LINK VALIDATOR · SIGNED CANON

Torzon URL Validator 2026: Check a Verified Onion Address

Paste a Torzon onion address and this validator tells you on the spot whether it matches the signed canon. The check runs inside your browser, sends nothing to any server, and refuses every near-match. Use it before you log in, every time.

Written by Alex Ferran, security research · last checked 2026-08-25

CANON POINTERThe validator holds the same address list, but the canonical copy and the PGP block stay on the signed canon (index).torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion
VERIFY METHODhow it decides

What the validator does with the string you paste

The tool is deliberately dumb in one useful way: it does not care what a page looks like, only whether the exact address is on the signed list. It gets there in three moves.

Pasteonion stringNormalizescheme, slash, caseMatchexact vs canon
1 · PasteYou drop in a full onion. Partial strings and fragments are rejected outright.
2 · NormalizeIt lowercases the string and strips the scheme, trailing slashes, and stray spaces.
3 · MatchThe cleaned value is compared to each canon entry. Anything short of a full match reads as unverified.
OUR METHODwhat we contribute

How our exact-match check works, in detail

Plenty of "check your link" pages just eyeball the text. This one runs a fixed procedure so the result does not depend on a hunch.

What it normalizes

Before any comparison, the input is lowercased and cleaned of the parts that carry no meaning for identity: the http or https prefix, trailing slashes, and whitespace. Two addresses that differ only in those cosmetic bits should not read as different, so they get flattened first.

What counts as a match

The cleaned value is then tested against every entry in the embedded canon list, character for character. There is no fuzzy scoring and no "looks close enough". A single wrong character fails, because on Tor a single wrong character is a different server.

Where PGP takes over

Matching the list proves the address is one we published. It does not prove the list itself is genuine on a page you do not trust. That last step is PGP: the mirror list ships with a signature, and you verify it against a fingerprint you already hold. The tool handles the string; the signature handles the source. Full walkthrough in the PGP guide.

WORKED EXAMPLEstep by step

A worked walkthrough: checking one real address

Here is the validator run through on an actual entry from the canon, plus a deliberately altered version of the same string, so you can see exactly what a pass and a fail look like before you try it yourself.

Step 1 — take the primary address from the canon

The primary Torzon reference on this site is:

http://torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion

Step 2 — paste it into the validator, as-is

Pasted exactly, including the http:// prefix and any trailing whitespace a copy-paste sometimes adds, the tool first normalizes the string — lowercases it, strips the scheme and any trailing slash — before comparing it. The normalized form matches an entry in the canon list exactly, so the result reads "In the signed canon (genuine format)". That is a format pass: the string is one we published.

Step 3 — try a one-character clone

Now take the same address and change a single character in the middle, the way a phishing clone would to register a similar-looking but different onion key — for example swapping one letter so it reads http://torzonguqmlfy2kfi5tjbnt4bp3idtkjzl4qtupmhpdihjftomjtdzqd.onion. Paste that version in and the validator returns "Not in canon; treat as phishing". Nothing about the change is visible at a glance — it is a genuinely different onion address pointing at a genuinely different server, and the tool catches it because it never does fuzzy matching.

Step 4 — finish with the PGP check

A genuine-format result from Step 2 is not the end of the process. Import the canon PGP key once it publishes in Phase 0, and verify the mirror list's signature the way the PGP guide walks through. The validator confirms the string; the signature confirms the list that string came from actually belongs to this reference.

TELL THEM APARTreal signals

Phishing clone vs signed canon: the tells that hold up

Layout and wording copy easily. These signals do not.

Phishing clone

  • Address is off by a character or two from the one you know.
  • No signature, or a signature that fails the check.
  • Pushes urgency: "old link dead, use this one now".
  • Asks for a deposit or fee on a clearnet page.
  • Reached you through an ad, a DM, or a search result.

Signed canon

  • Address matches the list character for character.
  • Signature verifies against a fingerprint you already had.
  • Handed out with a PGP block, not a countdown.
  • Only ever asks you to act inside Tor.
  • You fetched it yourself from a source you keep.
WHY IT EXISTSthe reasoning

Why a Torzon URL validator exists at all

A Torzon onion address is a 56-character string with no memorable pattern — nothing about it is meant to be typed from memory or recognized at a glance. That is a deliberate property of how Tor onion services work, not a design flaw, but it does mean the normal human habit of eyeballing a URL and deciding it "looks right" fails completely for Torzon and every other onion service. The validator on this page exists specifically to replace that unreliable habit with an exact, mechanical comparison.

