///enEarning and Maintaining the Tor Guard Flag: Configuration Guide
The Guard flag is assigned to Tor relays that have demonstrated sufficient stability and bandwidth to serve as the entry point (guard relay) for Tor client circuits. Guard relays are the first hop in a 3-hop Tor circuit: they see the client's real IP address but not the destination. For this reason, Tor clients use a small number of guard relays consistently over time (rather than selecting randomly for each circuit) - this reduces the probability that a client's guard is a malicious relay controlled by an adversary. Running a relay that earns and maintains the Guard flag provides particularly valuable contribution to the Tor network's security model.
Bandwidth Requirements for Guard Flag
The bandwidth requirement for Guard flag is dynamic: set at the median measured bandwidth of all relays in the current consensus. As the Tor network grows, the median bandwidth increases. In 2026, the median is approximately 2-5 Mbit/s sustained. To ensure your relay meets the bandwidth requirement with margin: set RelayBandwidthRate and RelayBandwidthBurst at least 20% above the current median. Monitor your relay's measured bandwidth (vs your configured rate) on Tor Metrics. Measured bandwidth is what the bandwidth authority (bwauth) observes, not your configured rate. If measured bandwidth is significantly below configured rate, investigate: network interface saturation, CPU overload (AES-NI not active), or VPS provider throttling. Measured bandwidth must be above the median for the Guard flag.
Losing the Guard Flag and Recovery
The Guard flag can be lost if: measured bandwidth drops below the median (relay is overloaded or network connection degrades), WFU drops below threshold (relay has significant downtime), or the relay goes offline entirely for a significant period. Recovering the Guard flag after loss: address the underlying cause (upgrade bandwidth, fix stability issues), then wait for the relay to re-establish consensus presence with good stability metrics. Recovery typically takes 2-4 weeks of consistent stable operation. To minimize Guard flag loss: configure monitoring that alerts within 5 minutes of Tor process failure, use a VPS provider with strong uptime SLAs (99.9% or better), and schedule maintenance windows to minimize total downtime duration.
Ready to get started?
Skip the research. Tell us what you need, and we'll scope it, implement it, and hand it back — fully documented and production-ready.