Guide · · 6 min read
How to send an encrypted email with Kleopatra
OpenPGP step by step, with our key as the example
You can now write to the Biscuit team by encrypted email. Our OpenPGP key is published, and only the holder of the matching private key can read messages encrypted to it. This is useful if you are reporting a security issue, writing about something sensitive, or simply prefer not to send plain text.
This guide shows how to send an encrypted email to anyone with Kleopatra, and how to read their encrypted reply. We use our own key as the example throughout; the steps are the same for any recipient.
How does it work?
OpenPGP gives everyone a pair of keys. Think of it as an open padlock and the only key that opens it.
- Your public key is the padlock. You can hand out copies freely: anyone can snap one shut on a message, but only you can open it again.
- Your private key opens the padlock. It never leaves your computer.
To write to someone, you need their public key. For them to reply, they need yours. Each key has a fingerprint, a 40-character code that identifies it, so you can tell a genuine key from a fake.
Kleopatra calls keys “certificates” and the private key the “secret key”. This guide uses both words.
What does encryption protect, and what doesn’t it?
OpenPGP encrypts the body of your message. It also protects any files you encrypt before attaching them. A file you attach directly in your mail client is not encrypted.
Some things stay visible to every mail server the message passes through:
- the subject line;
- the sender and recipient addresses;
- the date and time.
Use a neutral subject such as “Message” or “Report”, and put every detail in the encrypted body.
Encryption does not make you anonymous. The recipient sees your address, and your mail provider knows you sent a message, and to whom.
Install Kleopatra
- Windows: install Gpg4win. Kleopatra is included.
- Linux: install it with your package manager, for example
sudo dnf install kleopatraon Fedora, orsudo apt install kleopatraon Debian and Ubuntu. - macOS: Kleopatra is not the usual tool there. GPG Suite is a common alternative. The principles below still apply, but the menus differ.
Create your own key pair
You need a key pair of your own to read encrypted replies and to sign your messages.
- In Kleopatra, choose File → New OpenPGP Key Pair. The wording varies slightly between versions.
- Enter your name and the email address you will write from.
- Protect the key with a strong passphrase. It guards your secret key if someone gets hold of your computer.
- Back up your secret key. Right-click your certificate, choose Backup Secret Keys, and store the file somewhere safe and offline. If you lose this key, you can no longer read replies encrypted to it.
Get the recipient’s public key
People usually publish their public key on their website, send it to you directly, or upload it to a key server. Ours is available both ways:
- Download
biscuit-contact-key.asc, then click Import in Kleopatra and select the file. - Or search for
biscuitwallet@tutamail.comon keys.openpgp.org and import the result. Lookup on Server in Kleopatra does the same, depending on which key server it is set to use.
Importing a key does not mean you should trust it yet.
Verify the key
Anyone can create a key with any name and any email address. If you encrypt to a fake key, the person who made it can read your message, and the real recipient cannot. Verification is the step that prevents this, and the one people most often skip.
The general method works for every key: compare the fingerprint with a second, independent source.
- Double-click the certificate in Kleopatra to see its fingerprint.
- Compare it with the fingerprint the owner published somewhere else: their website, a business card, a phone call, or in person.
- Check all 40 characters, not just the first few.
Using our key as the example, the fingerprint is:
B16D 2CF2 C40A 15FD 34B1 F7CF 22FF 741B A0E5 9CEC
It is published on our Contact page, and the key is linked from the Encryption: line of our security.txt. The key itself is also on keys.openpgp.org. Our site and the key server are two independent sources, so check one against the other:
- if you downloaded the key from our site, check that keys.openpgp.org returns the same fingerprint;
- if you got it from the key server, check it against the Contact page.
To slip you a fake key, someone would have to tamper with both.
For Biscuit, there is one more check. Our contact key is certified by the key that signs every Biscuit release:
- name: “Biscuit Wallet releases”;
- fingerprint:
D714 332E 6101 C1DA AC60 E644 202F 1FA3 98DE CEFA.
Key servers such as keys.openpgp.org don’t pass on certifications made by other keys, so this check needs the copy from our website:
- Import
biscuit-contact-key.ascfrom our site. - Import the release key, as described in Verify your download.
- Open the details of our contact certificate. Among its certifications, you should see one made by “Biscuit Wallet releases”.
This ties the contact key to the key that signs our software. If you checked that key when you installed Biscuit, you already trust it.
Once the fingerprint matches, you can record it in Kleopatra: select the certificate and use Certify with your own key. Otherwise Kleopatra may keep warning you that the key is not certified.
Write and encrypt your message
- Click Notepad in Kleopatra and write your message.
- Open the Recipients tab and add the recipient’s certificate, for example ours.
- Make sure your own certificate is included too; in many versions this is an Encrypt for me option. Otherwise you won’t be able to read your own sent message later.
- If you like, sign the message with your key, so the recipient can confirm it came from you.
- Click Sign/Encrypt. The Notepad now shows a block of text that starts with
-----BEGIN PGP MESSAGE-----. - Copy the whole block, including the BEGIN and END lines.
- In your usual mail client, write to the recipient (for us,
biscuitwallet@tutamail.com). Use a neutral subject and paste the block as the body. Send it as plain text if your client allows: HTML formatting can damage the block.
To receive an encrypted reply, attach your public key.
- Right-click your certificate and choose Export. This saves an
.ascfile containing only your public key. - Attach that file to your email.
Never attach the secret key backup you made earlier. That one stays with you.
Read the reply
- Copy the entire
-----BEGIN PGP MESSAGE-----block from the reply. - In Kleopatra, use the clipboard’s Decrypt/Verify action (in most versions under Tools → Clipboard), or paste the block into the Notepad and click Decrypt/Verify.
- Enter your passphrase.
Kleopatra shows the text. If the message was signed, it also tells you whether the signature is valid.
Prefer the command line? The same steps with GnuPG:
gpg --import biscuit-contact-key.asc
gpg --fingerprint biscuitwallet@tutamail.com
gpg --encrypt --armor --sign -r biscuitwallet@tutamail.com -r you@example.org message.txt
The last command writes message.txt.asc, ready to paste into an email.
What are the limits?
- The outside shows. Subject, addresses and date travel in the clear.
- Not anonymous. Encryption hides what you say, not that you wrote.
- Only as good as the key. A fingerprint you didn’t check protects nothing.
- Your secret key is the whole secret. Back it up, guard its passphrase, and never send it to anyone.
One thing we will never ask
Encryption protects a message in transit. It does not make a request legitimate. Never send a seed phrase, a password or a private key to anyone, encrypted or not. We will never ask for them. If someone claiming to be us does, it is not us.
Learn more
- Contact: our address and key fingerprint
- Verify your download: the release key, and how to check Biscuit’s signatures
- Gpg4win: Kleopatra for Windows, with its documentation
- keys.openpgp.org: the key server, searchable by email address
Questions about this guide? Write to us, encrypted or not, through the contact page.