Your online banking page is on the deep web. So is your email inbox, your company intranet and every article behind a paywall. None of that is sinister, and none of it is the dark web. The confusion between deep web and dark web is so widespread that even news reports mix them up, which makes it hard to judge what is actually risky. This page separates the three layers of the internet with concrete examples, shows where the dark web sits in that picture, and explains why the words matter when you read about breaches, leaks and onion sites.
The surface web: what search engines can reach
The surface web is everything a search engine can crawl and index. When you search for a recipe and land on a cooking blog, you are on the surface. The page has a public address, no login wall, and the site owner allows crawlers to read it.
The surface web is smaller than most people assume. Search engines index only pages that are linked from other pages and that the owner has not blocked. A page that exists but is never linked, or a page that requires a form submission to reach, does not appear in results even though anyone could visit it with the right URL.
The practical point is that "not on Google" does not mean hidden or illegal. It usually just means not linked, not crawlable, or blocked by the site owner through a robots file. Most of the internet falls into that category.
Site owners can also ask search engines to remove pages, which is why some public content disappears from results without disappearing from the web.
The deep web: everything behind a login or a query
The deep web is the part of the internet that search engines cannot index, mostly because it sits behind authentication or is generated on demand. Deep web examples are ordinary:
- Your webmail inbox and cloud storage.
- Online banking dashboards and medical patient portals.
- University library databases and paywalled journals.
- Company intranets, ticketing systems and internal wikis.
- Database results that only appear after you fill a search form on a site.
By any measure the deep web is far larger than the surface web, simply because personal and organizational data dwarfs public content. Nothing about it requires special software. You reach it with a normal browser and, usually, a password.
When someone says a leak was "found on the deep web," they may mean an exposed database that was never meant to be public. That is a security failure, not a hidden network. The data was sitting on an ordinary server without a password.
The dark web: a network you need special software to enter
The dark web is a small subset of the deep web that lives on overlay networks, most commonly Tor. Sites on it use onion addresses that ordinary browsers cannot resolve. To visit one you need Tor Browser or similar software, and the site's location is hidden by design.
The defining feature is not secrecy of content but the anonymity architecture. A dark web site can be a newspaper's whistleblower drop box, a privacy-focused email provider, a copy of a mainstream site for readers in censored countries, or a forum where stolen data is traded. The same technology serves all of them.
Examples of the dark web that are entirely legal include onion mirrors run by major news organizations, the Tor Project's own documentation, search engines that index onion services, and libraries of public-domain books. The illegal parts exist too and get most of the attention, which is why the whole layer carries a reputation that the technology itself does not deserve.
Why the distinction matters when you read the news
Headlines regularly say that personal data was "found on the dark web" when it was actually posted on a surface-web forum or a public paste site. The imprecision changes how you should react. Data on an open forum can be indexed and copied by anyone in minutes. Data on a members-only onion forum spreads more slowly but is harder to monitor.
The mix-up also drives bad decisions. People install Tor to "check the deep web" for their information, which is neither necessary nor useful; breach lookups on the surface web already index that data. Others assume that using a bank portal or a corporate VPN puts them somewhere dangerous, when it is just the deep web doing its job.
A clean rule: if you reached it with a password in a normal browser, it is deep web. If you needed Tor and the address ended in .onion, it is dark web. If a search engine could have shown it to you, it is surface web.
How the layers connect in practice
The three layers are not separate internets. They are the same physical network viewed through different access rules. A single organization can span all three: a public marketing site on the surface, a customer portal on the deep web, and an onion mirror on the dark web for readers who need anonymity.
Tor itself blurs the boundary. You can use Tor Browser to visit surface websites, and your traffic exits the network through a relay so the site sees the relay's address rather than yours. That is Tor as an anonymity tool for the ordinary web. Onion services are the additional step where the site itself is inside the network and never exposes a public address.
For the reader this means Tor is not a door into a separate place. It is a different route through the same internet, plus a set of destinations that only exist along that route.
Context from people who study and police these layers
- Tor Project documentation describes onion services as ordinary web servers reachable only through the network; the software does not distinguish legal from illegal content. For you this means the dark web is a tool, and the risk comes from where you go and what you download, not from the connection.
- Academic research on onion services has found that a substantial share of active onion sites are non-criminal: mirrors, infrastructure, personal pages and privacy services. It corrects the impression that every onion address is a market.
- Public law-enforcement statements about breach investigations often refer to stolen data appearing on "underground forums," many of which run on the surface web with ordinary domains. The lesson is that the dark web is not the only place leaked data travels.
- Security-vendor reports on data exposure regularly attribute leaks to misconfigured cloud storage rather than to any hidden network. Most "deep web" leaks are simply servers without passwords.
A clearer way to think about it, and one thing to do
Instead of picturing an iceberg with a dark tip, picture access rules. Public and indexed is the surface. Private and password-protected is the deep. Reachable only through an anonymity network is the dark. Content and legality vary in every layer; only the access method changes.
If you want to see the difference for yourself without any risk, do this: open the Tor Project website in your regular browser and read its short overview of onion services. You will have visited the surface web, learned how the dark web is built, and never needed to touch it.
If you want a second exercise, pick a breach-notification headline from this week and ask where the data actually appeared: an open paste site, a members-only forum on the regular web, or an onion service. In most cases the answer is one of the first two, and the phrase in the headline was chosen for effect rather than accuracy. Learning to make that distinction is most of what this topic requires.
Frequently asked questions
What is the difference between deep web and dark web?
The deep web is everything search engines cannot index, mostly pages behind logins such as email, banking and intranets. The dark web is a small part of the deep web hosted on anonymity networks like Tor, reachable only with special software through .onion addresses.
Is the deep web illegal?
No. The deep web is mostly private data that belongs to you or to organizations: inboxes, patient records, paid content. Using it is a normal part of everyday internet use. Legality depends on what you do, not on which layer you are in.
What are examples of the dark web that are legal?
Onion mirrors of major news organizations, whistleblower submission systems used by newsrooms, privacy-focused email and chat services, search engines for onion sites, the Tor Project's own pages, and libraries of public-domain books all run as legal onion services.
How big is the dark web compared to the deep web?
The dark web is tiny by comparison. The deep web includes every private account and database online, which dwarfs public content. Active onion services number in the tens of thousands at most according to Tor Project metrics, while deep web pages are effectively uncountable.
Do I need Tor to see the deep web?
No. The deep web is reached with a normal browser and usually a password. Tor is only needed for the dark web, meaning onion services and anonymous browsing.
Sources and further reading
- Tor Project: onion services overviewcommunity.torproject.org
- Wikipedia: Dark weben.wikipedia.org
- Wikipedia: Deep weben.wikipedia.org
- Tor Project metrics: onion services statisticsmetrics.torproject.org