pgp verify
got a message claiming to be from someone? check it against their public key. a valid signature means that key's owner really wrote it - and that nobody touched a single character on the way.
this tool auto-detects what you paste: clearsigned messages, detached signatures or encrypted blocks.
privacy: with javascript enabled, verification runs entirely in your browser - nothing you paste ever leaves your device. without javascript the form posts to the server instead, where your message and key live in memory for the length of that single check - never stored, never logged, discarded when the response is sent. the javascript path is strongly preferred; note the no-javascript path supports rsa signatures only, while the browser handles modern keys too.
faq
- what does a valid signature actually prove?
- two things: the message was signed by the private key belonging to the public key you checked against, and not one character changed afterwards. it does not prove anything about who controls that key unless you trust where you got the public key from.
- signature valid but the fingerprint looks different?
- then you are verifying against a different key than intended - possibly an impersonator. always compare fingerprints over a second channel before trusting any result.
- "encrypted message detected" - now what?
- what you pasted is an encrypted block, not a signature. run it through the decrypt tool first; if it contains a signature you can verify the plaintext here afterwards.
- i don't have their public key at all
- then verification is impossible - anyone could have written the message. find the key on the person's official page or profile first.
- the paste looks mangled and nothing parses?
- copy-paste often flattens armor onto one line. this tool auto-repairs the common damage, but for badly broken blocks run it through the armor cleaner first.