Connectivity Quick Answers
Answers for the moment Tor itself appears blocked, throttled, or refused. Mirror choice, bridge configuration, mobile access, address verification. Still stuck? Write the connectivity team.
About the Gateway
Torzon Gateway is the independent connectivity layer in front of the Torzon onion service. It publishes the authenticated mirror addresses, distributes signed lists of bridge relays, and documents which pluggable transports defeat which blocking technique. It does not operate the marketplace's escrow, vendor system, or any transaction-side feature. The full positioning is on the About page.
The Gateway has operated since 2022. The PGP fingerprint used to sign the mirror manifest has not rotated since launch — that key is the single chain of trust for every address we publish. Connectivity milestones are documented on the About page.
No. Reading the page, copying a mirror address, fetching a bridge line, or writing to connectivity support is free of charge. There are no Gateway accounts to register and nothing to subscribe to.
Bridges & Pluggable Transports
Open Tor Browser's Connection Settings, choose Use a bridge, and either pick a built-in obfs4 bridge or paste one of our published bridge lines. If obfs4 IPs are also being blocked, switch to snowflake — it routes through volunteer WebRTC proxies whose addresses change constantly. The full walkthrough is in the access guide.
A pluggable transport disguises Tor traffic so DPI cannot fingerprint it. obfs4 randomizes the bytes — works against most ISPs and is the right default. snowflake hops through ephemeral WebRTC proxies — best where bridge IPs are constantly burned. meek-azure tunnels through Microsoft's CDN — necessary on corporate networks that only allow HTTPS to known fronts.
In Tor Browser open Settings → Connection → Bridges → Add a bridge manually, then paste a bridge line in the format
obfs4 IP:PORT FINGERPRINT cert=… iat-mode=0. Our bridge list is signed with PGP fingerprint 8C71 4F25 6A93 D182 E574 B91C 3D67 8F45 A2D6 C918 — verify before pasting.Yes, and we recommend it for users whose family or social graph keeps hitting the same blocks. A $5/month VPS in a friendly jurisdiction is enough. The access guide includes a self-host walkthrough for obfs4; once the bridge is up, share the bridge line with the people you trust and they get a dedicated, low-traffic entry point.
Mirrors & Reachability
The mirror with the lowest probe latency from your bridge exit. Empirically: Mirror α is tuned for obfs4 (residential ISPs that DPI-fingerprint Tor), Mirror β for snowflake (regions where bridge IPs are burned), Mirror γ for meek-azure (CDN-front transport behind corporate proxies). The reachability monitor on the home page reflects current status from inside three censored test networks.
Single-endpoint services fail the moment one upstream buckles under throttling, DDoS or coordinated AS-level filtering. Three independent onion services on three distinct hosting regions, with three separate guard relay sets, means at most one region drops at a time. The other two stay reachable, the monitor reflects which.
Stall at 10% almost always means the firewall is blocking guard IPs at the network layer. The standard Tor directory is unreachable. Solution: configure a bridge with a pluggable transport — start with obfs4, fall back to snowflake if obfs4 IPs are also blocked. If the bootstrap completes but onion sites time out, the failure is DPI fingerprinting Tor TLS instead.
Three checks. (1) Source — only ever copy from this signed page; bookmark it. (2) Length — every v3 onion address is exactly 56 base32 characters before
.onion; v2 addresses (16 characters) are deprecated and should be treated as hostile. (3) Signature — apply our PGP public key against the signed address manifest. A valid signature is the only authentic chain of trust.Mobile Access
Yes. Install Orbot from F-Droid or Google Play. Orbot 17.x supports the same three pluggable transports — obfs4, snowflake, meek-azure — and accepts bridge lines either pasted as text or imported via QR code. Once Orbot is connected, open any Tor-capable browser (Tor Browser for Android works best) and visit the mirror address.
Install Onion Browser from the App Store. It supports built-in obfs4 and snowflake bridges. meek-azure is more limited on iOS due to Apple's networking restrictions. Onion Browser 3.x has been verified against all three Gateway mirrors as of May 2026.
OPSEC & Traffic Analysis
Vanilla Tor is detectable by passive traffic analysis because the TLS handshake has a recognizable signature. With a pluggable transport over a private bridge, the traffic looks like generic encrypted noise. Add a no-log VPN as an outer layer and an upstream observer sees only opaque data flowing to one IP — no Tor signature.
A VPN is not strictly required and Tor itself does not depend on one. A VPN as an outer wrapper (VPN → Tor) hides from your ISP the fact that you are using Tor at all, which matters in jurisdictions that monitor Tor usage. Choose a no-log provider that accepts cryptocurrency, and connect to the VPN before launching Tor Browser or Orbot.
Phishing pressure intensifies whenever a national firewall rolls out new blocking — operators of replicas know exactly when users panic-search for a fresh entry point. Defences: bookmark this Gateway in your existing browser and return to it for every fresh address; reject any onion address dropped in censorship-help chatrooms or bridge channels; validate the PGP signature on the published address manifest, not just the visible page text.
Write to [email protected] with your country and observed symptoms (where the bootstrap stalls, what error appears, what transports you have tried). We can often suggest a private bridge or test a fresh transport build. PGP-encrypted messages preferred — our key fingerprint is documented under Network Security.
Need More?
The access guide covers every transport end-to-end. The security page documents PGP verification and traffic-analysis resistance.
