toxbootstrap.org

Read this before you rely on it

Tox is encrypted. Tox is not anonymous.

Plenty of sites about Tox — including an earlier version of this one — list "anonymity" as a feature. That is wrong, and getting it wrong is how people end up trusting a tool with something it was never built to protect. Tox encrypts your conversations very well. It does not hide where you are.

The short version

In a peer-to-peer network, packets travel directly between two machines. For that to work, each machine has to know the other's address. When you accept a friend request, that person can see your IP address. So can anyone who compromises their device, and so can anyone who successfully sends you a friend request you accept.

If your safety depends on nobody learning your location or your internet provider, Tox on its own is not enough. Route it through Tor, or use a tool designed for that threat model.

What Tox does protect

What Tox does not protect

Your IP address from contacts

The big one. Direct connections require addresses. Everyone on your contact list can see roughly where you are and who your internet provider is. Adding a stranger means giving a stranger your IP.

The fact that you use Tox

Your provider and network administrator cannot read your traffic, but they can see its shape. Tox is identifiable by deep packet inspection and is blocked on that basis in several countries.

Your DHT activity from nodes

Any bootstrap node — including this one — sees the IP addresses that query it and when. Most clients rotate their DHT key at every start, which limits correlation, but does not eliminate it.

Anything on a compromised device

Encryption ends where the screen begins. Malware, a keylogger, or somebody with your unlocked laptop reads everything. No protocol fixes this.

Which threat model are you in?

You want to…Tox alone
Keep conversations away from advertisers and data brokersWorks well
Message without giving anyone a phone numberWorks well
Avoid a company that could be breached or subpoenaedWorks well
Talk to people you already know and trustWorks well
Hide your location from the people you are talking toNeeds Tor
Hide from a network operator that you use Tox at allNeeds Tor or a bridge
Protect a source, or organise under a hostile governmentNot sufficient on its own

Running Tox over Tor

Tor hides your IP address from the people you talk to; Tox encrypts what you say to them. Together they cover more than either does alone.

The mechanics: Tor carries TCP only, so you must disable UDP in your client and force TCP-only mode. That is not a small change. With UDP off, every connection goes through TCP relays like this node instead of directly to your peer, so expect noticeably higher latency and slower file transfers. Audio and video calls generally become unusable — real-time media does not survive the added delay.

Set your client's proxy to your local Tor SOCKS5 listener, usually 127.0.0.1 on port 9050, then enable TCP-only mode in the same settings section. Verify it worked before trusting it: if the client connects with the proxy pointed somewhere invalid, it is not using the proxy.

One caveat worth stating plainly: this configuration is fiddly, and a misconfiguration fails open — you stay connected while leaking your real address. If your safety genuinely depends on this, test it with a machine you control on the other end before you rely on it.

What this node logs

This node runs tox-bootstrapd in its standard configuration. It answers DHT queries and relays TCP. It has no key that can decrypt anything passing through it, and no plaintext ever exists on this machine to be logged.

What it does necessarily process, as any node must: the IP addresses that connect to it, their DHT public keys, and connection timing. Treat any public node — this one included — as a party that can observe when you were online and from where. That is not a reason to avoid public nodes; it is a reason to know what you are trusting them with. Details are on the status page.

If you need more than this

Different tools make different trades, and the right answer depends on what you are protecting against:

Tox's distinctive strength is that it is genuinely serverless and genuinely leaderless. That is worth something real. It just isn't anonymity.

Background How the Tox DHT works

Why the design exposes an IP address in the first place.

This node Status & policy

Specs, ports, logging and how to report a problem.