VERIFY CONSOLE · PGP · FINGERPRINT · 2026

Verify a Mars Onion Link with PGP and Fingerprint in 2026

Verifying a Mars link is two checks in order: prove the signed list with a PGP signature, then match the address you hold against the fingerprint. A good signature proves the key, not what waits behind the link. The tool below checks an address’s shape; the signature check is what proves it is really Mars.

CANON POINTERThis console explains the method; it does not restate the mirror table. The verified address and the full signed list live on the Mars canon (home).
WHAT IT CHECKStwo real checks

What a real verification actually checks

People conflate two different tests. One asks whether an address is shaped like an onion. The other asks whether it is the address the canon signed. Only the second one is proof. Here is how they line up.

The verification path for a Mars onion linkPastean addressSignatureprove the listMatchfingerprint
1 · PasteYou drop an address in. On its own it is just a candidate, trusted by nobody yet.
2 · SignatureA PGP check proves the signed mirror list is genuine and unaltered.
3 · MatchThe address has to match a fingerprint in that list. No match, no trust.
METHODtwo commands

Verify a Mars link in two commands

The whole proof is short once the key is on your machine. Import the canon key one time, then verify the signature that travels with the mirror list. A pass means the list is authentic and the addresses in it can be trusted by comparison.

gpg --import mars-canon.asc
gpg --verify mirrors.json.sig mirrors.json

Read the output for a good signature from the canon key, then compare the printed fingerprint with the one you first trusted. If either the signature or the fingerprint is off, stop and copy a fresh address from the signed canon.

Honest limit: the fingerprint publishes in Phase 0. Until then, compare the full 56-character string by eye and cross-check the canary before you connect.

FORMAT CHECKclient-side only

Check the shape of an onion address

Paste an onion string to check its shape. This runs in your browser: it confirms the length and character set of a v3 onion. It does not prove the address is the verified Mars onion, and it sends nothing anywhere.

PHISHING VS CANONthe real gap

Phishing clone or signed canon?

A phishing page can copy the design, the wording, even a plausible onion. What it cannot copy is a signature made with a key it does not have. That gap is the whole game.

Signed canon

Its address is in the PGP-signed list and clears the fingerprint check. Verifiable without trusting the page in front of you.

Phishing clone

Looks right, passes a format check, but is missing from the signed set. It exists to catch a login and a deposit.

Rule of thumb: a page that looks perfect but fails the signature is more dangerous than one that looks rough, not less.

COMMON MISTAKESwhere checks go wrong

Where Mars onion verification goes wrong in practice

Most people who get burned on a Mars darknet market link did not skip verification entirely — they did a partial version of it and stopped one step short. The three patterns below account for nearly every phishing report we have read about Mars-branded pages. None of them require a lecture on cryptography to understand; they are habits, and habits are fixable.

Trusting a search engine result instead of the signed list

A Mars darknet market link that ranks on a clearnet search engine tells you almost nothing about whether it is genuine. Ad slots and organic results on search engines are routinely bought or seeded by phishing operators who mirror the real Mars market's look exactly, down to the loading animation and the login copy. The address itself may resolve, load fast, and even accept a login — all of that is possible on a clone. The only fact that matters is whether the onion address appears in the PGP-signed canon list, matched by fingerprint, not by how convincing the page around it looks. Bookmark the verified address once you have checked it here, and stop re-discovering Mars through search results each session.

Confusing "the mirror loaded" with "the mirror is verified"

A working page and a verified page are not the same claim, and conflating them is the single most common verification mistake we see. Tor hidden services can and do load correctly while still being operated by someone other than the Mars team — cloning a darknet market's front end is a mechanical task, not a cryptographic one. A page loading proves only that a server answered on that onion address. It says nothing about who controls the server, what happens to a password typed into its login form, or whether a Monero address shown at checkout was substituted. Verification means the fingerprint of the address matches the one in the signed canon; nothing short of that check earns the word "verified" on this page, and we try to avoid using it loosely.

Skipping re-verification after a Mars mirror rotation

Darknet market operators, Mars included, rotate onion addresses for operational reasons — a suspected leak, a DDoS pattern, routine hygiene, or infrastructure moves that have nothing to do with the market's legitimacy. Each rotation invalidates the previous address as a trust anchor even if the old one still technically resolves for a while during transition. A canon that was accurate last month can be stale today. Treat every Mars session as a fresh check: re-run the fingerprint match against the current signed list rather than relying on an address saved from a prior visit, and prefer the mirrors page for the current canon over a bookmark you set weeks ago.

QUESTIONSplain answers

Verification questions people ask

Does the format checker prove a link is the real Mars?

No. It only confirms an address has the shape of a v3 onion. Proof comes from matching it to the PGP-signed fingerprint, which happens off this page.

What does a good signature actually tell me?

That the mirror list was signed by the canon key and has not been altered. It does not vouch for what the market does once you are inside.

Where does the checker send what I paste?

Nowhere. The shape check runs in your browser and sends nothing. You can read the page source to confirm it before you trust it.

A clone matched the format check. Now what?

That is expected: a clone can share the exact onion format. Reject it because it is absent from the signed list, not because of how it looks.

Do I need to verify Mars again if I already verified it last week?

Yes. Darknet market operators including Mars rotate onion addresses without warning, and a canon that was accurate last week can be stale today. Re-run the fingerprint match each time you return rather than trusting a saved address.

Can two different onion addresses both be genuine Mars mirrors at once?

Yes — Mars, like most darknet markets, publishes several parallel mirrors for redundancy. Any address on the current signed list counts as genuine; the count of live mirrors changes as old ones rotate out.

RELATED

Once a link clears

Compare working onions on the mirrors page, or follow the full access sequence before you log in.

See working mirrors