Best VPS for Running a Tor Relay
Running a Tor relay is one of the most policy-sensitive things you can do on a VPS. The provider landscape splits cleanly: a handful of hosts explicitly welcome Tor relays (including exit nodes), most major providers explicitly ban exit relays, and a few say they allow Tor and then change their mind after the first abuse complaint. Which category your provider falls into determines whether your relay runs for years or gets suspended in weeks. This guide maps the policies, distinguishes the three relay types and their risk profiles, and documents what actually happens when abuse complaints arrive.
Exit vs middle vs bridge — the risk spectrum
The three Tor relay types carry fundamentally different risk profiles. Most "can I run Tor on X" questions fail to distinguish between them, which leads to confusion:
| Relay type | What it does | Abuse complaints | IP listed publicly? | Provider risk |
|---|---|---|---|---|
| Exit relay | Final hop — sends traffic to the open internet. Destination sees your IP. | All complaints land here: DMCA, hacking reports, spam, fraud | Yes (Tor directory) | High |
| Middle/guard relay | Carries encrypted Tor-to-Tor traffic between relays. Never touches the open internet. | Rarely receives complaints | Yes (Tor directory) | Low |
| Bridge | Unlisted relay helping censored users reach Tor. Not in public directory. | Virtually zero | No | Minimal |
The Tor Project itself describes the distinction clearly: exit relays have "the greatest legal exposure and liability of all the relays," while middle relays "usually do not receive abuse complaints," and bridges are "relatively easy, low-risk and low bandwidth." (Source: Tor Project — Types of Relays)
When providers say they "ban Tor," they almost always mean exit relays. Middle relays and bridges fly under the radar at most providers because they generate no abuse complaints and their traffic looks like normal encrypted connections. But always check — some providers (OVHcloud) ban all Tor relay types.
Providers that explicitly allow exit relays
These providers have documented policies supporting Tor exit relays. This is a short list because exit relays are operationally expensive for providers — they generate abuse complaints that staff must process:
| Provider | Country | Starting price | Exit policy |
|---|---|---|---|
| BuyVM | US / Luxembourg | $2/mo | Exits, relays, bridges all allowed. Must open ticket, set rDNS, block SMTP ports |
| FlokiNET | Iceland / Romania / Finland | ~€7.50/mo | Runs their own exit + relay nodes. Full Tor support |
| Fourplex | US | Budget | Hosts 42+ exits. Published policy: "We allow Tor exit relays — here's why" |
| IncogNET | US / Netherlands | Budget | Provides a Tor relay config generator on their website |
| Privex | Sweden | $50/mo (exits) | Exits in Sweden only. Middle/guard relays allowed everywhere without permission |
| 1984Hosting | Iceland | Budget | Listed as exit-friendly on Tor Project's Good/Bad ISP list |
| Njalla | Finland | Moderate | Exit-friendly. Privacy brand by Peter Sunde |
BuyVM: the community standard
BuyVM is the most commonly recommended provider for Tor relays in the self-hosting community. Their AUP explicitly allows "Exit, Relay, and Bridge nodes." The requirements: open a support ticket to notify them, set your rDNS to identify the IP as a Tor exit, and block SMTP ports (25, 465, 587) to prevent email abuse through the exit. Once registered, BuyVM's abuse team ignores Tor-related abuse notices for your IP. At $2/month with unmetered bandwidth, the economics work for volunteer relay operators. (Source: BuyVM AUP)
FlokiNET: the privacy-first provider
FlokiNET operates their own Tor exit and relay nodes — they're a Tor Project supporter, not just a tolerant host. Locations in Iceland, Romania, and Finland provide jurisdictional diversity. Starting around €7.50/month. If your primary concern is finding a provider that philosophically supports Tor, FlokiNET is the strongest signal.
Privex: exits with managed abuse
Privex allows exit relays only in their Sweden location, with a minimum spend of $50/month and prior permission required. The value proposition: Privex handles all abuse complaints automatically for operators using their Reduced Exit Policy. Middle and guard relays are allowed at all locations without permission. The price premium buys operational peace of mind. (Source: Privex Tor Exit Policy)
Providers that explicitly ban exit relays
These providers have AUP language that specifically prohibits Tor exit nodes:
DigitalOcean
DigitalOcean's Network Abuse section prohibits: "Operating open proxies, open mail relays, open recursive domain name servers, Tor exit nodes, or other similar network services." Exit relays are listed by name. Middle relays and bridges are not mentioned. (Source: DigitalOcean AUP)
Vultr
Vultr's Prohibited Activities (Section 7) includes a single line: "Host TOR exit nodes." No elaboration, no distinction between relay types — but the language targets exit nodes specifically. (Source: Vultr Use Policy)
OVHcloud
OVHcloud bans all Tor relay types, not just exits: "anonymization services or public proxy (including VPN, Tor, P2P, IRC) are not permitted." Exit relays are classified as "open proxies" and subject to immediate suspension without notice. (Source: OVHcloud Service-Specific Terms)
Providers who say yes then suspend you
Worse than a clear ban is a provider that claims to allow Tor and then reverses course after abuse complaints arrive. Two documented cases:
Contabo
Multiple exit relay operators report being told at signup that Tor exits were allowed, then receiving suspensions after abuse complaints accumulated. Contabo charged reactivation fees not specified in their terms. The Tor Project's GitLab has a discussion thread (Issue #191) titled "Good Bad ISP — Remove Contabo" debating whether to delist them from the Tor-friendly provider list. If you're considering Contabo for an exit relay, the community consensus is to avoid it. (Source: Tor mailing list, community reports)
Vultr (historical)
Vultr support initially told at least one exit node operator that running exit nodes was acceptable. Six months later, Vultr unilaterally updated their Use Policy to explicitly add "Host TOR exit nodes" to the prohibited activities list. The operator's existing exit was affected retroactively. (Source: Tor Project wiki, community reports)
Aeza
In 2025, Aeza changed their terms to explicitly ban all Tor components — exits, relays, and bridges. A user running a middle relay on a Swedish promotional plan received a TOS violation warning and had their VPS suspended exactly 24 hours later. Data was preserved and restored after contacting support, but the policy change was unilateral and retroactive. (Source: LowEndTalk, 2025)
The pattern: providers with no explicit Tor policy are rolling the dice. They may tolerate your relay for months, then change their mind after their first batch of forwarded DMCA notices. Use a provider with explicit, documented Tor support — not one where "support said it was OK."
Handling abuse complaints
Exit relay IPs receive abuse complaints because they appear as the source of whatever traffic passes through them. The volume and type of complaints you receive depends on your exit policy:
Reduced Exit Policy
The Tor Project recommends a "Reduced Exit Policy" that blocks BitTorrent ports, SMTP, and other commonly abused protocols. According to the Tor Project, this eliminates roughly 80% of automated abuse complaints — the majority of which are DMCA takedowns triggered by BitTorrent. Fourplex, which hosts 42+ exit relays, reports that abuse from their Tor exits is less frequent than abuse from their non-Tor customers.
Response templates
The Tor Project provides pre-written response templates for every category of abuse complaint: DMCA, hacking reports, spam, fraud, and law enforcement requests. The key argument: exit relay operators are intermediaries, similar to ISPs, and are not responsible for the content of traffic passing through. The EFF provides additional legal templates citing DMCA Section 512 safe harbor provisions. (Source: Tor Abuse Response Templates)
ExoneraTor
The Tor Project's ExoneraTor tool (exonerator.torproject.org) proves that a given IP was operating as a Tor exit relay at a specific time. This is useful when responding to abuse complaints or law enforcement inquiries — it provides independent, third-party verification that your IP was a Tor exit and that the traffic did not originate from you.
Legal status
The EFF states they are "not aware of an individual being sued, prosecuted, or convicted for running a Tor relay" in the United States. One case is frequently cited: Dmitry Bogatov, a Russian mathematics teacher, was arrested in 2017 in connection with posts allegedly made through his Tor exit relay. He was later cleared. (Source: EFF Tor Legal FAQ)
Middle relays and bridges have even less legal exposure because they never directly contact destination servers — they only pass encrypted traffic between other Tor nodes.
The Tor Project recommends that exit relay operators be affiliated with an organization (university, library, hackerspace, privacy NGO) rather than operating as individuals, and that exit relays should never be run from home IP addresses. For volunteer operators on VPS infrastructure, the provider's policy and abuse handling is the primary practical concern, not legal risk.
FAQ
Which VPS providers allow Tor exit relays?
BuyVM ($2/mo, must notify via ticket), FlokiNET (runs their own exits), Fourplex (42+ exits, published support policy), IncogNET, Privex ($50/mo minimum in Sweden), 1984Hosting (Iceland), and Njalla (Finland). Major providers — DigitalOcean, Vultr, OVH — explicitly ban exit relays in their AUP.
Is it legal to run a Tor relay?
In most countries, yes. The EFF is not aware of anyone being convicted for running a relay in the US. Middle relays and bridges carry essentially zero legal risk. Exit relays receive abuse complaints but operators are generally protected as intermediaries. The Tor Project provides abuse response templates and legal guidance.
What's the difference between exit, middle, and bridge relays?
Exit = final hop, destination sees your IP, all abuse complaints land here (high risk). Middle = encrypted Tor-to-Tor traffic only, rarely receives complaints (low risk). Bridge = unlisted relay for censored users, not in public directory (minimal risk). Most provider bans target exit relays specifically.