Best VPS for Running a Tor Relay

By Nate Corwin · Updated 2026 · self-hosting practitioner since 2017

This article contains affiliate links for some providers. Tor relay recommendations are based on provider policy toward Tor, not affiliate status.

Running a Tor relay is one of the most policy-sensitive things you can do on a VPS. The provider landscape splits cleanly: a handful of hosts explicitly welcome Tor relays (including exit nodes), most major providers explicitly ban exit relays, and a few say they allow Tor and then change their mind after the first abuse complaint. Which category your provider falls into determines whether your relay runs for years or gets suspended in weeks. This guide maps the policies, distinguishes the three relay types and their risk profiles, and documents what actually happens when abuse complaints arrive.

Exit vs middle vs bridge — the risk spectrum

The three Tor relay types carry fundamentally different risk profiles. Most "can I run Tor on X" questions fail to distinguish between them, which leads to confusion:

Relay typeWhat it doesAbuse complaintsIP listed publicly?Provider risk
Exit relayFinal hop — sends traffic to the open internet. Destination sees your IP.All complaints land here: DMCA, hacking reports, spam, fraudYes (Tor directory)High
Middle/guard relayCarries encrypted Tor-to-Tor traffic between relays. Never touches the open internet.Rarely receives complaintsYes (Tor directory)Low
BridgeUnlisted relay helping censored users reach Tor. Not in public directory.Virtually zeroNoMinimal

The Tor Project itself describes the distinction clearly: exit relays have "the greatest legal exposure and liability of all the relays," while middle relays "usually do not receive abuse complaints," and bridges are "relatively easy, low-risk and low bandwidth." (Source: Tor Project — Types of Relays)

When providers say they "ban Tor," they almost always mean exit relays. Middle relays and bridges fly under the radar at most providers because they generate no abuse complaints and their traffic looks like normal encrypted connections. But always check — some providers (OVHcloud) ban all Tor relay types.

Providers that explicitly allow exit relays

These providers have documented policies supporting Tor exit relays. This is a short list because exit relays are operationally expensive for providers — they generate abuse complaints that staff must process:

ProviderCountryStarting priceExit policy
BuyVMUS / Luxembourg$2/moExits, relays, bridges all allowed. Must open ticket, set rDNS, block SMTP ports
FlokiNETIceland / Romania / Finland~€7.50/moRuns their own exit + relay nodes. Full Tor support
FourplexUSBudgetHosts 42+ exits. Published policy: "We allow Tor exit relays — here's why"
IncogNETUS / NetherlandsBudgetProvides a Tor relay config generator on their website
PrivexSweden$50/mo (exits)Exits in Sweden only. Middle/guard relays allowed everywhere without permission
1984HostingIcelandBudgetListed as exit-friendly on Tor Project's Good/Bad ISP list
NjallaFinlandModerateExit-friendly. Privacy brand by Peter Sunde

BuyVM: the community standard

BuyVM is the most commonly recommended provider for Tor relays in the self-hosting community. Their AUP explicitly allows "Exit, Relay, and Bridge nodes." The requirements: open a support ticket to notify them, set your rDNS to identify the IP as a Tor exit, and block SMTP ports (25, 465, 587) to prevent email abuse through the exit. Once registered, BuyVM's abuse team ignores Tor-related abuse notices for your IP. At $2/month with unmetered bandwidth, the economics work for volunteer relay operators. (Source: BuyVM AUP)

FlokiNET: the privacy-first provider

FlokiNET operates their own Tor exit and relay nodes — they're a Tor Project supporter, not just a tolerant host. Locations in Iceland, Romania, and Finland provide jurisdictional diversity. Starting around €7.50/month. If your primary concern is finding a provider that philosophically supports Tor, FlokiNET is the strongest signal.

