How to Set Up a Tor Exit Node on a VPS Hosted in Sweden from £4.99/mo
A step-by-step guide to running a Tor exit node VPS on Ubuntu or Debian: the resources you need, a working configuration, how to handle abuse reports, and where to host it.
- Dedicated IPv4
- DDR4 ECC RAM
- DDoS mitigation included
- Pay with crypto, incl. Monero
What is a Tor exit node?
Tor routes traffic through three relays: a guard, a middle relay and an exit. The exit node is the last hop. It sends the traffic out to the public internet, so websites see the exit's IP address rather than the user's.
That makes exit relays the most valuable and the most demanding part of the network. Because destination sites see your IP, you will receive abuse complaints, and you need a host that allows exit traffic. Running a non-exit relay is simpler, but exits are what the network is short of.
Before you start: Running an exit relay is legal in many countries, but you are responsible for complying with local law and your host's terms. HammerVM allows Tor relays and exit nodes, but read the Terms of Service and Fair Usage Policy first. This guide is not legal advice.
What resources does a Tor exit node VPS need?
Tor is limited mainly by network capacity and CPU, not storage. A relay writes very little to disk, so a small HDD or SSD is plenty. These are practical starting points, with the HammerVM Sweden plan that fits each one:
| Use case | CPU | RAM | Bandwidth | Storage | HammerVM plan |
|---|---|---|---|---|---|
| Small non-exit relay | 1 core | 1-2 GB | 16+ Mbit/s | 10 GB | Plastic, £2.99/mo 1 core, 2 GB, 100 Mbit/s (limited stock) |
| Moderate exit node | 2 cores | 4 GB | 50-100 Mbit/s | 20 GB | Rubber, £4.99/mo 2 cores, 4 GB, 100 Mbit/s |
| High-capacity exit node | 2-4 cores | 8+ GB | 200-300 Mbit/s | 40 GB | Metal, £8.99/mo 2 cores, 8 GB, 300 Mbit/s Silver, £14.99/mo 4 cores, 16 GB, 300 Mbit/s |
Silver gives you the extra cores and RAM to run two relay instances on one IP, which is the maximum Tor allows per address.
Bandwidth and traffic
An exit averaging 50 Mbit/s moves roughly 16 TB per direction each month. Cap your relay's rate so you stay within your host's fair usage limits.
CPU and RAM
Encryption load grows with throughput. Two dedicated cores and 4 GB of RAM handle a 100 Mbit/s exit comfortably.
Ramp-up time
New relays get little traffic at first. Expect several weeks before usage reaches its full potential as the network measures and trusts your node.
Why host a Tor exit node in Sweden?
Stockholm is a strong location for a relay, and HammerVM's Sweden VPS runs inside the OBE Kista datacentre.
Mature EU privacy framework
Sweden operates under GDPR, with legal process required before data is handed over.
Excellent connectivity
Stockholm is a major European hub with direct routes to the Nordics, the UK and Central Europe, which suits Tor traffic well.
DDoS mitigation included
OBE Basic DDoS Mitigation is on every Sweden VPS at no extra cost, keeping your relay stable during attacks.
Diversity for the network
A healthier Tor network spreads relays across many networks and countries. A new independent exit in Stockholm adds to that.
Want the full picture of our Swedish infrastructure? See our Sweden VPS hosting overview or our general Tor relay hosting page.
Step-by-step: set up a Tor exit node on Ubuntu or Debian
Both work well for Tor. Pick your operating system in step 2 and follow the matching tab. Commands change over time, so cross-check them with the official Tor Project exit relay guide.
1. Order a VPS
Deploy a Sweden VPS with a dedicated IPv4 address and choose Ubuntu LTS (22.04 or 24.04) or a current Debian stable release as the operating system. Then log in over SSH.
2. Install Tor, DNS and the firewall
We use the Tor Project's own repository rather than the distribution's package, because it ships current, security-patched builds. Running an outdated relay hurts the network.
Update the system and add prerequisites
sudo apt update && sudo apt upgrade -y
sudo apt install -y apt-transport-https gpg wget lsb-release
Add the Tor Project repository and install Tor
wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor | sudo tee /usr/share/keyrings/tor-archive-keyring.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/tor-archive-keyring.gpg] https://deb.torproject.org/torproject.org $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/tor.list
sudo apt update
sudo apt install -y tor deb.torproject.org-keyring
Set up a local DNS resolver (Ubuntu uses systemd-resolved)
sudo apt install -y unbound
sudo systemctl enable --now unbound
sudo sed -i 's/^#\?DNS=.*/DNS=127.0.0.1/' /etc/systemd/resolved.conf
sudo systemctl restart systemd-resolved
resolvectl query torproject.org
Open the firewall (ufw is preinstalled on Ubuntu)
sudo ufw allow OpenSSH
sudo ufw allow 9001/tcp
sudo ufw enable
Update the system and add prerequisites
Minimal Debian images may not include sudo. Run these as root, and the rest will work with sudo afterwards.
apt update && apt upgrade -y
apt install -y sudo apt-transport-https gpg wget lsb-release
Add the Tor Project repository and install Tor
wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor | sudo tee /usr/share/keyrings/tor-archive-keyring.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/tor-archive-keyring.gpg] https://deb.torproject.org/torproject.org $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/tor.list
sudo apt update
sudo apt install -y tor deb.torproject.org-keyring
Set up a local DNS resolver
sudo apt install -y unbound
sudo systemctl enable --now unbound
echo "nameserver 127.0.0.1" | sudo tee /etc/resolv.conf
If your image regenerates /etc/resolv.conf on reboot, set the resolver in your network configuration instead.
Install and open the firewall (ufw is not preinstalled on Debian)
sudo apt install -y ufw
sudo ufw allow 22/tcp
sudo ufw allow 9001/tcp
sudo ufw enable
3. Configure your exit relay
This step is identical on Ubuntu and Debian. Edit /etc/tor/torrc and replace its contents with the configuration below. It starts with a web-only exit policy, which attracts far fewer abuse reports than a wide-open exit.
Nickname SwedenExit01
ContactInfo you AT example DOT com
ORPort 9001
ExitRelay 1
SocksPort 0
# Keep bandwidth within your plan's fair usage
RelayBandwidthRate 8 MBytes
RelayBandwidthBurst 10 MBytes
# Web-only exit policy
ExitPolicy reject *:25
ExitPolicy accept *:80
ExitPolicy accept *:443
ExitPolicy reject *:*
- Nickname is the public name of your relay.
- ContactInfo lets the Tor Project and others reach you. Obfuscate the email to reduce spam.
- RelayBandwidthRate is in bytes, so 8 MBytes is about 64 Mbit/s. Adjust it to match your plan.
- Widen the exit policy later, once you are comfortable handling abuse reports.
4. Start Tor and check the logs
sudo systemctl enable tor@default
sudo systemctl restart tor@default
sudo journalctl -u tor@default -f
Look for a message saying your ORPort is reachable from the outside. Within a few hours your relay should appear on Tor Relay Search when you search for your nickname.
5. Set reverse DNS, automate updates and monitor
Set your IP's reverse DNS to something recognisable, such as tor-exit, so abuse desks can tell at a glance what it is. Then turn on automatic security updates, which work the same on Ubuntu and Debian:
sudo apt install -y unattended-upgrades apt-listchanges
sudo dpkg-reconfigure -plow unattended-upgrades
To include Tor itself, add "origin=TorProject"; to the Origins-Pattern list in /etc/apt/apt.conf.d/50unattended-upgrades. A monitor like Nyx is also handy for watching traffic and connections.
Handling abuse complaints
Every exit operator gets complaints, because the internet sees your IP as the source. It is manageable when you are prepared.
- Use a restricted exit policy. Blocking mail and allowing only web ports removes most spam and high-risk traffic.
- Reply quickly and politely. Explain that the IP is a Tor exit, that you do not log user traffic, and link to the Tor Project's abuse response templates.
- Keep your contact details current. Use a dedicated email address so reports do not get lost.
- Choose a host that understands Tor. Hosts that ban exits often suspend accounts on the first complaint. Here at HammerVM, exit relays are explicitly supported.
Recommended Sweden VPS plans for Tor
Dedicated resources, DDR4 ECC RAM and a full dedicated IPv4 address on every plan, hosted in Stockholm.
Rubber
Best for a first exit node
£4.99/mo
- 2 Cores [E5-2640v4]
- 4 GB DDR4 ECC RAM
- 20 GB HDD
- 100 Mbit/s (Fair Usage)
- Dedicated IPv4
Metal
Best for a high-capacity exit
£8.99/mo
- 2 Cores [E5-2640v4]
- 8 GB DDR4 ECC RAM
- 40 GB HDD
- 300 Mbit/s (Fair Usage)
- Dedicated IPv4
Need more? See every Sweden plan or request a custom quote.
Why run your Tor exit node with HammerVM?
Dedicated resources
Dedicated cores and ECC RAM, not shared pools, so throughput stays steady when the network is busy.
Privacy-friendly payments
Pay with Monero and other cryptocurrencies to fund your relay without tying it to your identity.
Real human support
Talk to staff who understand relays and exits, not a ticketing black hole.
Frequently asked questions
Can I run a Tor exit node on a VPS?
Yes, as long as your provider allows exit traffic. HammerVM supports Tor relays and exit nodes, with locations in Stockholm and Chicago.
Should I use Ubuntu or Debian for a Tor exit node?
Both work well, and the Tor Project repository supports both. Debian is leaner, while Ubuntu LTS is familiar to many admins. Choose the one you are comfortable maintaining and patching.
How much bandwidth does a Tor exit node use?
It depends on your bandwidth cap. An exit averaging 50 Mbit/s uses about 16 TB per direction per month. Set RelayBandwidthRate to stay within your plan's fair usage.
What are the minimum specs for a Tor exit node?
For a moderate exit, aim for 2 CPU cores, 4 GB of RAM, 20 GB of storage and 50-100 Mbit/s of bandwidth, plus a static public IPv4 address.
Will I get abuse complaints?
Most likely, yes. A restricted exit policy, a clear reverse DNS name and prompt polite replies keep them manageable. A relay that is not an exit gets almost none.
Can I pay for a Tor VPS with Monero?
Yes. HammerVM accepts Monero (XMR) and other cryptocurrencies, so you can fund your relay without linking it to your identity.
Ready to run your Tor exit node?
Deploy a dedicated Sweden VPS from £4.99/mo and help build a faster, freer Tor network.
View Sweden VPS plansDocument Publish Date: 29th of September, 2026