Biscuit Wallet

Guide · · 6 min read

How to send an encrypted email with Kleopatra

OpenPGP step by step, with our key as the example

You can now write to the Biscuit team by encrypted email. Our OpenPGP key is published, and only the holder of the matching private key can read messages encrypted to it. This is useful if you are reporting a security issue, writing about something sensitive, or simply prefer not to send plain text.

Ink drawing of a sealed envelope closed with a padlock

This guide shows how to send an encrypted email to anyone with Kleopatra, and how to read their encrypted reply. We use our own key as the example throughout; the steps are the same for any recipient.

How does it work?

OpenPGP gives everyone a pair of keys. Think of it as an open padlock and the only key that opens it.

To write to someone, you need their public key. For them to reply, they need yours. Each key has a fingerprint, a 40-character code that identifies it, so you can tell a genuine key from a fake.

Kleopatra calls keys “certificates” and the private key the “secret key”. This guide uses both words.

What does encryption protect, and what doesn’t it?

OpenPGP encrypts the body of your message. It also protects any files you encrypt before attaching them. A file you attach directly in your mail client is not encrypted.

Some things stay visible to every mail server the message passes through:

Use a neutral subject such as “Message” or “Report”, and put every detail in the encrypted body.

Encryption does not make you anonymous. The recipient sees your address, and your mail provider knows you sent a message, and to whom.

Install Kleopatra

Create your own key pair

You need a key pair of your own to read encrypted replies and to sign your messages.

  1. In Kleopatra, choose File → New OpenPGP Key Pair. The wording varies slightly between versions.
  2. Enter your name and the email address you will write from.
  3. Protect the key with a strong passphrase. It guards your secret key if someone gets hold of your computer.
  4. Back up your secret key. Right-click your certificate, choose Backup Secret Keys, and store the file somewhere safe and offline. If you lose this key, you can no longer read replies encrypted to it.

Get the recipient’s public key

People usually publish their public key on their website, send it to you directly, or upload it to a key server. Ours is available both ways:

Importing a key does not mean you should trust it yet.

Verify the key

Anyone can create a key with any name and any email address. If you encrypt to a fake key, the person who made it can read your message, and the real recipient cannot. Verification is the step that prevents this, and the one people most often skip.

The general method works for every key: compare the fingerprint with a second, independent source.

  1. Double-click the certificate in Kleopatra to see its fingerprint.
  2. Compare it with the fingerprint the owner published somewhere else: their website, a business card, a phone call, or in person.
  3. Check all 40 characters, not just the first few.

Using our key as the example, the fingerprint is:

B16D 2CF2 C40A 15FD 34B1  F7CF 22FF 741B A0E5 9CEC

It is published on our Contact page, and the key is linked from the Encryption: line of our security.txt. The key itself is also on keys.openpgp.org. Our site and the key server are two independent sources, so check one against the other:

To slip you a fake key, someone would have to tamper with both.

For Biscuit, there is one more check. Our contact key is certified by the key that signs every Biscuit release:

Key servers such as keys.openpgp.org don’t pass on certifications made by other keys, so this check needs the copy from our website:

  1. Import biscuit-contact-key.asc from our site.
  2. Import the release key, as described in Verify your download.
  3. Open the details of our contact certificate. Among its certifications, you should see one made by “Biscuit Wallet releases”.

This ties the contact key to the key that signs our software. If you checked that key when you installed Biscuit, you already trust it.

Once the fingerprint matches, you can record it in Kleopatra: select the certificate and use Certify with your own key. Otherwise Kleopatra may keep warning you that the key is not certified.

Write and encrypt your message

  1. Click Notepad in Kleopatra and write your message.
  2. Open the Recipients tab and add the recipient’s certificate, for example ours.
  3. Make sure your own certificate is included too; in many versions this is an Encrypt for me option. Otherwise you won’t be able to read your own sent message later.
  4. If you like, sign the message with your key, so the recipient can confirm it came from you.
  5. Click Sign/Encrypt. The Notepad now shows a block of text that starts with -----BEGIN PGP MESSAGE-----.
  6. Copy the whole block, including the BEGIN and END lines.
  7. In your usual mail client, write to the recipient (for us, biscuitwallet@tutamail.com). Use a neutral subject and paste the block as the body. Send it as plain text if your client allows: HTML formatting can damage the block.

To receive an encrypted reply, attach your public key.

  1. Right-click your certificate and choose Export. This saves an .asc file containing only your public key.
  2. Attach that file to your email.

Never attach the secret key backup you made earlier. That one stays with you.

Read the reply

  1. Copy the entire -----BEGIN PGP MESSAGE----- block from the reply.
  2. In Kleopatra, use the clipboard’s Decrypt/Verify action (in most versions under Tools → Clipboard), or paste the block into the Notepad and click Decrypt/Verify.
  3. Enter your passphrase.

Kleopatra shows the text. If the message was signed, it also tells you whether the signature is valid.

Prefer the command line? The same steps with GnuPG:

gpg --import biscuit-contact-key.asc
gpg --fingerprint biscuitwallet@tutamail.com
gpg --encrypt --armor --sign -r biscuitwallet@tutamail.com -r you@example.org message.txt

The last command writes message.txt.asc, ready to paste into an email.

What are the limits?

One thing we will never ask

Encryption protects a message in transit. It does not make a request legitimate. Never send a seed phrase, a password or a private key to anyone, encrypted or not. We will never ask for them. If someone claiming to be us does, it is not us.

Learn more

Questions about this guide? Write to us, encrypted or not, through the contact page.

Share: Mastodon · X · Facebook · Reddit · Email

← The whole journal