🗝️ How to sign files or emails with a GPG key
📆 2026-10-06 08:05
Sign files with a GPG key
A GPG signature proves that a file or message was signed by your private key and has not been modified. Signing does not hide the contents. To create a detached signature for a file:
To verify the signature:
To create a readable signed message:
To verify a clearsigned message:
Encrypt files with a GPG key
Encryption is different: it hides the contents so only the intended recipient can read them. Encrypt a file using the recipient's public key:
To decrypt an encrypted file:
Sign and encrypt together
You can also sign and encrypt a file at the same time:
This creates filename.gpg. The recipient can decrypt it with:
GPG will use the recipient's private encryption key to decrypt the file and your public key to verify the signature. Signing proves authenticity and integrity; encryption provides confidentiality. If you want both you and the recipient to be able to decrypt the file, specify both public keys with --recipient:
Sign emails
GPG can also sign emails. Most email clients with OpenPGP support can use your GPG key automatically. Once your key is configured, choose the Sign option when composing an email. The recipient can then use your public key to verify the signature. There are quite a few email clients that support OpenPGP/PGP:
- Thunderbird - native OpenPGP support since version 78; works on Linux, Windows and macOS.
- KMail - KDE mail client with OpenPGP support.
- Claws Mail - OpenPGP support through its GPG integration.
- Evolution - OpenPGP support on Linux.
- Mutt/Neomutt
- Aerc
You can also learn
🪙 Donate
If this tutorial saved you time, sanity, or a mild existential crisis... consider fueling future chaos with a small donation: