# Security Considerations Regarding Trust in Iroh's Relay Servers

> Explore security considerations for Iroh's relay servers, leveraging end-to-end encryption and mutual TLS for secure communication even with untrusted infrastructure.

- Repository: [number zero/iroh](https://github.com/n0-computer/iroh)
- Tags: deep-dive
- Published: 2026-07-09

---

**Iroh treats relay servers as untrusted infrastructure, relying on end-to-end encryption via QUIC, mutual TLS authentication, and automatic health-checking to guarantee security regardless of relay compromise.**

The n0-computer/iroh networking library assumes its public relay infrastructure operates as potentially malicious forwarders, making **security considerations regarding trust in iroh's relay servers** a foundational aspect of its cryptographic design. By implementing comprehensive end-to-end encryption and verification mechanisms in the core transport layer, iroh ensures that compromised relays cannot decrypt traffic, impersonate endpoints, or access persistent user data.

## End-to-End Encryption and Mutual Authentication

All payload data transmitted through iroh's relay system is wrapped in a **QUIC-based encrypted stream** (`noq`) that is keyed by the endpoints' public keys. In [`iroh/src/socket/transports/relay.rs`](https://github.com/n0-computer/iroh/blob/main/iroh/src/socket/transports/relay.rs), the `RelaySender::poll_send` method forwards already-encrypted `Datagrams` to the relay without terminating the encryption layer, ensuring the relay never accesses plaintext content.

```rust
// Sending a datagram through a relay – the data is already encrypted.
let mut sender = endpoint.create_sender();          // creates a RelaySender
let dest_url = RelayUrl::parse("https://relay.iroh.link")?;
let dest_id = EndpointId::from_bytes(&peer_pub_key)?;
sender.poll_send(cx, dest_url, dest_id, &tx)?;

```

QUIC provides **mutual authentication via TLS 1.3**, where each endpoint presents its public key to establish cryptographically verified identities. The relay acts solely as a forwarder and does not terminate the TLS session, preventing the relay from impersonating either endpoint in a man-in-the-middle attack.

## Integrity Protection and Replay Detection

QUIC's built-in **AEAD packet integrity checks** guarantee that any tampering by a relay is detected by the receiver, causing the packet to be discarded. This cryptographic verification prevents corrupt or altered traffic from being silently accepted, even if a compromised relay attempts to modify data in transit.

## Relay Health Monitoring and Automatic Fallback

Iroh implements proactive **health-checking mechanisms** to detect and mitigate misbehaving relays. The `RelayNetworkChangeSender` triggers immediate health checks after network changes through the `check_connection_after_network_change` method, while the relay actor drops connections that become unresponsive.

```rust
// Reacting to a network change – the relay actor performs a health check.
let network_change_sender = transport.create_network_change_sender();
network_change_sender.check_connection_after_network_change(); // triggers a health check

```

The **HomeRelayWatch** system monitors relay status via `my_relay_status()` and `local_addr_watch()`, automatically switching to healthier relays when the current one fails. This ensures trust is never concentrated in a single relay instance.

```rust
// Watching the home‑relay – automatically switches to a healthier relay.
let watch = transport.my_relay_status();
watch.map(|status| {
    if let Some(relay) = status {
        // `relay.url()` is a signed URL; we can safely use it.
        println!("Current relay: {}", relay.url());
    }
});

```

## Signed DNS Resolution and Relay Verification

Endpoint IDs resolve through the **iroh-dns-server**, which serves **signed PKARR records** (`dns.iroh.link`). These signatures cryptographically bind an `EndpointId` to a domain name, preventing DNS spoofing attacks and allowing clients to verify that a relay URL truly belongs to the advertised endpoint.

## Stateless Design and Decentralized Infrastructure

The **public relay ecosystem** runs the open-source `iroh-relay` binary, encouraging decentralization and reducing reliance on single operators. Relays maintain only **transient forwarding state** and never store user data long-term, ensuring that even physical compromise yields no "data at rest" for attackers to harvest. According to the implementation in [`iroh-relay/src/relay_map.rs`](https://github.com/n0-computer/iroh/blob/main/iroh-relay/src/relay_map.rs), the relay mapping logic handles connection state without persisting sensitive payload information.

## Summary

- **End-to-end encryption** via QUIC ensures relays never access plaintext data, as implemented in [`iroh/src/socket/transports/relay.rs`](https://github.com/n0-computer/iroh/blob/main/iroh/src/socket/transports/relay.rs).
- **Mutual TLS authentication** prevents relay impersonation and man-in-the-middle attacks.
- **Automatic health-checking** and fallback mechanisms (`check_connection_after_network_change`, `HomeRelayWatch`) isolate misbehaving relays quickly.
- **Signed PKARR DNS records** prevent spoofed relay addresses and verify endpoint identity.
- **Stateless operation** ensures relays store no persistent user data, minimizing impact of compromise.

## Frequently Asked Questions

### Can a compromised iroh relay server read my encrypted traffic?

No. Iroh uses end-to-end encryption via QUIC (`noq`) where traffic is encrypted with the endpoints' public keys before reaching the relay. The `RelaySender::poll_send` method in [`iroh/src/socket/transports/relay.rs`](https://github.com/n0-computer/iroh/blob/main/iroh/src/socket/transports/relay.rs) forwards already-encrypted datagrams, ensuring the relay only handles ciphertext and cannot decrypt communication content.

### How does iroh prevent relay servers from impersonating my device?

Iroh implements mutual authentication via TLS 1.3, where each endpoint cryptographically proves its identity using public keys. Since the relay does not possess your private key and does not terminate the TLS session, it cannot impersonate your endpoint to other peers or intercept authenticated communications.

### What happens if the iroh relay I'm using becomes malicious or unresponsive?

The `RelayNetworkChangeSender` triggers health checks through `check_connection_after_network_change`, and the `HomeRelayWatch` system automatically switches to alternative relays. This fallback mechanism ensures continuous operation without trusting any single relay permanently, limiting denial-of-service exposure.

### How does iroh verify that a relay URL actually belongs to my intended peer?

Iroh resolves endpoint IDs through signed PKARR records served by `iroh-dns-server`. These cryptographic signatures bind `EndpointId` values to specific domain names, allowing clients to verify relay URLs and prevent DNS-based spoofing attacks before establishing connections.