What SecureDrop Is and Why It Matters
SecureDrop is an open-source whistleblower submission platform developed by the Freedom of the Press Foundation. News organizations deploy SecureDrop instances on their own infrastructure, each with its own onion address. A journalist or source can submit documents, messages or tips through SecureDrop without revealing their identity, even to the news organization, until they choose to communicate further. The system is designed so that the news outlet never sees the source's IP address, and the source never needs to create an account or provide personal information. SecureDrop runs on Tor, which means both the source and the journalist access it through the Tor browser, adding a layer of network-level anonymity.
How SecureDrop Onion Addresses Are Organized
Each news organization that uses SecureDrop hosts its own instance. The New York Times has one onion address, the Washington Post has another, and smaller outlets may have their own. There is no single master SecureDrop onion address. Instead, each outlet publishes its address on its official website, usually in a dedicated section labeled 'Tips' or 'Contact Us'. Some outlets also publish their SecureDrop address on social media or in their masthead. The address format is a long string of random characters followed by '.onion', similar to other onion services. Because these addresses are long and hard to remember, outlets often provide them in a clickable link or a QR code on their official site.
Finding the Correct Address for a Specific Outlet
To find the real SecureDrop address for a news organization, follow these steps:
- Visit the official website of the news outlet directly (type the URL into your browser or use a bookmark).
- Look for a 'Tips', 'Contact', 'Leak', or 'Whistleblower' section on their site.
- The SecureDrop onion address should be listed there, often with instructions on how to access it via Tor.
- If you cannot find it on the main site, check their press or newsroom page.
- Verify the address against any official social media accounts or press releases from that outlet.
Do not search for SecureDrop addresses on Google, dark web directories, or forums. Search results and third-party listings are common targets for phishing clones. The only reliable source is the news organization's own website.
Phishing Clones and How to Avoid Them
Phishing clones of SecureDrop instances exist on the dark web. These fake sites are designed to look identical to the real SecureDrop interface but are controlled by attackers. When you submit a tip to a clone, your information goes to the attacker instead of the news organization. Some clones are created by state actors or criminal groups seeking to identify and compromise sources. Others are scams designed to harvest data or install malware. The easiest way to fall for a clone is to find the address through a search engine, a dark web directory, or a forum post. Even if the address looks correct, if you did not verify it through the official news outlet's website, you cannot be certain it is real. Always assume that any onion address you find outside of an official source is potentially malicious.
Verification Best Practices Before Submitting
Before you submit anything to a SecureDrop instance, verify the address one more time:
- Open the news outlet's official website in a fresh Tor browser window.
- Confirm the onion address matches exactly what you see on their site.
- Check for any security warnings or notices on their SecureDrop page.
- If the outlet publishes a PGP key for SecureDrop communications, verify that the key fingerprint matches what they list on their official site.
- If you are unsure, contact the outlet through a different channel (phone, email, social media) and ask them to confirm the address.
Taking an extra minute to verify prevents you from sending sensitive information to an attacker. News organizations understand that sources are cautious and will not mind if you double-check.
Reality Layer: How Verification Actually Works in Practice
The Tor Project documentation on onion services emphasizes that onion addresses are not human-readable and cannot be verified by appearance alone. This matters because it means you cannot tell a legitimate address from a clone just by looking at it. Law enforcement and security researchers have documented cases where phishing clones of SecureDrop instances were deployed to identify sources. Court records from prosecutions of journalists and sources show that some compromises occurred because sources accessed a fake instance. Security vendor incident reports on dark web threats consistently flag SecureDrop clones as a high-risk attack vector. The practical lesson is that no amount of caution during submission (using Tor, disabling JavaScript, using Tails) will protect you if the address itself is fake. Verification of the address through the official source is the only step that actually prevents this attack.
Common Mistakes and How to Avoid Them
Sources often make mistakes that compromise their security before they even submit. Searching for 'SecureDrop' or a news outlet name on a dark web search engine like Torch or Ahmia and clicking the first result is risky. Using a SecureDrop address from a Reddit thread, a forum, or a dark web directory is equally dangerous. Bookmarking an onion address without verifying it first, then using that bookmark months later, can lead to a clone if the bookmark was wrong from the start. Assuming that a SecureDrop instance is safe because it looks professional or has correct branding is a mistake; clones can be very convincing. The safest approach is to verify the address every single time you plan to submit, even if you have used it before. Treat each submission as a fresh verification task.
What to Do If You Suspect a Phishing Clone
If you encounter a SecureDrop instance that looks suspicious or does not match the address on the outlet's official website, do not submit anything. Instead, report it to the Freedom of the Press Foundation, which maintains SecureDrop and can investigate. You can also contact the news outlet directly and let them know about the suspicious address. If you have already submitted to a suspected clone, consider contacting the outlet through a different channel to warn them. Do not panic; submitting to a clone does not automatically compromise your identity, especially if you used Tor correctly and did not include identifying information in your submission. However, assume that the information you submitted is no longer confidential. The outlet will be able to advise you on next steps based on what you submitted and the sensitivity of the information.
Common Questions
Is there one SecureDrop onion address for all news outlets
No. Each news organization that uses SecureDrop hosts its own instance with its own onion address. The New York Times, Washington Post, BBC and other outlets each have different addresses. You must find the address for the specific outlet you want to contact.
How do I know if a SecureDrop address is real or a phishing clone
Verify the address on the news outlet's official website only. Do not trust addresses from search results, directories, forums or social media. If the address does not match what the outlet publishes on their own site, assume it is a clone and do not use it.
What happens if I accidentally submit to a fake SecureDrop
Your submission goes to the attacker instead of the news organization. Assume the information is no longer confidential. Contact the outlet through another channel to warn them. If you used Tor correctly and did not include identifying details, your anonymity may not be compromised, but the content is at risk.
Can I bookmark a SecureDrop onion address and use it later
You can bookmark it, but verify the address again before each submission. Bookmarks can be wrong if you saved an incorrect address initially, or the outlet may have updated their address. Re-verify every time to be safe.
Where should I report a suspected SecureDrop phishing clone
Contact the Freedom of the Press Foundation or the news outlet directly. You can also report it to the Tor Project if it involves abuse of onion services. Provide as much detail as possible about where you found the suspicious address.

