This blog now lives on the dark web as a Tor hidden service
Self-Hosting on the Dark Web

The author walks through self-hosting a static site as a Tor onion service: installing Tor, pointing a hidden service at a local nginx port, and building a second copy with the .onion address as its base URL so links don't leak back to clearnet. No certificate authority, no DNS, no exposed IP — the address is derived from a public key, and Tor encrypts the connection end to end.
There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself.
- p4bl0
My personal website has been hosted on Tor for years. It's easy to do from your home even behind a NAT because it's an outgoing connection from your point of view (which also makes it a great way to expose local services even when you are behind a NAT and don't not have a static IP), and by design your personal IP is hidden from your visitors.
I wrote about it in 2600 almost ten years ago (already?!). A copy of my article can be found here: https://pablorauzy.fr/outreach/2600/how-to-run-a-tor-hidden-...
If you have an Onion copy of your website, don't forget the Onion-Location http header which will automatically redirect Tor Browser users to the onion version of the website even if they visit it at the clear web address.
If it interests people, I also have a follow up article about I2P: https://pablorauzy.fr/outreach/2600/how-to-run-an-i2p-hidden...
- ivanmontillam
What I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:
- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).
- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).
- Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.
- Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.
As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.
If you can ship your website to the browser in a single connection, you've won.
I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.
--
[0]: https://news.ycombinator.com/item?id=49872320
EDIT: Formatting of bullet points.
- basilikum
You probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it: https://community.torproject.org/onion-services/advanced/oni...
- mzajc
Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:
> HiddenServicePort 80 127.13.37.1:8080
> listen 127.13.37.1:8080;
This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
- dherls
What is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?
- tombert
I thought about doing this back when I was self-hosting my blog, purely because I thought there would be a neatness factor to being able to honestly say "I have a site on the dark web".
I eventually moved the blog to Cloudflare Pages primarily because I wanted to use Cloudflare Workers to handle the comments, though I have still considered dual-publishing it just to still say I've done it.
- coldblues
I recommend that people give I2P and Yggdrasil a try as well, especially Yggdrasil. It makes no compromises on speed and latency, but it has no anonymity.
- sowbug
In a guide like this, it might be helpful to emphasize backing up the generated private key, loss of which would cause you to have to change your onion address.