you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 1 min ago 255 onions tracked
home / tools / pgp encrypt

pgp encrypt

scramble a message so that only one person can read it: the one whose public key you paste below. you need their public key (starts with -----BEGIN PGP PUBLIC KEY BLOCK-----) and your text. that's all.

1

paste the recipient's public key

this decides who can read the message - and who can't. get the block straight from the recipient (their website, a keyserver they point you to, or handed over in person), never from an unverified email. before sending anything sensitive, compare the key's fingerprint - the short checksum that identifies it - with its owner over a channel you already trust. encrypting to a look-alike key means an impostor holds the private half and reads everything you send. two keys look similar? check them in the fingerprint comparator.

a block starting with BEGIN PGP PRIVATE KEY BLOCK will technically work too, but that's almost always a mix-up - encrypt to the recipient's public key.

2

write your message

3

encrypt it

where should this run?

privacy note

with javascript enabled, encryption happens entirely in your browser - your message and keys never leave your device. with javascript blocked, the same button submits this form and the encryption runs on our server instead: your input is processed in memory for that one request, then discarded - nothing is logged or stored - but the plaintext does cross the network to reach us. if that ever bothers you, enable javascript.

faq

is my message or my key uploaded?
not when javascript is on: everything runs inside your browser tab - open dev tools and watch the network panel stay quiet when you click encrypt. when javascript is blocked, the browser-mode can't work, so the form posts to the server and we encrypt there, in memory, keeping nothing. that server fallback only supports rsa keys.
how do i know i'm encrypting to the right key?
ask the recipient to read out their key's fingerprint over a channel you already trust (a voice call, or in person) and match it against the key you pasted - the fingerprint comparator does the diffing for you. a matching fingerprint proves the key is really theirs; skipping this check is exactly how impostor attacks happen.
what does "also sign" do?
it attaches your signature inside the encrypted package so the recipient can prove the message came from your key, not just from whoever knows their address. needs your private key + passphrase to do that.
i don't have a public key to encrypt to
then ask the recipient to send theirs, or use the key generator if you actually want to make your own pair first.
how long should my message be?
any length works. pgp encrypts text of any size into a similar-sized armored block.