everyday
pgp encrypt
scramble a message so that only one person can read it: the one whose public key you paste below. you need their public key (starts with -----BEGIN PGP PUBLIC KEY BLOCK-----) and your text. that's all.
privacy note
with javascript enabled, encryption happens entirely in your browser - your message and keys never leave your device. with javascript blocked, the same button submits this form and the encryption runs on our server instead: your input is processed in memory for that one request, then discarded - nothing is logged or stored - but the plaintext does cross the network to reach us. if that ever bothers you, enable javascript.
faq
- is my message or my key uploaded?
- not when javascript is on: everything runs inside your browser tab - open dev tools and watch the network panel stay quiet when you click encrypt. when javascript is blocked, the browser-mode can't work, so the form posts to the server and we encrypt there, in memory, keeping nothing. that server fallback only supports rsa keys.
- how do i know i'm encrypting to the right key?
- ask the recipient to read out their key's fingerprint over a channel you already trust (a voice call, or in person) and match it against the key you pasted - the fingerprint comparator does the diffing for you. a matching fingerprint proves the key is really theirs; skipping this check is exactly how impostor attacks happen.
- what does "also sign" do?
- it attaches your signature inside the encrypted package so the recipient can prove the message came from your key, not just from whoever knows their address. needs your private key + passphrase to do that.
- i don't have a public key to encrypt to
- then ask the recipient to send theirs, or use the key generator if you actually want to make your own pair first.
- how long should my message be?
- any length works. pgp encrypts text of any size into a similar-sized armored block.