TechEarl

Tor Country Codes List: Set Exit Nodes by Country (torrc)

The full Tor country code list (ISO 3166-1 alpha-2) and how to set exit nodes by country in torrc: ExitNodes, ExcludeNodes, EntryNodes, ready-to-paste Five/Nine/14 Eyes blocks, torify and torsocks examples, and the StrictNodes pitfall.

Ishan Karunaratne⏱️ 18 min readUpdated
Share thisCopied
The full Tor country code list (ISO 3166-1) and how to pin exit nodes by country in torrc: ExitNodes, ExcludeNodes, Five/Nine/14 Eyes blocks, StrictNodes pitfalls.

Tor country codes are two-letter ISO 3166-1 alpha-2 codes wrapped in braces ({us}, {de}, {nl}) that you put in your torrc to control which countries your traffic may enter, exit, or avoid. Use ExitNodes for exit selection, ExcludeExitNodes for exit exclusions, and ExcludeNodes for broader exclusions. StrictNodes applies to ExcludeNodes; it does not enforce ExitNodes.

Below is the full searchable list of every Tor country code, plus working torrc snippets, ready-to-paste blocks for excluding the Five Eyes / Nine Eyes / 14 Eyes countries, command-line examples with torify and torsocks, the StrictNodes failure modes that catch most people, and how to verify which country your exit is actually using.

What are Tor country codes?

Tor country codes are two-letter abbreviations from the ISO 3166-1 alpha-2 standard that the Tor client uses to identify the geographic origin of a relay. You wrap them in braces inside torrc and pass them as a comma-separated list to one of three directives: ExitNodes (allowed exits), ExcludeNodes (banned countries for any hop), or EntryNodes (allowed entry guards). The Tor client maps relay addresses using its configured GeoIP database, so the codes work without any external service. The same codes apply across all platforms: Tor Browser, the tor daemon on Linux/macOS, and the bundled Tor inside applications like OnionShare. The table below lists every code Tor accepts in 2026.

In short, here is how Tor country codes work:

  • Format: lowercase ISO 3166-1 alpha-2 in braces, e.g. {us}, {de}, {nl} (Tor parses them case-insensitively).
  • ExitNodes {us},{de}: restrict the last hop to these countries.
  • ExcludeNodes {cn},{ru}: ban these countries from any hop.
  • EntryNodes {se},{ch}: restrict the first hop (guard) to these countries.
  • StrictNodes 1: makes ExcludeNodes mandatory even for special-purpose circuits. It does not change ExitNodes or ExcludeExitNodes.

Jump to:

Full Tor country code list

Tor country codes (ISO 3166-1 alpha-2)246
Countrytorrc code
ASCENSION ISLAND{ac}
AFGHANISTAN{af}
ALAND{ax}
ALBANIA{al}
ALGERIA{dz}
ANDORRA{ad}
ANGOLA{ao}
ANGUILLA{ai}
ANTARCTICA{aq}
ANTIGUA AND BARBUDA{ag}
ARGENTINA REPUBLIC{ar}
ARMENIA{am}
ARUBA{aw}
AUSTRALIA{au}
AUSTRIA{at}
AZERBAIJAN{az}
BAHAMAS{bs}
BAHRAIN{bh}
BANGLADESH{bd}
BARBADOS{bb}
BELARUS{by}
BELGIUM{be}
BELIZE{bz}
BENIN{bj}
BERMUDA{bm}
BHUTAN{bt}
BOLIVIA{bo}
BOSNIA AND HERZEGOVINA{ba}
BOTSWANA{bw}
BOUVET ISLAND{bv}
BRAZIL{br}
BRITISH INDIAN OCEAN TERR{io}
BRITISH VIRGIN ISLANDS{vg}
BRUNEI DARUSSALAM{bn}
BULGARIA{bg}
BURKINA FASO{bf}
BURUNDI{bi}
CAMBODIA{kh}
CAMEROON{cm}
CANADA{ca}
CAPE VERDE{cv}
CAYMAN ISLANDS{ky}
CENTRAL AFRICAN REPUBLIC{cf}
CHAD{td}
CHILE{cl}
PEOPLE'S REPUBLIC OF CHINA{cn}
CHRISTMAS ISLANDS{cx}
COCOS ISLANDS{cc}
COLOMBIA{co}
COMORAS{km}
CONGO{cg}
CONGO (DEMOCRATIC REPUBLIC){cd}
COOK ISLANDS{ck}
COSTA RICA{cr}
COTE D IVOIRE{ci}
CROATIA{hr}
CUBA{cu}
CYPRUS{cy}
CZECH REPUBLIC{cz}
DENMARK{dk}
DJIBOUTI{dj}
DOMINICA{dm}
DOMINICAN REPUBLIC{do}
EAST TIMOR{tp}
ECUADOR{ec}
EGYPT{eg}
EL SALVADOR{sv}
EQUATORIAL GUINEA{gq}
ESTONIA{ee}
ETHIOPIA{et}
FALKLAND ISLANDS{fk}
FAROE ISLANDS{fo}
FIJI{fj}
FINLAND{fi}
FRANCE{fr}
FRANCE METROPOLITAN{fx}
FRENCH GUIANA{gf}
FRENCH POLYNESIA{pf}
FRENCH SOUTHERN TERRITORIES{tf}
GABON{ga}
GAMBIA{gm}
GEORGIA{ge}
GERMANY{de}
GHANA{gh}
GIBRALTER{gi}
GREECE{gr}
GREENLAND{gl}
GRENADA{gd}
GUADELOUPE{gp}
GUAM{gu}
GUATEMALA{gt}
GUINEA{gn}
GUINEA-BISSAU{gw}
GUYANA{gy}
HAITI{ht}
HEARD & MCDONALD ISLAND{hm}
HONDURAS{hn}
HONG KONG{hk}
HUNGARY{hu}
ICELAND{is}
INDIA{in}
INDONESIA{id}
IRAN, ISLAMIC REPUBLIC OF{ir}
IRAQ{iq}
IRELAND{ie}
ISLE OF MAN{im}
ISRAEL{il}
ITALY{it}
JAMAICA{jm}
JAPAN{jp}
JORDAN{jo}
KAZAKHSTAN{kz}
KENYA{ke}
KIRIBATI{ki}
KOREA, DEM. PEOPLES REP OF{kp}
KOREA, REPUBLIC OF{kr}
KUWAIT{kw}
KYRGYZSTAN{kg}
LAO PEOPLE'S DEM. REPUBLIC{la}
LATVIA{lv}
LEBANON{lb}
LESOTHO{ls}
LIBERIA{lr}
LIBYAN ARAB JAMAHIRIYA{ly}
LIECHTENSTEIN{li}
LITHUANIA{lt}
LUXEMBOURG{lu}
MACAO{mo}
MACEDONIA{mk}
MADAGASCAR{mg}
MALAWI{mw}
MALAYSIA{my}
MALDIVES{mv}
MALI{ml}
MALTA{mt}
MARSHALL ISLANDS{mh}
MARTINIQUE{mq}
MAURITANIA{mr}
MAURITIUS{mu}
MAYOTTE{yt}
MEXICO{mx}
MICRONESIA{fm}
MOLDAVA REPUBLIC OF{md}
MONACO{mc}
MONGOLIA{mn}
MONTENEGRO{me}
MONTSERRAT{ms}
MOROCCO{ma}
MOZAMBIQUE{mz}
MYANMAR{mm}
NAMIBIA{na}
NAURU{nr}
NEPAL{np}
NETHERLANDS ANTILLES{an}
NETHERLANDS, THE{nl}
NEW CALEDONIA{nc}
NEW ZEALAND{nz}
NICARAGUA{ni}
NIGER{ne}
NIGERIA{ng}
NIUE{nu}
NORFOLK ISLAND{nf}
NORTHERN MARIANA ISLANDS{mp}
NORWAY{no}
OMAN{om}
PAKISTAN{pk}
PALAU{pw}
PALESTINE{ps}
PANAMA{pa}
PAPUA NEW GUINEA{pg}
PARAGUAY{py}
PERU{pe}
PHILIPPINES (REPUBLIC OF THE){ph}
PITCAIRN{pn}
POLAND{pl}
PORTUGAL{pt}
PUERTO RICO{pr}
QATAR{qa}
REUNION{re}
ROMANIA{ro}
RUSSIAN FEDERATION{ru}
RWANDA{rw}
SAMOA{ws}
SAN MARINO{sm}
SAO TOME/PRINCIPE{st}
SAUDI ARABIA{sa}
SCOTLAND{uk}
SENEGAL{sn}
SERBIA{rs}
SEYCHELLES{sc}
SIERRA LEONE{sl}
SINGAPORE{sg}
SLOVAKIA{sk}
SLOVENIA{si}
SOLOMON ISLANDS{sb}
SOMALIA{so}
SOMOA,GILBERT,ELLICE ISLANDS{as}
SOUTH AFRICA{za}
SOUTH GEORGIA, SOUTH SANDWICH ISLANDS{gs}
SOVIET UNION{su}
SPAIN{es}
SRI LANKA{lk}
ST. HELENA{sh}
ST. KITTS AND NEVIS{kn}
ST. LUCIA{lc}
ST. PIERRE AND MIQUELON{pm}
ST. VINCENT & THE GRENADINES{vc}
SUDAN{sd}
SURINAME{sr}
SVALBARD AND JAN MAYEN{sj}
SWAZILAND{sz}
SWEDEN{se}
SWITZERLAND{ch}
SYRIAN ARAB REPUBLIC{sy}
TAIWAN{tw}
TAJIKISTAN{tj}
TANZANIA, UNITED REPUBLIC OF{tz}
THAILAND{th}
TOGO{tg}
TOKELAU{tk}
TONGA{to}
TRINIDAD AND TOBAGO{tt}
TUNISIA{tn}
TURKEY{tr}
TURKMENISTAN{tm}
TURKS AND CALCOS ISLANDS{tc}
TUVALU{tv}
UGANDA{ug}
UKRAINE{ua}
UNITED ARAB EMIRATES{ae}
UNITED KINGDOM (no new registrations){gb}
UNITED KINGDOM{uk}
UNITED STATES{us}
UNITED STATES MINOR OUTL.IS.{um}
URUGUAY{uy}
UZBEKISTAN{uz}
VANUATU{vu}
VATICAN CITY STATE{va}
VENEZUELA{ve}
VIET NAM{vn}
VIRGIN ISLANDS (USA){vi}
WALLIS AND FUTUNA ISLANDS{wf}
WESTERN SAHARA{eh}
YEMEN{ye}
ZAMBIA{zm}
ZIMBABWE{zw}
Build your torrc block
torrc
# Select countries from the table above…

In plain English: Select one or more countries from the table above to build your torrc block.

The table above is a country-code reference, not a live list of exit relays. A code can be valid even when no suitable exit is currently available there. The selector builds a torrc snippet from your chosen countries. Tick the countries you want, choose the directive (ExitNodes, ExcludeNodes, EntryNodes, or ExcludeExitNodes), and copy the generated snippet straight into your config.

Set Tor exit nodes by country with ExitNodes

ExitNodes tells Tor which countries are acceptable for the last hop, where your traffic exits onto the public internet. This is the directive that matters for almost every use case (testing geolocated content, checking a site as seen from another country, avoiding a specific jurisdiction).

text
# torrc
ExitNodes {us},{de},{nl}

ExitNodes restricts selection for connections that exit to the public internet. If no suitable listed exit allows the destination, the connection can fail. StrictNodes does not change this behavior. Onion-service and directory circuits are different and do not necessarily end at an internet exit.

For a single country, drop the comma list:

text
ExitNodes {us}

Validate the configuration and reload the specific daemon instance you edited. For Tor Browser, close it before editing and restart it afterwards.

Set the exit node country in Tor Browser

To pin the exit country in Tor Browser, edit the bundle's own torrc and add the same ExitNodes line described above, then fully restart the browser. Tor Browser does not read /etc/tor/torrc; it ships its own copy inside the bundle:

text
# Linux
~/.local/share/torbrowser/tbb/x86_64/tor-browser/Browser/TorBrowser/Data/Tor/torrc

# Windows
<install dir>\Browser\TorBrowser\Data\Tor\torrc

# macOS
~/Library/Application Support/TorBrowser-Data/Tor/torrc

Close Tor Browser first, open that file, and add the same syntax the rest of this article uses, for example ExitNodes {us}. See the official Tor Browser torrc locations for your platform. Browser command-line settings can override options in the file. A connection toggle inside the browser is not enough; quit the whole process so the bundled tor daemon rereads the file on next launch.

Two caveats. Tor Browser updates can overwrite or relocate this file, so recheck the directive after upgrading. And pinning to one country shrinks your exit set, which reduces anonymity and makes you easier to fingerprint, so prefer a few countries over a single one unless you specifically need one jurisdiction.

Use ExcludeNodes to ban specific countries

ExcludeNodes blacklists countries for any hop in the circuit, not just the exit. Common reasons: avoid hosting countries you distrust, avoid countries that block traffic to your destination, or comply with internal policy that bans certain jurisdictions.

text
# torrc
ExcludeNodes {cn},{ru},{ir},{kp}
StrictNodes 1

With StrictNodes 0, Tor can make exceptions to ExcludeNodes for purposes such as directory access and onion-service connections. StrictNodes 1 forbids those exceptions and can break that functionality.

There is also ExcludeExitNodes, which bans countries from being the exit specifically but allows them at other hops. Use it when you don't mind a country being in the middle of the circuit but don't want it terminating the connection.

text
ExcludeExitNodes {us},{gb},{ca},{au},{nz}

Block exit nodes by alliance: Five Eyes, Nine Eyes, 14 Eyes

The most common reason people reach for a long ExcludeNodes list is to avoid the intelligence-sharing alliances: the Five Eyes (AU, CA, NZ, GB, US), the Nine Eyes (Five Eyes plus DK, FR, NL, NO), and the 14 Eyes / SIGINT Seniors Europe (Nine Eyes plus DE, BE, IT, SE, ES). Here are the three ready-to-paste blocks. Each list is additive: Nine Eyes contains the Five, and 14 Eyes contains the Nine.

text
# torrc — exclude Five Eyes (AU, CA, NZ, GB, US)
ExcludeNodes {au},{ca},{nz},{gb},{us}
StrictNodes 1
text
# torrc — exclude Nine Eyes (Five Eyes + DK, FR, NL, NO)
ExcludeNodes {au},{ca},{nz},{gb},{us},{dk},{fr},{nl},{no}
StrictNodes 1
text
# torrc — exclude 14 Eyes (Nine Eyes + DE, BE, IT, SE, ES)
ExcludeNodes {au},{ca},{nz},{gb},{us},{dk},{fr},{nl},{no},{de},{be},{it},{se},{es}
StrictNodes 1

Two things to get right that most copy-paste lists get wrong:

  • {au} is Australia, {at} is Austria. Several widely-shared Five Eyes lists accidentally exclude Austria instead of Australia. Double-check the Five Eyes block above: it uses {au}.
  • Large exclusions can remove useful relay capacity. The effect changes with the live relay set and destination exit policies; a fixed percentage is not reliable. A relay's country does not prove its operator or jurisdiction. Country filtering is not an anonymity guarantee. If your requirement concerns only internet exits, use ExcludeExitNodes rather than excluding all hops.

Exclude ungeolocated relays (the unknown country code)

Tor maps every relay to a country using its bundled GeoIP database. A relay whose IP the database cannot place is assigned the country code ??. You can target those relays explicitly with the same brace syntax:

text
# Drop every relay Tor cannot geolocate
ExcludeNodes {??}
StrictNodes 1

This is useful when a policy requires a known jurisdiction for every hop, since {??} relays are exactly the ones whose location can't be confirmed. The {??} code also works in ExitNodes and ExcludeExitNodes. Note that excluding {??} shrinks the relay pool, so pair it with a generous country list to keep circuits buildable.

Use EntryNodes to choose the guard country

EntryNodes controls the first hop, the guard relay. Most users should leave this alone. Tor's guard-selection algorithm has security properties (long-lived guards, fingerprint diversity) that you defeat by pinning entries.

If you do need to set it, for testing or research:

text
EntryNodes {se},{no}

The countries you pick for entry should ideally be jurisdictions with strong privacy laws and a large healthy relay set (Sweden, Norway, Netherlands, Switzerland are common choices).

Combining directives

The three directives compose freely. A typical "research lab" configuration:

text
EntryNodes {se},{ch}
ExitNodes {us},{de}
ExcludeNodes {cn},{ir},{kp},{ru},{sy}
StrictNodes 1

This says: enter through Sweden or Switzerland, exit through US or Germany, and never touch China, Iran, North Korea, Russia, or Syria at any hop.

Run torify and torsocks through country-pinned exits

torify and torsocks both route a single command's TCP traffic through Tor's local SOCKS proxy (default 127.0.0.1:9050). Neither tool accepts country codes directly. To make torify curl exit from a specific country, you configure ExitNodes in torrc, reload the Tor daemon, then run the command. The country pinning happens inside the Tor daemon, not the wrapper. The wrapper only works for applications and network calls it can intercept; raw sockets, static binaries, and some platform restrictions can bypass or prevent interception. Prefer native SOCKS support when available.

The three-step workflow:

1. Pin the exit country in torrc.

text
# /etc/tor/torrc
ExitNodes {us}

2. Reload the Tor daemon.

bash
# Linux (systemd)
sudo systemctl reload tor

# macOS (Homebrew) or non-systemd Linux
pkill -HUP tor

3. Run your command through torify.

bash
torify curl https://dnschkr.com/api/ip
# {"ip":"151.115.X.X","type":"IPv4","success":true,
#  "geo":{"country":"United States","country_code":"US","flag_emoji":"🇺🇸", ...}}

I use DNS Checker (dnschkr.com/api/ip) for verification because its response returns more diagnostic context than most IP lookup endpoints: the ISO alpha-2 country_code Tor uses internally, the full geo block, ASN, flag emoji, and IPv4/IPv6 type in a single payload. Compare the reported country with Tor's view, allowing for disagreements between GeoIP databases.

torify is a thin wrapper around torsocks. On modern systems (Debian/Ubuntu 22.04+, Fedora 38+, Arch, Tor Browser bundle) the two names are interchangeable. Run which torify to confirm what's installed; on many systems it's a symlink to torsocks.

Common torify command examples

bash
# Verify exit IP and country (dnschkr returns the ISO alpha-2 code)
torify curl https://dnschkr.com/api/ip
torify curl https://check.torproject.org/api/ip

# Anonymous download
torify wget https://example.com/file.tar.gz

# Clone a git repo through Tor
torify git clone https://github.com/user/repo.git

# SSH over Tor (the destination must allow Tor)
torify ssh user@example.com

# nmap a host through Tor (TCP scans only, no SYN scan)
torify nmap -sT -p 80,443 example.com

The wrapper intercepts the program's network calls (via LD_PRELOAD on Linux, DYLD_INSERT_LIBRARIES on macOS) and routes everything through the SOCKS proxy, including DNS lookups. This matters: a plain curl --socks5 127.0.0.1:9050 resolves DNS locally and leaks the hostname to your ISP. torify curl resolves through Tor, so no leak.

torify vs torsocks

ToolStatusWhat it does
torifyDeprecated wrapper, still shipsCalls torsocks underneath. Equivalent for most uses.
torsocksCurrent, maintainedThe actual library that hooks network calls and routes them through Tor's SOCKS port.
proxychains / proxychains-ngThird-party alternativeMore configurable, supports chained proxies. Not part of Tor.

For new scripts and documentation, prefer torsocks. For pasting one-liners from old guides, torify still works.

Multiple Tor instances for per-command country switching

The single-torrc approach pins everything routed through Tor to one country. To switch exit countries per command without restarting Tor, run multiple Tor daemon instances on different SOCKS ports, each with its own torrc.

text
# /etc/tor/torrc-us
SocksPort 9051
DataDirectory /var/lib/tor-us
ExitNodes {us}

# /etc/tor/torrc-de
SocksPort 9052
DataDirectory /var/lib/tor-de
ExitNodes {de}

Start each instance:

bash
tor -f /etc/tor/torrc-us &
tor -f /etc/tor/torrc-de &

Point torsocks at the SOCKS port you want with -p / --port (you can also export TORSOCKS_TOR_PORT instead of passing the flag):

bash
# Exit from US (country_code: "US")
torsocks -p 9051 curl https://dnschkr.com/api/ip

# Exit from Germany (country_code: "DE")
torsocks -p 9052 curl https://dnschkr.com/api/ip

This pattern is the standard way to run multi-country smoke tests for geo-blocked content from a single shell session. For three or four countries it's fine; beyond that consider a proper Tor SOCKS proxy farm or a service like Tor's own MapAddress feature.

The same -p flag works for torify on systems where it's a torsocks symlink.

StrictNodes 1: what it does and when it breaks Tor

The Tor manual defines StrictNodes specifically for ExcludeNodes.

SettingEffect on ExcludeNodes
StrictNodes 0 (default)Avoids excluded nodes but permits exceptions for specified special-purpose operations
StrictNodes 1Enforces the exclusion even when an operation would otherwise fail

It does not make ExitNodes or ExcludeExitNodes stricter. If an exit-country list leaves no usable exit for a destination, changing StrictNodes is not the remedy; revise the exit list after checking the logs. Check for conflicts too: ExcludeNodes wins when a relay is both selected and excluded.

A broad ExcludeNodes list plus StrictNodes can also prevent onion-service or directory operations. Validate the configuration and test the traffic you actually need, rather than assuming a successful bootstrap proves every connection will work.

Verify the exit node country

After setting ExitNodes, confirm the exit is actually in the country you asked for. Three ways:

1. DNS Checker IP API (returns the ISO alpha-2 code Tor uses):

bash
torify curl https://dnschkr.com/api/ip
# {"ip":"151.115.X.X","success":true,
#  "geo":{"country":"United States","country_code":"US","flag_emoji":"🇺🇸", ...}}

The geo.country_code field is the same two-letter code you put in ExitNodes {us}, so verification is a direct string match. DNS Checker is a useful tool for this kind of debugging because it returns more diagnostic context than check.torproject.org (full geo block, ASN, flag emoji, IPv4/IPv6 type) in a single response, so you can confirm exit country and ASN in one call.

2. Tor's own check service:

bash
torify curl https://check.torproject.org/api/ip

Returns the exit IP plus a confirmation that you're actually using Tor. Cross-reference the IP against any geolocation service.

3. From Tor Browser:

Open the circuit display (the lock icon → "View circuit info"). The last hop is labeled with its country flag.

If the reported country differs, check that you used the intended Tor instance, that the configuration loaded, and whether the two GeoIP databases disagree. Do not attribute the mismatch to StrictNodes being off.

Troubleshooting

Tor won't connect after editing torrc. Validate the actual configuration with tor --verify-config -f /path/to/torrc, then inspect that instance's logs. Check for invalid syntax, missing GeoIP data, conflicting selections, and an exit list too small for your destination. Back out the particular change you made; disabling StrictNodes will not relax ExitNodes.

Circuit builds but the site geoblocks me anyway. Some sites use multiple geo sources (IP geolocation + browser headers + timezone). Tor Browser already spoofs the timezone and locale, but check that the exit IP is actually in the country you wanted (above) and that you're not leaking your real timezone via JavaScript.

Exit country is correct but speed is terrible. Country pinning concentrates load on a small relay set. Try a country with more capacity (US, Germany, Netherlands, France) or list multiple alternatives so Tor can load-balance.

{us} syntax not working. Country codes require braces: ExitNodes {us},{de}. Bare identifiers are not equivalent country-code syntax.

Bridges and pluggable transports. If you're using bridges (obfs4, Snowflake, meek), country restrictions still apply to your exit, but the entry hop goes through the bridge instead of a normal guard. Country directives don't apply to bridges themselves.

Resources

FAQ

Tor country codes are the two-letter ISO 3166-1 alpha-2 codes ({us}, {de}, {nl}) you place in torrc to tell Tor which countries may serve as your exit, entry, or excluded hops. Tor accepts every alpha-2 code, mapping each relay to a country via its bundled GeoIP database.

The full searchable list of Tor country codes is in the country code list above; the underlying standard is ISO 3166-1 alpha-2.

Yes. Tor uses ISO 3166-1 alpha-2, the same two-letter codes as TLDs ({us}, {de}, {jp}) and as most web APIs. The only difference is the brace syntax: {us} in torrc, us elsewhere.

The codes are lower-case in torrc by convention but Tor parses them case-insensitively.

A common cause is an exit-country list with no suitable available relay. If the countries you picked have no exit relays that allow your destination port, Tor refuses to build the circuit and the connection hangs.

Inspect the logs and revise the exit list if needed. StrictNodes only affects ExcludeNodes; changing it does not relax ExitNodes.

ExcludeNodes bans the listed countries from any hop in the circuit (entry, middle, or exit). ExcludeExitNodes bans them only from being the exit, allowing them at intermediate hops.

Use ExcludeNodes when you want to avoid a country touching your traffic at all. Use ExcludeExitNodes when you just don't want a particular jurisdiction terminating the connection (a common pattern for the Five Eyes countries).

Put the alliance's country codes in ExcludeNodes with StrictNodes 1. Five Eyes is {au},{ca},{nz},{gb},{us}; Nine Eyes adds {dk},{fr},{nl},{no}; 14 Eyes adds {de},{be},{it},{se},{es} on top of that. The ready-to-paste blocks are above.

Watch two things: {au} is Australia (not {at}, Austria), and broad exclusions can substantially reduce the available relay set, so with StrictNodes 1 it can stall. If you only care about the exit jurisdiction, use ExcludeExitNodes with the same list instead.

{??} matches relays that Tor's bundled GeoIP database cannot place in any country. ExcludeNodes {??} with StrictNodes 1 drops every relay whose location is unknown, but GeoIP classification does not establish a confirmed legal jurisdiction. The same code works in ExitNodes and ExcludeExitNodes.

Tor Browser uses its own bundled torrc at Browser/TorBrowser/Data/Tor/torrc. Edit that file (when Tor Browser is closed) and the next launch picks up the directives. On macOS it is under Library/Application Support/TorBrowser-Data/Tor in the user profile.

Follow the official instructions for your platform; Tor Browser may override options with command-line settings.

No. Tor selects according to its own GeoIP database. A destination may use a different database, account location, or other signals, so it may assign the same address a different country.

Tor Browser spoofs the most common fingerprint signals, but third-party JavaScript can still leak intent. For high-stakes geoblocking, verify with the site directly.

The distribution changes over time. Compare current relay counts and exit bandwidth using Tor Metrics; a country-code table is not evidence of current exit capacity.

Live numbers are at Tor Metrics: relay flags. Filter for the Exit flag to see current distribution.

Yes, but Tor also accepts relay fingerprints (40-character hex strings) and nicknames in the same fields. The brace syntax ({us}) signals a country code specifically; bare strings are interpreted as fingerprints or nicknames first.

Stick with the brace syntax for country pinning to avoid ambiguity.

Not directly. torify and torsocks route traffic through whatever exit countries the Tor daemon is configured to use. To pin torify curl to a country, set ExitNodes {us} in your torrc, reload Tor with systemctl reload tor or pkill -HUP tor, then run the command. The pinning happens at the daemon, not the wrapper.

To switch countries per command without reloading, run multiple Tor instances on different SOCKS ports (see the section above) and point torsocks -p PORT at the one you want.

torsocks is the actual library that hooks a program's network calls and routes them through Tor's SOCKS proxy. torify is a deprecated shell wrapper around it; on modern Linux and macOS Tor packages, torify is typically a symlink to torsocks.

For new scripts and documentation, use torsocks. For one-liners copied from older guides, torify still works on most systems.

Yes. torify and torsocks intercept the program's DNS resolution and send the hostname through Tor instead of resolving locally. A plain curl --socks5 127.0.0.1:9050 https://example.com does NOT do this; it resolves example.com via your local resolver, which leaks the hostname to your ISP.

If you're routing traffic through Tor for privacy reasons, always prefer torify curl or torsocks curl over the bare --socks5 flag.

See also

Sources

Authoritative references this article was fact-checked against.

TagsTORNetworkingPrivacySecurityAnonymitytorrctorifytorsocksCommand Line

Found this useful? Pass it on.

Copied

Ishan Karunaratne

Systems and Network Architect · Chief Technology Officer

Systems and network architect and Chief Technology Officer with more than two decades designing, building, and running production software, cloud and network architecture, Linux systems, and the bare metal underneath them, and lately working AI into the stack. A US Army veteran who served in Operation Iraqi Freedom. What I write here is drawn from the full arc of that work, across architecture, engineering, and operations, not any single job.

Keep reading

Related posts

grep -c counts matching lines, not occurrences. Use grep -o piped into wc -l for the true count, grep -rc for per-file counts, grep -vc to count non-matching lines, plus the macOS BSD vs GNU differences.

How to Count Matches with grep -c (and the Line-vs-Occurrence Trap)

grep -c counts matching LINES, not occurrences. A line with three hits still counts as 1. The fix is grep -o piped into wc -l, which puts every match on its own line first. Per-file counts, filtering out the :0 noise, counting non-matching lines, and the BSD vs GNU differences.