🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
The deep web is everything search engines cannot index, including email inboxes, banking portals, and company intranets. The dark web is a small subset of that, hosted on anonymity networks such as Tor and reachable only with specific software.
Everything turns on why the content stays hidden. Deep web pages sit behind logins and paywalls because access is controlled. Dark web sites hide because their operators, and in most cases their visitors, want no trace of who they are.
A logged-in bank account and a Tor marketplace both fall outside Google's index. Treating them as the same thing is where most confusion about this topic begins.
Both layers sit outside search results, and they differ in access method, purpose, and the risk each one carries.
Scale separates the two by orders of magnitude. Practically every authenticated page on the internet belongs to the deep web, while dark web sites number in the hundreds of thousands at most, and only a fraction of those stay online from one month to the next.
Deep web content stays out of search results for four ordinary technical reasons, none of which involve secrecy.
Ordinary internet use runs mostly through the deep web. Checking email, reviewing a payslip, opening a CRM record, and watching a subscription stream all happen on pages no search engine can reach, using the same browser as any public website.
For security teams, this layer is where the data lives. Misconfigured portals, exposed APIs, and internal tools that slip into public indexes turn deep web assets into findings, which is the work covered by external attack surface management.

Deep Web works by limiting access to content through verification rather than hiding it from the internet entirely. Pages remain unseen in search results because viewing them requires approval first.
Login systems check credentials such as passwords or account permissions before granting entry. After access is approved, temporary sessions allow users to navigate private areas without making the content public.
Search engines may detect the existence of these pages but cannot read what sits behind access barriers. This structure allows private information to stay protected while functioning as part of normal internet activity.
Dark web sites run on overlay networks that hide the location of both the visitor and the server. Tor carries most of that traffic.
A Tor connection travels through three volunteer-run relays, each peeling off one layer of encryption, so no single relay knows both the origin and the destination. Onion services go further: the visitor and the site meet at a rendezvous point inside the network, and the traffic never exits to the public internet at all.
Addressing reflects that design in a visible way. A version 3 onion address is a 56-character string derived from the service's public key, which makes it unguessable, unmemorable, and impossible to register through any registrar.
Other networks carry their own share of this traffic. I2P hosts eepsites and suits peer-to-peer use, while Hyphanet, formerly Freenet, distributes content across participating nodes so no single host holds a complete copy.
Measurement works better at the network level than in percentages. The Tor Project's own metrics show a network of thousands of volunteer-run relays serving millions of users, with onion service counts tracked separately.

Dark Web works by routing connections through multiple layers of encrypted relays instead of direct paths. This routing method prevents network observers from linking users to destinations.
Specialized software manages these connections and separates identity from activity. Requests move across distributed nodes, making traffic analysis and tracking difficult.
Sites operate on non-standard addresses that avoid traditional indexing and discovery. Combined with layered routing, this setup removes conventional visibility and shifts control away from centralized systems.Â
Most articles on this topic repeat that the deep web is 90% or 96% of the internet and the dark web around 6%. Those numbers have no current basis.
The figures trace back to an estimate published in 2001, when the web was a fraction of its present size and measurement methods were far cruder. Nobody can count what search engines have not indexed, because the only way to size an unindexed page is to find it first.
Three things can be counted instead: onion addresses seen by Tor directories, relays in the network, and the traffic they carry. Those figures describe a dark web that stays small, volatile, and nowhere near a fixed percentage of anything.
For a security team, the layer matters less than where the organization's data ends up, and exposure appears on both.
One shift over the past few years complicates the picture. Much of the trading that people still call dark web activity now happens on Telegram, paste sites, and public code repositories, which sit on the clear web. Monitoring built only for Tor misses the venues where stolen data moves fastest, a change covered in the future of dark web monitoring.
Anonymity removes friction, and the crimes that benefit most are the ones that need coordination, resale, or pressure.
Reported figures understate every category above. The FBI's IC3 recorded 3,611 ransomware complaints and $32.3 million in reported ransomware losses during 2025, within $20.9 billion in total cybercrime losses, and those totals cover only incidents victims chose to report to one agency in one country.
Deep web use raises no legal question at all. Anyone who logs into an account is already doing it.
Most countries treat Tor and similar tools as legal, and a handful restrict or block them. Journalists, researchers, and people living under censorship use them for the same reason criminals do, so the software itself carries no legal weight either way.
Conduct draws the line instead of technology: buying stolen data, trading illegal goods, or accessing material that is illegal to possess remains a crime regardless of the network used to reach it. Security teams that research these environments work under written authorization, from segregated infrastructure, with a policy covering what analysts download or purchase.
Organizations rarely need to browse either layer. What they need is early warning when their data, credentials, or brand appears somewhere they cannot see.
CloudSEK XVigil monitors surface, deep, and dark web sources, including forums, marketplaces, paste sites, code repositories, IRC, I2P, and Telegram, for exposure tied to an organization's own assets, and supports takedowns for fake domains, apps, and phishing infrastructure.
Coverage across layers decides whether monitoring works. CloudSEK's guide to choosing a dark web monitoring tool sets out how to test that coverage before buying, and dark web monitoring explains how the discipline works day-to-day.
Do I need Tor to access the deep web?
No. Deep web content opens in any standard browser once credentials, a subscription, or a direct link provides access.
Can search engines index .onion sites?
Standard search engines cannot. Specialized onion search services index a portion of them, and results stay incomplete because sites appear and vanish constantly.
Is the dark web dangerous to visit?
It carries real risk. Malicious downloads, scam sites, and law enforcement monitoring make unmanaged access a poor idea for anyone without a defined purpose.
How large is the dark web compared to the deep web?
It varies by measurement. Onion addresses number in the hundreds of thousands, while deep web pages include every authenticated page on the internet.
