Dark web security checklist
Print or bookmark this checklist. Use it before your first darknet market session and review the per-session section every time you connect.
Before first darknet market access
- Tor Browser downloaded exclusively from torproject.org and fully updated.
- PGP key pair generated; public key ready to share with vendors; private key backed up offline.
- Monero (XMR) wallet set up; funds available for transactions.
- Darknet market onion address verified from two independent trusted sources.
- Unique username and strong random password generated for the target market.
- No personal identifiers (real name, email, phone) used in any market registration.
Each dark web market session
- Onion address re-verified against trusted source before connecting.
- No clearnet accounts (email, social media) open in same Tor Browser session.
- 2FA (PGP-based preferred) enabled and tested on market account.
- PGP 2FA login challenge successfully decrypted—confirms genuine mirror.
- Shipping address encrypted with vendor PGP public key before sending.
- Escrow confirmed active; 'finalize early' request refused regardless of vendor pressure.
Baseline security controls
- OS and Tor Browser automatic updates enabled; pending reboots completed.
- Password manager active with unique credentials for all accounts.
- Phishing-resistant MFA on email and financial accounts.
- Large cryptocurrency balances withdrawn from market wallets after use.
- No market-related discussion on clearnet platforms or unencrypted channels.
- Files from darknet markets opened in isolated VM only, never on primary OS.
Why Tor Browser alone is not enough
Tor handles network anonymity—it hides your IP from darknet markets and hides your destinations from your ISP. It does not protect against malware on your device, operational mistakes, or identity correlation through repeated patterns. The checklist above addresses the layers Tor does not cover. Revisit after major life events, travel, or vendor breaches affecting services you use. See also the darknet markets directory for verified current onion addresses.