The problem with trusting memory

Nobody memorizes a 56-character Torzon onion string, so every visit involves either copying a saved address or pasting one from somewhere else — a bookmark, a forum post, a search result. Each of those sources can be wrong, and a wrong source that is 90% correct looks, to a tired human eye late at night, exactly like a correct one. The Torzon validator does not get tired and does not skim.

What "exact match" means in practice

The validator does not attempt fuzzy matching, similarity scoring, or "close enough" logic of any kind. A Torzon address either matches one entry in the signed canon list character for character, or it is rejected outright. This is intentional: onion addresses are cryptographic identifiers, not brand names, and there is no such thing as a legitimate near-variant of a real Torzon address.

What the validator deliberately does not do

It does not fetch the address over the network, does not check whether the corresponding onion service is currently reachable, and does not make any claim about the content behind a matching Torzon address. Format validation and reachability are different questions; conflating them is how some competing "checker" tools give a false sense of security. Pair a passing result here with the PGP signature check described on the PGP page for the complete picture.

COMMON ERRORSwhat trips people up

Common mistakes when checking a Torzon address

Most failed Torzon verifications trace back to one of a handful of avoidable habits. Recognizing them in advance is faster than debugging a bad paste after the fact.

Pasting from a screenshot instead of text

A screenshot of a Torzon address cannot be pasted as text at all, which forces manual retyping — and retyping a 56-character string by hand is exactly the kind of error-prone step this validator exists to eliminate. Always insist on a copyable text source for any Torzon address.

Trusting autocomplete or browser history

A browser that has previously visited a phishing clone may autocomplete toward that clone's Torzon-look-alike address the next time you start typing. Never accept an autocompleted suggestion for a Torzon onion address without running it through the validator first.

Stopping at "genuine format"

A validator pass confirms the string matches the canon list — it is not, by itself, proof the underlying Torzon service is safe to log into. Finish with the PGP signature check before entering any credentials.

Reusing an old saved address without rechecking

Mirror status changes over time, and a Torzon address saved months ago may now point at a dead or reassigned mirror. Recheck a saved address against the current canon periodically rather than assuming yesterday's verification still holds.

CHECKLISTbefore you trust a result

Torzon validator checklist: reading the result correctly

A pass from the Torzon validator is one input into a decision, not the whole decision. Use this short checklist every time you run a Torzon address through the tool above.

  1. Paste the Torzon address as text, never retyped from memory or a screenshot.
  2. Confirm the validator reports an exact Torzon canon match, not a partial or fuzzy result.
  3. Treat a rejected Torzon address as rejected — do not manually override or "fix" a near-miss.
  4. Follow a passing Torzon result with the PGP signature check on the mirror list.
  5. Recheck any saved Torzon address periodically rather than trusting last month's pass.

The Torzon validator and the PGP check are complementary, not redundant — format matching catches typos and near-miss clones, while the signature catches everything else. Together they are the two checks this entire Torzon reference is organized around, and neither one alone is a substitute for running both before you open a Torzon onion address in Tor Browser.

LIMITSwhat a validator cannot do

What this Torzon validator cannot tell you

An exact character match against the signed canon proves one thing precisely: the address you pasted is the same string this reference has on file. It does not prove the market behind that address is honest, that an order will be filled, or that the site has not been quietly compromised at the server level while keeping the same onion key — a scenario that is rare but not theoretical, since an onion address is tied to a cryptographic key, not to the server's ongoing integrity.

Match plus PGP, not match alone

That is why this page pairs the validator with the PGP fingerprint check rather than presenting either as sufficient by itself. A matching address with an unverifiable or mismatched signature is still a reason to stop, not proceed — the two checks catch different failure modes, and skipping one to rely on the other narrows the protection this reference is built to provide. A validator that returned a green result on address alone, with no PGP layer at all, would be trivial for a clone to defeat: simply register a phishing page under the exact address text once it is known, which the address-only check could never catch but a fingerprint mismatch would.

QUESTIONSplain answers

Validator questions

Does the validator send my link anywhere?

No. The address list is baked into the page and the comparison runs locally. Nothing about what you paste leaves your browser.

It says genuine format. Am I fully safe now?

Not on its own. A format pass means the string matches our list. Finish with the PGP signature check on the mirror list before you trust it.

Why reject an address that is almost right?

Because almost is exactly how clones work. Onion addresses have no near-misses; a changed character is a different key and a different server.

Where do I get a link to test?

Copy one from the mirror table on the canon, then paste it here to confirm the tool agrees.

RELATED

Before and after the check

New to the pieces, or ready to connect? Read what an onion link is, then follow how to access Torzon.

Read the access guide