The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. At least one form appears to submit information to another hostname. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that torproject.org is legitimate or fraudulent.
Is torproject.org safe?
Independent website safety report covering the connection, domain history, browser protections, page behavior and reputation signals observed by DarkOra.
What the latest scan says about torproject.org
DarkOra separates technical evidence from community opinion and explains the factors behind the score.
Valid TLS certificate observed
CSL Computer Service Langenbach GmbH d/b/a joker.com
5 of 6 monitored headers
MDN HTTP Observatory result
Evidence that influenced the score
Review both columns. A high total score does not cancel a material caution signal.
Signals that support trust
Valid TLS certificate
The certificate is trusted, matches the hostname and is currently valid.
TLS · transport · +7 pointsHTTPS is active
The final page is delivered through an encrypted HTTPS connection.
Transport · transport · +4 pointsLong-established domain registration
Registration records indicate an age of about 19 years.
RDAP · domain · +4 pointsWebsite responded successfully
The scanned destination returned HTTP 200.
HTTP · transport · +3 pointsDomain email controls are published
The domain exposes multiple mail-routing or anti-spoofing controls.
DNS · domain · +2 pointsHSTS is present
The response includes the strict-transport-security header.
Security headers · security · +2 pointsContent Security Policy is present
The response includes the content-security-policy header.
Security headers · security · +2 pointsStrong MDN Observatory grade
MDN HTTP Observatory assigned grade A+.
MDN HTTP Observatory · security · +2 pointsContact route found
The page exposes a contact or support page.
Content · transparency · +2 pointssecurity.txt is available
A security contact file was found under .well-known.
Public files · transparency · +2 pointsNormal homepage content was accessible
The scanner received a usable HTML homepage rather than an interstitial or access-control page.
Content · behavior · +2 pointsNo monitored high-risk wording detected
The accessible homepage did not contain the monitored high-pressure or credential-request phrases.
Content · behavior · +2 pointsResponsive origin server
The initial request completed in about 571 ms.
Performance · transport · +1 pointsPublic DNS resolution
The domain resolves to 8 validated public network addresses.
DNS · domain · +1 pointsNameserver redundancy
At least two authoritative nameservers were found.
DNS · domain · +1 pointsCertificate authority policy
CAA records restrict which authorities may issue certificates.
DNS · domain · +1 pointsDNSSEC validation confirmed
Google Public DNS returned authenticated DNS data for this hostname.
Google Public DNS · domain · +1 pointsPublic routing identity found
RIPEstat mapped the address to AS24940 and prefix 116.202.0.0/16.
RIPEstat · domain · +1 pointsMIME sniffing protection is present
The response includes the x-content-type-options header.
Security headers · security · +1 pointsReferrer policy is present
The response includes the referrer-policy header.
Security headers · security · +1 pointsClickjacking protection
Framing is restricted through X-Frame-Options or CSP.
Security headers · security · +1 pointsHSTS preload list entry
The hostname is included in Chromium’s HSTS preload status data.
Chromium HSTS Preload · security · +1 pointsDescriptive page title
The homepage provides a usable browser title.
Content · transparency · +1 pointsPage description is provided
The homepage includes a descriptive meta summary.
Content · transparency · +1 pointsSome policy information is linked
At least one policy or company-information page was found.
Content · transparency · +1 pointsrobots.txt is available
The website publishes a non-empty robots.txt file.
Public files · transparency · +1 pointsSubstantive homepage content
The scanned page contains enough readable text to explain its purpose.
Content · transparency · +1 pointsConsistent canonical redirect
Redirects remain within the same domain family.
HTTP · behavior · +1 pointsSignals worth reviewing
Form submits to another domain
1 form appear to send data to a different hostname.
Forms · behavior · -5 pointsMissing permissions-policy
The response did not include this browser security header. Missing headers affect hardening, but do not by themselves prove fraud.
Security headers · securityNetwork, certificate and page-level observations
These values were captured at scan time and may change after a server, DNS or certificate update.
Infrastructure footprint
- Resolved IP addresses
- 204.8.99.146, 116.202.120.165, 116.202.120.166, 204.8.99.144, 95.216.163.36, 2620:7:6002::466:39ff:fe32:e3dd
- Authoritative nameservers
- 6
- Mail / MX records
- 1
- CAA policy
- Published
- SPF policy
- Published
- DMARC policy
- Published
Connection security
- HTTP status
- 200
- Final protocol
- HTTPS
- Certificate validation
- Trusted and valid
- Certificate issuer
- TLS protocol / cipher
- TLSv1.3 TLS_AES_256_GCM_SHA384
- Certificate expires
- October 23, 2026
Registration context
- Approximate age
- 19.8 years
- Registered
- October 17, 2006
- Expires
- October 17, 2027
- Registrar
- CSL Computer Service Langenbach GmbH d/b/a joker.com
- RDAP status entries
- 1
- RDAP available
- Yes
5/6 monitored protections detected
External security and reputation context
Provider failures stay separate from the base scan. DarkOra never fabricates a provider result.
DNSSEC authenticated data
The AD flag confirms that the DNS answer was validated through DNSSEC.
Response code 0 · 6 answersIndependent header grade
MDN evaluated the live HTTP security configuration independently from DarkOra.
115 points · 10/10 tests passedPreload-list status
Browsers can enforce HTTPS before the first network request.
Independent transport-hardening contextRouting and origin identity
The scanned address maps to prefix 116.202.0.0/16.
BGP present · registry presentOfficial threat-list context
The optional official Web Risk integration is not configured.
Checked Jul 27, 2026Official profile lookup
Trustpilot requires an official API key. DarkOra does not scrape profile pages.
Open Trustpilot profileResponse and redirect details
- Origin address used
- 116.202.120.166
- Server header
- Apache
- Content type
- text/html
- Downloaded response
- 23,012 bytes
- Redirect hops
- 1
- Initial response time
- 571 ms
What the homepage exposes
- Internal links
- 65
- External links
- 17
- External-link ratio
- 21%
- Forms detected
- 1
- Suspicious phrase groups
- 0
- Scanner methodology
- Version 4.0.0
Questions about this website safety report
Plain-language answers explain what the score can and cannot tell you.
Is torproject.org safe to visit?+
The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. At least one form appears to submit information to another hostname. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that torproject.org is legitimate or fraudulent.
What is the DarkOra score for torproject.org?+
The latest DarkOra website safety score is 85 out of 100, classified as Strong trust signals. The score reflects observable technical and reputation evidence collected during the latest scan.
How is this website safety score calculated?+
DarkOra uses six independently capped areas: connection and TLS, domain maturity and DNS, browser security, identity and transparency, page behavior, and external reputation. No single signal determines the entire score.
When was torproject.org last checked?+
The report was last updated on July 27, 2026. Website, DNS and certificate settings can change after this time.
Does a high score prove that torproject.org is legitimate?+
No. Automated evidence can reduce uncertainty, but it cannot prove ownership, product quality or honest intent. Verify the organization, payment destination, refund terms and independent reputation before sharing sensitive information.
Reviews from DarkOra members
Account-linked reviews are screened for spam and published only after manual moderation.
No approved community review yet
Be the first member to describe a direct experience with this website.
Write a review
Sign in with your DarkOra account to submit a moderated review.
Sign in to reviewUse this report as one part of your decision. Automated checks can miss newly created threats and may flag legitimate configurations. Verify the organization, payment recipient, refund terms and independent reputation before sharing money, credentials or sensitive data.
