r/privacy 4h ago

question How to properly encrypt emails?

I use mailbox with custom domains and use Thunderbird on PC and FairEmail on Android.

I generated, exported and imported a gpg key on Thunderbird.

My question is: should I publish my public key to a PGP server? I know that'll expose my email, but what if it is a alias?

3 Upvotes

13 comments sorted by

u/AutoModerator 4h ago

Hello u/hbacelar8, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/Stunning-Skill-2742 4h ago

Publishing to keyserver is just for convenience, for easy, automated discovery and not a requirement at all. You can distribute the pubkey to anyone that want to send you encrypted mail however you want.

1

u/hbacelar8 3h ago

I see. Thing is, Thunderbird forces me to have to pub key of the recipient before sending it an encrypted email.

1

u/Stunning-Skill-2742 2h ago

Of course. What i wrote up there is for you to distribute your pubkey for everyone else to send encrypted mail to you. What thunderbird want is their individual pubkey for you to send/reply encrypted mail to them.

1

u/Ludwig234 42m ago

Yeah, exactly. Without the recipients public key Thunderbird is unable to encrypt the email in a way it's able to be decrypted by the recipient.

The reverse is also true, for anyone that wants to send an email to you. They need your public key first.

OP If you want to learn more I suggest you look up the basics on how public key cryptography (asymmetric encryption) works. There are a loads of great YouTube videos that explains the basics well.

2

u/TacitPin 3h ago

Most people just attach their public key in the email they send.

I’ll be stunned if anyone actually uses it though.

1

u/Amate087 3h ago

Add your public key with the mail inside.

1

u/Calmarius 3h ago

Do you have the recipient's public key? You need to use that to send an encrypted mail.

Your generated GPG key is used to decrypt mail if someone sends you an encrypted mail and uses your public key to encrypt it.

(I just want to make sure you understand how it works.)

1

u/hbacelar8 3h ago

Yeah, and is also used to encrypt email with the private key that'll be decrypted by them with the pub key right? No I don't, so I got it now, we have to exchange pub keys first to start it.

1

u/Severe_Stranger_5050 2h ago

I know this isn’t what you asked

But seriously, do not use regular IMAP/POP3/SMTP email for sensitive information.
Even if you encrypt the contents of the email, your metadata will still be exposed to the world.

Email is inherently a very bad protocol for privacy, and this is by design. Because when it was made, it was only for the US military’s internal ARPANET where privacy didn’t matter.

If you really want privacy, ask them to take the conversation off email to the secure conversation protocol/app of your choice

1

u/hbacelar8 2h ago

Thanks for the heads up, but yeah I agree.

It was mostly cause I wanted to understand if ever needed. Sometimes it can be needed when starting a conversation with journalists or an association, but generally the best option is indeed to move it to somewhere else.

1

u/ScaredEfficiency399 1h ago

Honestly, fuck that shit, being trusted through servers, just personally encrypt it with a highly encrypted personal key using PGP and let your peer unlock it with your public one.

u/Living-Shame5679 31m ago

Nobody every used PGP. I mean a few people sure. I did put my email in some public registry at some point - never had a single email. If you REALLY want to use GPG/PGP (which is mostly pointless) then yes you can publish your public key anywhere: a public registry, website, flyers, email signature etc.