and any browser connects. Convenient, and visible from both ends.
Onion service
No DNS, no exit node, no visible endpoint. Only Tor resolves the key, and the routing hides who is talking to whom.
The practical effect shows up the moment you try to open a Torzon .onion link outside Tor: nothing happens, because there is no DNS record anywhere on the open internet mapping that string to an IP address. A clearnet mirror of Torzon, by contrast, must resolve through public DNS to exist at all, which means it sits on infrastructure that can be logged, subpoenaed, or seized — one more reason the onion address, not a clearnet copy, is the one to trust for anything that matters.
Common onion questions
Can I open a .onion in Chrome or Safari with a plugin?
No. There is no safe plugin that turns a normal browser into a Tor client. Use the official Tor Browser. Anything that promises a shortcut is the risk you were trying to avoid.
Why is the address so long and unreadable?
Because it is math, not marketing. The string is tied to the service key, so it cannot be shortened or personalised without becoming a different service entirely.
Do onion addresses ever change?
The address itself only changes if the operator generates a new key, usually after a compromise or a deliberate rotation. A stable Torzon address that has run for a long stretch is one small point in its favor, though age alone never substitutes for verifying the signature.
Is visiting a .onion address illegal?
Using Tor and visiting onion services is legal in most jurisdictions; Tor itself is widely used for journalism, whistleblowing, and ordinary privacy. What you do once connected, and what the destination service is, is what carries legal weight, not the protocol.
Can my ISP see that I used Tor?
An ISP can typically see that you connected to the Tor network, since the entry guard relay's address is visible in normal traffic, but it cannot see which .onion address you reached or what you did there, because that information never leaves the encrypted circuit.
Why does Torzon publish only an onion address and no clearnet domain?
Because a clearnet domain needs a registrar and a DNS record, both of which a takedown request can reach. Torzon's onion address has neither — it is generated from a cryptographic key with no registrar involved, which is why this grid treats the signed onion, not a clearnet lookalike, as the only canon Torzon entry point.
Does a .onion address ever expose the Torzon server's real location?
No. That is the entire design goal of onion routing. A Torzon connection routes through three relays with layered encryption, so no single relay — and no observer at either end — ever learns both who is asking and where the Torzon server physically sits.
Is an onion address the same thing as a Torzon username?
No, and confusing the two is a common beginner mistake. The onion address is the network location of the Torzon service itself, shared by every visitor; a username is created only after connecting, inside the login flow, and identifies your individual account on that Torzon service.
Why does an onion link work in Tor Browser but fail in a "Tor-enabled" third-party app?
Only the audited Tor Project client correctly builds the three-hop circuit an onion address needs. A third-party app claiming Tor support may proxy traffic differently, log more than it should, or fail to resolve a .onion string at all — reasons this grid recommends the official Tor Browser for every Torzon session.
Ready to connect
When the concept is clear, walk the access sequence and verify the string before you open it.