Grey web

Grey web vs dark web vs deep web.

Not three layers of one stack. Three different reasons a page is not in front of you: permission, routing and time. Only one of them describes content that anybody could read, and nobody can now.

Short answer

Deep web content is blocked by permission and credentials retrieve it. Dark web content is blocked by routing and a Tor client reaches it. Grey web content is blocked by time: it was public, it was indexed, and then it was deleted, removed, made private or de-APIed. Nothing retrieves it, because nothing is left at the address. Only a capture made before it disappeared survives.
01

The iceberg diagram is wrong

Every explainer draws the same picture: a surface web on top, a deep web underneath, a dark web at the bottom, depth standing in for danger. It is memorable and it is misleading, because these are not layers of one stack. They are three unrelated reasons a page is not in front of you, and the reasons behave differently.

Deep web content is blocked by permission. Dark web content is blocked by routing. Grey web content, gray web in American usage, is blocked by time. Once you sort them that way the practical questions answer themselves, including the one that actually matters in an investigation: can I still go and get it.

The surface web belongs in the picture too, and not as the top of a pyramid. It is simply the part nothing blocks. The grey web is what the surface web leaves behind: pages that were on it, were indexed, and are not there any more.

02

Side by side

Surface webDeep webDark webGrey web
Why you cannot reach itYou canPermissionRoutingTime
What blocks youNothingLogin, paywall, query formNeeds Tor or equivalentIt was deleted or cut off
Was it ever public?YesNoNoYes
Indexed by search engines?YesNoNoIt was, until it went
Can you get it back live?Yes, just open itYes, with credentialsYes, with the clientNo, never
Share of the webSmallThe vast majorityVery smallGrowing, unmeasured
Typical contentNews, shops, public forumsBanking, intranets, databasesMarketplaces, leak sites, forumsDeleted posts, removed threads, dead communities
What recovers itA browserAccess rightsThe right browserA capture made before deletion
03

The deep web: blocked by permission

The deep web is everything a search engine cannot index because it would need to be somebody first. Your medical records, a company intranet, the contents of a database that only answers a form submission. By volume it dwarfs everything else on the web, and almost all of it is entirely mundane.

It is also the source of most of the confusion in this area, because popular coverage uses "deep web" and "dark web" interchangeably. They are not close. Logging into a webmail account puts you on the deep web. That is the whole of the mystery.

04

Deep web vs dark web: the confusion to clear first

Most people arriving at this question are really asking about two of the three, so it is worth settling before the grey web enters the picture. The deep web is everything a search engine cannot index because access needs a credential: online banking, a corporate intranet, a database that only answers a form. It is the bulk of the web by volume and it is almost entirely ordinary.

The dark web is a far smaller set of services reachable only through an anonymity network such as Tor. Popular coverage swaps the two words freely, which is where the folklore comes from. They are not close relatives. Logging into webmail puts you on the deep web; that is the whole of the mystery.

The grey web is neither, and it is the one no depth diagram has a place for, because it is not a place at all. It is the surface web after the fact.

05

The dark web: blocked by routing

The dark web is the set of services that are only reachable through an anonymity network, Tor above all. Being hard to find is the design goal rather than a side effect, and the population is small: a few tens of thousands of live services at any time, against billions of ordinary pages.

It matters to threat intelligence out of proportion to its size, because leak sites, ransomware blogs and some criminal markets live there. But it is not where most of the conversation happens. Attribution, recruitment, bragging, tooling talk and the early stages of a fraud campaign mostly take place on the open web, in public communities, in the clear. And then get deleted.

06

The grey web: blocked by time

Grey web content asked nothing of you when it was published. No credential, no client, no invitation. It sat in a public thread and search engines indexed it. Then the author deleted it, or a moderator removed it, or the community went private, or the platform closed its API and ended the ability to enumerate what exists.

This is the only one of the three where the blocker is not a door you can open. Credentials recover deep web content. A Tor client reaches dark web content. Nothing at all reaches grey web content, because there is nothing left at the address. The only thing that survives is a copy someone took while it was visible, which is what makes grey web data a fundamentally different asset from the other two.

