What Not Evil Is and Why It Matters
Not Evil is a decentralized search engine designed specifically for onion sites and dark web content. Unlike Torch or Haystak, which rely on centralized indexing, Not Evil operates on a peer-to-peer model, meaning no single operator controls the entire index. This design reduces the risk of a single point of failure or law-enforcement takedown, though it also means search results can be inconsistent and slower to update.
The search engine was created to index .onion addresses without storing user queries or logging IP addresses. It returns results for hidden services, forums, marketplaces, and informational sites across the dark web. Because Not Evil is decentralized, multiple mirrors and instances exist simultaneously, which is both a strength and a source of confusion for users trying to find the legitimate link.
How to Identify the Real Not Evil Onion Link
The legitimate Not Evil search engine is accessed through its official onion address, which is published on the Tor Project's community resources and on security-focused forums. To verify you have the correct link, follow these steps:
- Visit the official Tor Project documentation or the darkwebmarketslinks.net Useful Resources page for verified onion addresses
- Cross-reference the address with multiple independent sources, such as archived security blogs or PGP-signed announcements from the Not Evil operators
- Check that the onion address is exactly 16 characters (v2) or 56 characters (v3), with no typos or variations
- Load the address in Tor Browser and verify the site's SSL certificate matches the expected domain
- Look for the official Not Evil branding and layout; phishing clones often have subtle design differences or broken functionality
Never copy an onion link from a random search result or forum post without verification. Attackers create convincing replicas to harvest login credentials or inject malware.
Common Phishing Clones and How They Exploit Trust
Phishing clones of Not Evil are widespread because the search engine's reputation makes it a high-value target. Attackers register similar-looking onion addresses (for example, swapping a zero for the letter O) and host near-identical interfaces. When users land on these clones, they may enter search queries, click links, or interact with forms that appear legitimate but actually log their behavior or inject malicious scripts.
One common tactic is to host a clone on a fast, reliable server while the real Not Evil instance experiences temporary downtime. Users frustrated by slow loading times may accept the clone as an alternative. Another technique is to distribute the fake link through dark web forums and social media, where verification is difficult and trust is low. The clone operators benefit from traffic, referral fees, or data harvesting. To protect yourself, bookmark the verified address in Tor Browser, use it consistently, and never click links to Not Evil from third-party sources.
Why Decentralization Makes Not Evil Harder to Verify
Not Evil's peer-to-peer architecture means that multiple nodes can serve search results independently, and no central authority publishes a single canonical address. This is intentional: it prevents any one person or organization from controlling the index or shutting down the service. However, it also means that different instances may have slightly different content, performance, or even security posture.
Some instances are maintained by the original developers, while others are community-run mirrors. A mirror may be outdated, compromised, or simply abandoned. This differs from a centralized search engine like Torch, where one primary onion link serves all traffic. For users, the trade-off is clear: decentralization improves resilience but requires more diligence in verification. Always confirm that you are using an instance endorsed by the Not Evil community or documented in trusted security resources.
Searching Safely Once You Have the Real Link
After verifying the Not Evil onion link, use the search engine with the same operational security practices you would apply to any dark web tool. Keep Tor Browser updated to the latest version, disable JavaScript if you are not sure what a site requires, and use a VPN in addition to Tor if your threat model demands it. Do not maximize your browser window, as this can reveal your screen resolution to fingerprinting scripts.
When searching, use specific, descriptive queries rather than broad terms. Vague searches may return misleading or malicious results. For example, searching for "marketplace" will return hundreds of unrelated sites, whereas searching for a specific forum name or service type is more reliable. Be aware that Not Evil indexes both legitimate information sites and illegal marketplaces; the search engine itself is neutral and does not curate results by legality. Exercise judgment about which links to click.
Reality Check: How Onion Search Engines Actually Fail
According to Tor Project documentation on onion service discovery, decentralized search engines struggle with index freshness and spam filtering. Operators of onion sites often do not submit their addresses to search engines, so new or updated sites may take weeks or months to appear in results. This means Not Evil will never be comprehensive, and users may miss legitimate resources or encounter outdated information.
Law-enforcement agencies have historically targeted search engine operators, not the search engines themselves. When a search engine operator is identified and arrested, the service may go offline, but the decentralized model means other instances can continue. However, if an instance is seized, its logs and data may be forensically recovered. This is why Not Evil's design avoids logging: there is nothing to seize. Security-vendor incident reports on dark web monitoring show that phishing clones of search engines are among the most common attack vectors for credential theft on the dark web. For ordinary users, this means verifying the address is not optional; it is a baseline defense.
Next Steps: Verify and Bookmark
The core takeaway is simple: do not assume any onion link you find online is legitimate, even if it appears in search results or forum recommendations. Verification takes five minutes and eliminates the most common attack vector. Start by visiting the Useful Resources page on this site or consulting the Tor Project's official documentation for the current verified Not Evil onion address. Once you have confirmed the address, bookmark it in Tor Browser and use only that bookmark to access the search engine.
If you ever land on a Not Evil instance that looks different, loads slowly, or asks for unusual permissions, close the tab and use your bookmark instead. Keep Tor Browser and your operating system updated, and consider running searches from a dedicated virtual machine or Tails instance if you are researching sensitive topics. The effort you invest in verification now prevents hours of recovery if your credentials are compromised or your device is infected.
Frequently asked questions
Is Not Evil still online and working
Not Evil's status changes over time due to its decentralized nature. Multiple instances are usually available, but individual mirrors may go offline or become outdated. Always verify the current address through official Tor Project resources or trusted security documentation before accessing it. If one instance is slow or unresponsive, try another verified address.
How do I know if a Not Evil link is a phishing clone
Phishing clones often have subtle design differences, slower performance, or unusual requests for information. Verify the onion address character-by-character against official sources before clicking. If the site asks you to log in, create an account, or enter personal information, it is likely a clone. The real Not Evil does not require authentication to search.
Can I use Not Evil to search for illegal marketplaces
Not Evil indexes all onion sites without filtering by legality. You can search for any term, but accessing illegal marketplaces or purchasing illegal goods carries legal and security risks. This guide is for informational purposes only and does not constitute advice on how to engage in illegal activity.
What is the difference between Not Evil and Torch for deep web search
Torch is centralized and maintained by a single operator, while Not Evil is decentralized and peer-to-peer. Torch may have faster, more consistent results, but relies on one point of failure. Not Evil is more resilient but slower and less comprehensive. Both require verification of the onion link to avoid phishing clones.
Do I need a VPN with Tor to use Not Evil safely
Tor alone provides strong anonymity for most users. A VPN adds a layer of encryption between your device and the Tor entry node, but it also introduces a potential logging point. Use a VPN only if your threat model requires it, such as if your ISP or network administrator monitors traffic. Never use a VPN that logs data.


