Independent Tor encyclopedia Guides
Guides

How to Verify a Newsroom Onion

How a reader checks a SecureDrop onion against the Freedom of the Press Foundation directory and the outlet’s own landing page — not against a homemade list.

Where to copy a newsroom onion from Three steps. Copy from the Freedom of the Press Foundation SecureDrop directory, then from the outlet’s own landing page, then compare the full v3 string character by character. Do not use search ads or random lists. 01 FPF directory securedrop.org/directory Not a search ad 02 Outlet page Tips / SecureDrop landing Plain-text onion only 03 Full string All 56 characters match Prefix match = clone 01 FPF directory securedrop.org/directory Not a search ad 02 Outlet page Tips / SecureDrop landing Plain-text onion only 03 Full string All 56 characters match Prefix match = clone
Copy the onion from the FPF SecureDrop Directory, then from the outlet’s own Tips / SecureDrop page. Compare the full 56-character v3 string. A matching prefix is how clones look real.

Short answer: A newsroom .onion is a public key, not a logo. Copy it from two places that already agree: the SecureDrop Directory (Freedom of the Press Foundation) and that outlet’s own SecureDrop landing page. If those two strings differ, do not submit. Do not compile a third list. Do not trust a search ad.

This page is a check, not a catalog. We do not print outlet onions here. Background: press freedom, SecureDrop, and the general rule in verified onion links.

Procedure

  1. Open the SecureDrop Directory on a channel you already trust (clearnet in a normal browser is fine for this lookup). Find the outlet. Copy the full v3 onion string — not just the short ….securedrop.tor.onion name.
  2. Open the outlet’s own Tips / SecureDrop / Contact landing page. Landing pages are supposed to print the onion as plain text, not as a clickable http://….onion link. Copy that string.
  3. Compare all 56 characters. A shared prefix is how vanity clones look real. The middle that fails is the tell.
  4. If they match, paste the onion into the Tor Browser address bar. Do not follow a hyperlink from email or a random list.
  5. If they differ, stop. Report the discrepancy through the SecureDrop site in Tor Browser (FPF’s source docs). They will correct the directory if it is wrong.

What FPF actually maintains

Each organization runs its own SecureDrop. FPF maintains an incomplete directory of instances that meet their listing rules — not every newsroom, and not a live availability probe you should treat as an oracle. Directory entries also carry a human-readable onion name (….securedrop.tor.onion) that Tor Browser maps, via a signed ruleset FPF publishes, to the full v3 address. Desktop Tor Browser is what those names need.

A short onion name is not a second source. It is FPF’s map of names they already listed. If the directory and the landing page disagree, neither the name nor the long string is safe to use yet.

What a clone looks like

Same masthead, same “SecureDrop” word, a v3 string that shares a prefix with the real one. Vanity grinding makes the start look right. Search results and “new mirror” posts are how those copies spread — the same social attack as any other onion, described in phishing detection.

What we will not do

We will not paste a table of NYT / Guardian / BBC onions into this article. TorBible’s whistleblowing directory only shows strings already in our files, and it tells you to confirm them on the official SecureDrop directory first. That directory is the list. Ours is not a fork of it.

Sources

See also: source vs journalist path.