It is also the fastest-moving of the three. On a sample of Reddit comments we recaptured seven days after collecting them, roughly one in twenty had already left public view, most removed by moderation rather than by their author. That is a first measurement on a small sample, and we are still consolidating it, but a weekly attrition rate in that range means the grey web grows continuously and silently.

07

Which one your investigation actually needs

Sort by the failure you can least afford. If you need what an organisation holds internally, that is a legal process question, not a collection question. If you need leak site postings and market listings, you need dark web monitoring, and there are competent vendors for it.

If you need to know what a person or a community said before they cleaned up, no amount of dark web tooling helps, and neither does a live platform search: the query you run today returns what survives today and stays silent about the rest. That is the specific gap grey web intelligence fills, by collecting at publication time so that a deletion becomes a dated event rather than an absence.

The practical difference is easiest to see rather than argue about. Try user lookup on an account that has scrubbed itself, or deleted post search on a thread that no longer renders on Reddit. No account needed.

Need the full archive via API?

The free tools query a slice of the archive. The API gives you all 30 billion posts and comments back to 2005, deleted content included, in under 300ms.

FAQ

Grey, dark and deep, answered.

The dark web is unreachable because of routing: it requires Tor or an equivalent anonymity network, and it was never meant to be indexed. The grey web is unreachable because of time: it was ordinary public content, indexed and readable by anyone, until it was deleted, removed, made private or cut off when an API closed. A Tor browser reaches dark web content. Nothing reaches grey web content except a copy taken before it disappeared.

No. Deep web content is blocked by permission: a login, a paywall, a query form. It belongs to somebody and credentials retrieve it. Grey web content never required a credential. It was open to everyone, and then it stopped being retrievable at source.

It is not a place, so it is not dangerous in the way the question implies. It is a condition that public content falls into when it is deleted or cut off. Some of it is criminal chatter that was posted openly and then removed, which is exactly why investigators want it. Most of it is ordinary people deleting ordinary posts.

The deep web is everything a search engine cannot index because access needs a credential: online banking, an intranet, a database behind a query form. It is most of the web by volume and almost all of it is mundane. The dark web is the much smaller set of services reachable only through an anonymity network such as Tor. Popular coverage uses the two words interchangeably; they are not close. Logging into webmail puts you on the deep web.

The surface web is the part nothing blocks: indexed, reachable in an ordinary browser, no credential required. The grey web is what the surface web leaves behind. Every page in it was on the surface web and was indexed at the time, until it was deleted, removed, made private or cut off. The grey web is not a deeper layer, it is a former state of the same layer.

Because the early stages of most activity happen in the open before they move anywhere private. Recruitment, tooling discussion, bragging and attribution-relevant detail get posted in public communities and then deleted once they draw attention. A live platform search run afterwards returns nothing and gives no signal that anything was there.

There is no credible total, because you cannot count what is already gone. It can only be measured as a rate: how much of a known sample disappears over a given window. On Reddit comments recaptured seven days after collection, we observed roughly one in twenty already out of public view. That is a first measurement on a small sample and it is still being consolidated.

No. Dark web monitoring crawls onion services, leak sites and closed markets as they exist now. It has no mechanism for content that was public and has since been deleted, because that content has no live address to crawl. Covering the grey web requires having collected the material before it went.

Keep reading

What the grey web is

The definition, how content turns grey, and what grey web intelligence recovers.

Grey web intelligence

Where dark web monitoring ends and grey web collection has to begin.

Best Reddit OSINT tools

Tested, with what each one can and cannot see once content is removed.

THINKPOL is an independent intelligence platform and is not affiliated with, endorsed by, or sponsored by Reddit Inc. or any third-party tool named on this page. "Reddit" is a registered trademark of Reddit Inc. Third-party tool descriptions reflect publicly observable functionality as of July 2026 and may change; corrections are welcome via our contact page.

Stop reading about
it in the news.

Request access to THINKPOL. We respond within one working day. A 30-minute scoping call follows, and a sandbox tenant is provisioned within five working days of contract signature.

Contractual agreement requiredSandbox in 5 working days
© 2026 THINKPOL SAS
Backed byFrance 2030APOK InvestLa French Tech