Hextner
VerifIPDetectBTPricingDocsSupport
Sign inStart free →
  1. Hextner
  2. Glossary
  3. Tor exit node

What is a Tor exit node? 

A Tor exit node is the last relay in a Tor circuit: the server that sends a Tor user’s traffic out to the open internet, so websites see the exit node’s IP address instead of the user’s.

Tor is used by journalists, activists and people who want privacy, and also by attackers who want to hide where they are. Most Tor users are not abusive, but anonymity makes abuse cheap to repeat.

How are Tor exit nodes detected?

The Tor Project publishes the addresses of its current exit relays. Checking a client address against that list is reliable as long as the list is fresh, because relays come and go. Exits are listed per address, not per network range.

Should you block Tor?

It is a policy choice. A news site may welcome Tor users; a payment page or a promotion may not accept anonymous traffic. Many services allow Tor for reading and add a step-up check, such as email confirmation, for actions that cost money.

How Hextner uses it

VerifIP imports the Tor Project's exit list every 6 hours, adds IPv6 exits from Tor relay data, and returns is_tor: true. A Tor exit alone scores 25 and stays allow, because using Tor is not evidence of abuse; the verdict changes only when accusing evidence, such as an attack-feed listing, fires too. If a route should refuse anonymous traffic, read is_tor directly. The sources are on data sources and the weights in the VerifIP reference.

Related reading

  • IP fraud score
  • Datacenter IP
  • Residential proxy
  • ASN (autonomous system number)

Browse every definition in the glossary.

Hextner

Adversarial traffic detection for teams that ship to the open internet.

Product

  • VerifIP
  • DetectBT
  • Pricing
  • Documentation

Company

  • Support
  • Release notes
  • Talk to sales
  • Get an API key
  • Console

Resources

  • Glossary
  • Use cases
  • India

Stay in the loop

Release notes (also as an RSS feed), new signals, and the occasional write-up on how detection actually gets evaded.

Create an account →

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP blocklist data: The Spamhaus Project (DROP). Phishing data: PhishTank, CC BY-SA 2.5. Malware data: abuse.ch. Hextner uses the IP2Proxy LITE database for IP geolocation. Full notices: Data sources.

© 2026 Hextner. All rights reserved.
Privacy PolicyTerms of ServiceData sources