Short answer: Download Tor Browser only from torproject.org or the official store, verify the signature, connect, and keep default settings until your threat model requires otherwise. Add-ons and third-party “portable” bundles are a common risk.
Tor Browser is the recommended way to reach websites through the Tor network. Background: What is Tor?. If relays are blocked: Tor bridges. It is based on Firefox ESR, routes browser traffic through Tor, and adds protections against tracking and fingerprinting. Safe setup is not just clicking Install: source, freshness, connection method, and behavior matter equally.
This guide covers Windows, macOS, Linux, and Android. Menu names may shift between versions; the Tor Project manual remains authoritative. There is no official Tor Browser for iOS; the Tor Project recommends Onion Browser there, with technical limits compared to desktop.
Before download: clarify your threat model
Decide what you need: less tracking, research without direct IP linkage, or access in a censored network? Must the fact that you use Tor stay hidden? Could the device be seized or infected? These questions determine whether a standard install is enough.
Tor Browser protects the network path and unifies many browser traits. It does not protect a compromised OS, voluntary account logins, or leaky document metadata. A personal login still identifies you to that service. At high individual risk, seek qualified digital security advice.
Update the device first: OS patches, a non-shared user account, obvious malware removed. A current browser on an unsafe machine is weak protection. For especially sensitive work, Tails or a clean isolated environment may fit better if practiced beforehand.
1. Open the official source
Visit https://www.torproject.org/ directly. The domain must match exactly; HTTPS must not show certificate warnings. Avoid download portals, ads, and random mirrors. Tampered packages can defeat every later safeguard.
If the site is blocked, use documented Tor Project alternatives such as GetTor and official mirrors. Confirm addresses via a second trusted channel when possible. A file posted in a random forum is not a reliable source.
On Android, use Google Play or the official Tor Project F-Droid channel. For sideloaded APKs, use only the project site. On iOS, an app named “Tor Browser” is not automatically official. Phone-specific limits: Tor on mobile.
2. Download the right build
Choose OS and architecture. Save the file, note the version, and do not run it immediately. Cached installers go stale; when in doubt, re-download from the primary source.
A normal download may tell your ISP you fetched a Tor Project file. That is fine in many cases. If even that is sensitive, consider a trusted network, an official mirror, or GetTor — chosen to match your model, not under panic.
3. Verify signature or provenance
The Tor Project publishes cryptographic signatures for desktop packages. Verification checks that the file was signed with an expected project key and was not altered. It does not prove your device is clean, but it strongly protects against tampered downloads.
Follow the official OpenPGP steps for your OS. Import signing keys only via documented fingerprints. Skipping verification for a “simpler” unofficial installer is a common mistake.
4. Install Tor Browser
Windows: Run the installer, pick language and location. Avoid shared or cloud-synced folders if local visibility matters.
macOS: Open the disk image, drag to Applications. Do not bypass unexpected publisher warnings without re-downloading from the official source.
Linux: Extract the archive to your home directory and use the launcher. Do not trust random distro packages that may be outdated or misconfigured.
Android: Install from the confirmed store source. Do not leave “install unknown apps” enabled broadly.
5. First connection
Choose Connect on an unfiltered network. The first circuit build can take longer than a normal browser start. On a private machine, auto-connect may be reasonable; on a shared machine, saved settings can reveal Tor use.
If connection fails, check system date/time, captive portals, and official troubleshooting — do not blanket-disable security software.
6. Bridges when blocked
Open connection settings and choose a bridge when direct Tor access is filtered. obfs4 disguises traffic as random data. Snowflake uses short-lived WebRTC proxies. meek routes through allowed web infrastructure and may be slower.
Do not publish private bridges widely. Bridges improve reachability, not automatic “more anonymity.”
7. Security level
Via the shield icon: Standard for compatibility, Safer limits risky features on HTTP sites, Safest disables JavaScript by default. Higher levels reduce attack surface but break sites. Do not tweak about:config or add extensions to “harden” — uniqueness hurts the Tor Browser threat model. What each level disables, and why NoScript is not a second preset: Tor Browser security levels.
8. HTTPS and site identity
Tor encrypts inside the circuit; clearnet traffic still exits to the destination. HTTPS protects to the site and authenticates the domain. Many services offer both HTTPS and onion versions. A real onion address must come from the operator’s official channel — TorBible does not publish onion link lists.
Phishing works in Tor Browser too. Use password managers and bookmark verified addresses for critical services.
9. Separate identities and sessions
Tor does not hide what you tell a site. New Identity clears session state and requests new circuits; it cannot unsend data. New Circuit for this Site changes the path for one site context only. Writing style, timing, and reused pseudonyms still link roles.
10. Downloads and external apps
Opened documents may phone home outside Tor. Torrent clients must not run over Tor. Keep the browser and OS updated.
11. Verify it works
Visit https://check.torproject.org/ after connecting. It confirms the browser path uses Tor, not that every app on the device does.
Common mistakes
Unofficial downloads, extra extensions, ignored certificate warnings, assuming Tor anonymizes personal logins, and mixing roles across contexts. Tor is transport and browser tooling, not automatic identity management.
Conclusion
Safe Tor Browser setup starts at the official source, verified packages, appropriate bridges if needed, and a deliberate security level. HTTPS, updates, and unchanged defaults matter. Installation takes minutes; separating identities is ongoing work.
Sources
- Tor Project: Tor Browser User Manual
- Tor Project: Downloading
- Tor Project: Verifying the signature
- Tor Project: Circumvention and bridges
- Tor Project: Security settings
- Electronic Frontier Foundation: How to use Tor