Privex: exits with managed abuse

Privex allows exit relays only in their Sweden location, with a minimum spend of $50/month and prior permission required. The value proposition: Privex handles all abuse complaints automatically for operators using their Reduced Exit Policy. Middle and guard relays are allowed at all locations without permission. The price premium buys operational peace of mind. (Source: Privex Tor Exit Policy)

Providers that explicitly ban exit relays

These providers have AUP language that specifically prohibits Tor exit nodes:

DigitalOcean

DigitalOcean's Network Abuse section prohibits: "Operating open proxies, open mail relays, open recursive domain name servers, Tor exit nodes, or other similar network services." Exit relays are listed by name. Middle relays and bridges are not mentioned. (Source: DigitalOcean AUP)

Vultr

Vultr's Prohibited Activities (Section 7) includes a single line: "Host TOR exit nodes." No elaboration, no distinction between relay types — but the language targets exit nodes specifically. (Source: Vultr Use Policy)

OVHcloud

OVHcloud bans all Tor relay types, not just exits: "anonymization services or public proxy (including VPN, Tor, P2P, IRC) are not permitted." Exit relays are classified as "open proxies" and subject to immediate suspension without notice. (Source: OVHcloud Service-Specific Terms)

Providers who say yes then suspend you

Worse than a clear ban is a provider that claims to allow Tor and then reverses course after abuse complaints arrive. Two documented cases:

Contabo

Multiple exit relay operators report being told at signup that Tor exits were allowed, then receiving suspensions after abuse complaints accumulated. Contabo charged reactivation fees not specified in their terms. The Tor Project's GitLab has a discussion thread (Issue #191) titled "Good Bad ISP — Remove Contabo" debating whether to delist them from the Tor-friendly provider list. If you're considering Contabo for an exit relay, the community consensus is to avoid it. (Source: Tor mailing list, community reports)

Vultr (historical)

Vultr support initially told at least one exit node operator that running exit nodes was acceptable. Six months later, Vultr unilaterally updated their Use Policy to explicitly add "Host TOR exit nodes" to the prohibited activities list. The operator's existing exit was affected retroactively. (Source: Tor Project wiki, community reports)

Aeza

In 2025, Aeza changed their terms to explicitly ban all Tor components — exits, relays, and bridges. A user running a middle relay on a Swedish promotional plan received a TOS violation warning and had their VPS suspended exactly 24 hours later. Data was preserved and restored after contacting support, but the policy change was unilateral and retroactive. (Source: LowEndTalk, 2025)

The pattern: providers with no explicit Tor policy are rolling the dice. They may tolerate your relay for months, then change their mind after their first batch of forwarded DMCA notices. Use a provider with explicit, documented Tor support — not one where "support said it was OK."

Handling abuse complaints

Exit relay IPs receive abuse complaints because they appear as the source of whatever traffic passes through them. The volume and type of complaints you receive depends on your exit policy:

Reduced Exit Policy

The Tor Project recommends a "Reduced Exit Policy" that blocks BitTorrent ports, SMTP, and other commonly abused protocols. According to the Tor Project, this eliminates roughly 80% of automated abuse complaints — the majority of which are DMCA takedowns triggered by BitTorrent. Fourplex, which hosts 42+ exit relays, reports that abuse from their Tor exits is less frequent than abuse from their non-Tor customers.

Response templates

The Tor Project provides pre-written response templates for every category of abuse complaint: DMCA, hacking reports, spam, fraud, and law enforcement requests. The key argument: exit relay operators are intermediaries, similar to ISPs, and are not responsible for the content of traffic passing through. The EFF provides additional legal templates citing DMCA Section 512 safe harbor provisions. (Source: Tor Abuse Response Templates)

ExoneraTor

The Tor Project's ExoneraTor tool (exonerator.torproject.org) proves that a given IP was operating as a Tor exit relay at a specific time. This is useful when responding to abuse complaints or law enforcement inquiries — it provides independent, third-party verification that your IP was a Tor exit and that the traffic did not originate from you.

FAQ

Which VPS providers allow Tor exit relays?

BuyVM ($2/mo, must notify via ticket), FlokiNET (runs their own exits), Fourplex (42+ exits, published support policy), IncogNET, Privex ($50/mo minimum in Sweden), 1984Hosting (Iceland), and Njalla (Finland). Major providers — DigitalOcean, Vultr, OVH — explicitly ban exit relays in their AUP.

Is it legal to run a Tor relay?

In most countries, yes. The EFF is not aware of anyone being convicted for running a relay in the US. Middle relays and bridges carry essentially zero legal risk. Exit relays receive abuse complaints but operators are generally protected as intermediaries. The Tor Project provides abuse response templates and legal guidance.

What's the difference between exit, middle, and bridge relays?

Exit = final hop, destination sees your IP, all abuse complaints land here (high risk). Middle = encrypted Tor-to-Tor traffic only, rarely receives complaints (low risk). Bridge = unlisted relay for censored users, not in public directory (minimal risk). Most provider bans target exit relays specifically.