When Tor Itself Is Blocked: What Bridges Actually Do
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
If Tor will not connect from where you are, the reason is usually structural rather than mysterious. Tor's main list of relays is published deliberately, so that clients can find their way into the network without trusting a central authority — and the same openness that makes the design trustworthy makes the entry points trivially easy for a national filter to enumerate and block. Bridges exist to solve exactly that problem. This part of the series covers what they are, what pluggable transports add on top, and the important limits of both.
Why the Public Relay List Is Both the Strength and the Weakness
Tor's directory of relays is public so that anyone can verify the network rather than take its composition on trust. That transparency is genuinely load-bearing for the security model: a network whose membership is secret would require you to trust whoever curates it. The cost is that a censor can download the same list you do. Filtering every published entry point is neither difficult nor expensive, and it is the first measure most blocking regimes take. So a failure to connect from a censored network is rarely a sign that Tor has been broken. It is a sign that the front door, which is advertised on purpose, has been closed.
Bridges: Entry Points That Are Not on the List
A bridge is a Tor relay that is not published in the public directory. Because a censor cannot enumerate what it cannot see, a bridge address you obtain privately will often work where every listed relay fails. Tor Browser ships with some built-in bridges and can request others, and the project distributes them through channels designed to make bulk harvesting awkward — the difficulty of getting the whole list is the point of the mechanism. The practical implication is that bridges are a finite, contested resource rather than a permanent fix: an address that circulates widely eventually reaches the censor and stops working, which is why they are distributed in small numbers rather than published.
Pluggable Transports: Making Tor Traffic Not Look Like Tor
Hiding the address only helps if the traffic itself is not recognisable, and sophisticated filtering does not rely on address lists alone — it fingerprints the shape of the connection. Pluggable transports address that second problem by transforming Tor traffic so it does not carry the characteristics a filter looks for, in some cases by making it resemble ordinary encrypted web traffic, in others by relaying it through infrastructure that a country is unwilling to block wholesale because too much legitimate traffic depends on it. Which transport works where changes over time, because this is an adversarial contest with both sides adapting. That is also why advice on the subject dates quickly, and why the Tor Project's own current documentation is the only sensible source for what to use today.
What Bridges Do Not Do
Two limits matter, and both are commonly misunderstood. First, a bridge is a circumvention measure, not a legal one. It addresses whether you can connect, and says nothing about whether connecting is permitted where you are — a distinction covered in full in blocked is not the same as illegal. In a country that has criminalised the use of anonymity tools, evading the block successfully is not a defence, and it may be treated as an aggravating fact rather than a neutral one. Second, a bridge changes how you enter the network and nothing about what happens afterwards. Everything in what your ISP can see still applies to the rest of your setup: applications not routed through Tor still connect directly, and information you hand to a destination is still handed over.
If You Are Behind a Filter
The correct starting point is the Tor Project's own documentation and its current bridge distribution channels, not a bridge address pasted into a forum or a video description, which is both likely to be dead and impossible to verify. Treat any third party offering bridges with the same caution you would apply to any other unverified entry point into your network, because that is precisely what it is. And before any of the technical work, answer the question the technical work cannot: whether the law where you are addresses this at all. If the block is simply a filter in a country that has not criminalised the tool, a bridge is a reasonable and lawful way to reach a lawful network. If the law does address it, the decision is a different one entirely, and it deserves better information than a general guide can give — start with how to check the law where you actually live.
Frequently Asked Questions
What is a Tor bridge?
A Tor relay that is not listed in the public directory. Because a censor cannot enumerate relays it cannot see, a privately obtained bridge address often works where every published entry point is blocked.
Why can a country block Tor so easily?
Because Tor's main relay list is published deliberately, so that users can verify the network rather than trust a central curator. The same openness lets a censor download the list and filter every entry point on it.
What is a pluggable transport?
A layer that disguises the shape of Tor traffic so that filtering which fingerprints connections — rather than just blocking addresses — does not recognise it. Which transports work where changes over time, so use the Tor Project's current documentation.
Does using a bridge make Tor legal where it is banned?
No. A bridge addresses the technical block only. Where the law prohibits the use of anonymity tools, evading the block is not a mitigation and may be treated as an aggravating fact.
Where should I get bridge addresses?
From the Tor Project's own distribution channels. Addresses pasted in forums or video descriptions are usually dead, and an unverified bridge is an unverified entry point into your network.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy