Grey web vs dark web vs deep web.
Not three layers of one stack. Three different reasons a page is not in front of you: permission, routing and time. Only one of them describes content that anybody could read, and nobody can now.
Short answer
The iceberg diagram is wrong
Every explainer draws the same picture: a surface web on top, a deep web underneath, a dark web at the bottom, depth standing in for danger. It is memorable and it is misleading, because these are not layers of one stack. They are three unrelated reasons a page is not in front of you, and the reasons behave differently.
Deep web content is blocked by permission. Dark web content is blocked by routing. Grey web content, gray web in American usage, is blocked by time. Once you sort them that way the practical questions answer themselves, including the one that actually matters in an investigation: can I still go and get it.
The surface web belongs in the picture too, and not as the top of a pyramid. It is simply the part nothing blocks. The grey web is what the surface web leaves behind: pages that were on it, were indexed, and are not there any more.
Side by side
| Surface web | Deep web | Dark web | Grey web | |
|---|---|---|---|---|
| Why you cannot reach it | You can | Permission | Routing | Time |
| What blocks you | Nothing | Login, paywall, query form | Needs Tor or equivalent | It was deleted or cut off |
| Was it ever public? | Yes | No | No | Yes |
| Indexed by search engines? | Yes | No | No | It was, until it went |
| Can you get it back live? | Yes, just open it | Yes, with credentials | Yes, with the client | No, never |
| Share of the web | Small | The vast majority | Very small | Growing, unmeasured |
| Typical content | News, shops, public forums | Banking, intranets, databases | Marketplaces, leak sites, forums | Deleted posts, removed threads, dead communities |
| What recovers it | A browser | Access rights | The right browser | A capture made before deletion |
The deep web: blocked by permission
The deep web is everything a search engine cannot index because it would need to be somebody first. Your medical records, a company intranet, the contents of a database that only answers a form submission. By volume it dwarfs everything else on the web, and almost all of it is entirely mundane.
It is also the source of most of the confusion in this area, because popular coverage uses "deep web" and "dark web" interchangeably. They are not close. Logging into a webmail account puts you on the deep web. That is the whole of the mystery.
Deep web vs dark web: the confusion to clear first
Most people arriving at this question are really asking about two of the three, so it is worth settling before the grey web enters the picture. The deep web is everything a search engine cannot index because access needs a credential: online banking, a corporate intranet, a database that only answers a form. It is the bulk of the web by volume and it is almost entirely ordinary.
The dark web is a far smaller set of services reachable only through an anonymity network such as Tor. Popular coverage swaps the two words freely, which is where the folklore comes from. They are not close relatives. Logging into webmail puts you on the deep web; that is the whole of the mystery.
The grey web is neither, and it is the one no depth diagram has a place for, because it is not a place at all. It is the surface web after the fact.
The dark web: blocked by routing
The dark web is the set of services that are only reachable through an anonymity network, Tor above all. Being hard to find is the design goal rather than a side effect, and the population is small: a few tens of thousands of live services at any time, against billions of ordinary pages.
It matters to threat intelligence out of proportion to its size, because leak sites, ransomware blogs and some criminal markets live there. But it is not where most of the conversation happens. Attribution, recruitment, bragging, tooling talk and the early stages of a fraud campaign mostly take place on the open web, in public communities, in the clear. And then get deleted.
The grey web: blocked by time
Grey web content asked nothing of you when it was published. No credential, no client, no invitation. It sat in a public thread and search engines indexed it. Then the author deleted it, or a moderator removed it, or the community went private, or the platform closed its API and ended the ability to enumerate what exists.
This is the only one of the three where the blocker is not a door you can open. Credentials recover deep web content. A Tor client reaches dark web content. Nothing at all reaches grey web content, because there is nothing left at the address. The only thing that survives is a copy someone took while it was visible, which is what makes grey web data a fundamentally different asset from the other two.
It is also the fastest-moving of the three. On a sample of Reddit comments we recaptured seven days after collecting them, roughly one in twenty had already left public view, most removed by moderation rather than by their author. That is a first measurement on a small sample, and we are still consolidating it, but a weekly attrition rate in that range means the grey web grows continuously and silently.
Which one your investigation actually needs
Sort by the failure you can least afford. If you need what an organisation holds internally, that is a legal process question, not a collection question. If you need leak site postings and market listings, you need dark web monitoring, and there are competent vendors for it.
If you need to know what a person or a community said before they cleaned up, no amount of dark web tooling helps, and neither does a live platform search: the query you run today returns what survives today and stays silent about the rest. That is the specific gap grey web intelligence fills, by collecting at publication time so that a deletion becomes a dated event rather than an absence.
The practical difference is easiest to see rather than argue about. Try user lookup on an account that has scrubbed itself, or deleted post search on a thread that no longer renders on Reddit. No account needed.
Need the full archive via API?
The free tools query a slice of the archive. The API gives you all 30 billion posts and comments back to 2005, deleted content included, in under 300ms.
Grey, dark and deep, answered.
The dark web is unreachable because of routing: it requires Tor or an equivalent anonymity network, and it was never meant to be indexed. The grey web is unreachable because of time: it was ordinary public content, indexed and readable by anyone, until it was deleted, removed, made private or cut off when an API closed. A Tor browser reaches dark web content. Nothing reaches grey web content except a copy taken before it disappeared.
No. Deep web content is blocked by permission: a login, a paywall, a query form. It belongs to somebody and credentials retrieve it. Grey web content never required a credential. It was open to everyone, and then it stopped being retrievable at source.
It is not a place, so it is not dangerous in the way the question implies. It is a condition that public content falls into when it is deleted or cut off. Some of it is criminal chatter that was posted openly and then removed, which is exactly why investigators want it. Most of it is ordinary people deleting ordinary posts.
The deep web is everything a search engine cannot index because access needs a credential: online banking, an intranet, a database behind a query form. It is most of the web by volume and almost all of it is mundane. The dark web is the much smaller set of services reachable only through an anonymity network such as Tor. Popular coverage uses the two words interchangeably; they are not close. Logging into webmail puts you on the deep web.
The surface web is the part nothing blocks: indexed, reachable in an ordinary browser, no credential required. The grey web is what the surface web leaves behind. Every page in it was on the surface web and was indexed at the time, until it was deleted, removed, made private or cut off. The grey web is not a deeper layer, it is a former state of the same layer.
Because the early stages of most activity happen in the open before they move anywhere private. Recruitment, tooling discussion, bragging and attribution-relevant detail get posted in public communities and then deleted once they draw attention. A live platform search run afterwards returns nothing and gives no signal that anything was there.
There is no credible total, because you cannot count what is already gone. It can only be measured as a rate: how much of a known sample disappears over a given window. On Reddit comments recaptured seven days after collection, we observed roughly one in twenty already out of public view. That is a first measurement on a small sample and it is still being consolidated.
No. Dark web monitoring crawls onion services, leak sites and closed markets as they exist now. It has no mechanism for content that was public and has since been deleted, because that content has no live address to crawl. Covering the grey web requires having collected the material before it went.
Keep reading
The definition, how content turns grey, and what grey web intelligence recovers.
Where dark web monitoring ends and grey web collection has to begin.
Tested, with what each one can and cannot see once content is removed.
THINKPOL is an independent intelligence platform and is not affiliated with, endorsed by, or sponsored by Reddit Inc. or any third-party tool named on this page. "Reddit" is a registered trademark of Reddit Inc. Third-party tool descriptions reflect publicly observable functionality as of July 2026 and may change; corrections are welcome via our contact page.
Stop reading about
it in the news.
Request access to THINKPOL. We respond within one working day. A 30-minute scoping call follows, and a sandbox tenant is provisioned within five working days of contract signature.
Grey web intelligence for national security, law enforcement, CTI and corporate security teams. Built in France, hosted in the EU.
Free tools
Guides
Contact
- 59 rue de Ponthieu, Bureau 326
75008 Paris, France - contact@think-pol.com
