you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 17 min ago 255 onions tracked
home / news / tor network
04 February 2025 tor network 4 min read

Running a Tor relay: what first-time operators need to know

Every Tor circuit is built by volunteers: someone's spare server picks up encrypted traffic, forwards it, and never asks what it carries. Most of those volunteers run middle or guard relays, and most of them will never see a single abuse complaint.

That surprises newcomers who assume any Tor involvement means lawyers and DMCA notices. The reality is more nuanced, and it depends almost entirely on which role you choose.

Three roles, three risk profiles

Tor routes traffic through three hops: a guard, a middle relay, and an exit. The guard knows who you are but not where you are going; the exit knows the destination but not the user; the middle knows neither. The Tor Project's overview of relay types lays out this split clearly, along with what each role demands technically. Middle relays pass encrypted traffic between other relays and never touch the open internet. Guards do the same at the entry position, earning the flag after proving stability and roughly 2 MB/s of sustained throughput. Exits are where traffic leaves the network toward websites, mail servers and everything else. Only exits generate complaints in any volume. Because exit IPs are the ones visible to destination services, copyright holders, spammers' victims and law enforcement all end up there. Guards and middles stay effectively invisible to that entire ecosystem.

The bandwidth bill nobody budgets for

A healthy relay is hungry. A modest 50 Mbit/s middle can push 15 to 20 terabytes per month, and faster relays scale well past that. The Tor Project recommends an unmetered plan or at least 2 TB of monthly included transfer before you even start (its guard setup guide covers configuration and limits). Cost matters less than the billing model. Metered cloud providers turn a $10 server into a four-figure invoice; hyperscalers are the classic trap for exactly this reason. Hobbyist operators overwhelmingly land on flat-rate hosts with generous or unlimited transfer, capping their exposure to the price of a streaming subscription. Tor itself helps here. The BandwidthRate, AccountingMax and related options let you cap daily or monthly usage precisely, so the daemon simply goes quiet when your quota is spent.

Abuse handling: mostly an exit problem

Run a non-exit relay and your inbox stays quiet. Run an exit and you become the return address for every misdeed performed through your pipe, from BitTorrent takedowns to port scans. The Tor Project's exit guidelines describe a workable routine: respond professionally within about a day, use pre-written templates, and point complainants at ExoneraTor, which proves an IP was a listed Tor exit at a given time. The volume is manageable in practice. Large operators report that roughly 80 percent of complaints are automated noise, and template replies settle most of the rest without escalation.
Although we are not aware of an individual being sued, prosecuted, or convicted for running a Tor relay, law enforcement has occasionally mistakenly investigated individuals running a Tor relay.

Legal notes worth reading twice

In most Western jurisdictions, liability rules treat relay operators much like common carriers: you forward traffic you cannot see and did not originate. The EFF's legal FAQ for relay operators walks through US frameworks such as DMCA safe harbor and wiretap law, and remains useful reading elsewhere. Two habits reduce risk dramatically. First, transparency: reverse DNS naming, a notice page on the exit IP and accurate WHOIS contacts mean anyone investigating reaches an explanation instead of suspicion. Second, location: the Tor Project advises against running exits from home and suggests institutional or organizational hosting instead, as detailed in its community and legal resources. None of this is legal advice, and jurisdictions differ. If you plan to run an exit in a country where operators have faced harassment, a short consultation with a local lawyer is cheap insurance.

Why middle and guard relays are the smart start

Strip away the exit-specific headaches and what remains is pleasantly boring: install tor, set ExitRelay 0, open one port, watch bandwidth graphs. Non-exit relays require minimal maintenance, rarely attract complaints, and still strengthen anonymity for everyone, since spying on users becomes harder with every additional hop. The network needs all roles eventually, and exits remain the scarcest resource. But there is no shame in starting where the risk is lowest. A stable middle relay today, promoted to guard after weeks of good uptime, teaches you the operational rhythms without ever putting your name on someone else's traffic. For context on why the operator base keeps shrinking despite how easy the entry level has become, see our earlier coverage of the operator decline, and follow future pieces in our tor network notes series.

more notes

all news ›