🗝️ How to sign files or emails with a GPG key

📆 2026-10-06 08:05

Sign files with a GPG key

A GPG signature proves that a file or message was signed by your private key and has not been modified. Signing does not hide the contents. To create a detached signature for a file:

To verify the signature:

To create a readable signed message:

To verify a clearsigned message:

Encrypt files with a GPG key

Encryption is different: it hides the contents so only the intended recipient can read them. Encrypt a file using the recipient's public key:

To decrypt an encrypted file:

Sign and encrypt together

You can also sign and encrypt a file at the same time:

This creates filename.gpg. The recipient can decrypt it with:

GPG will use the recipient's private encryption key to decrypt the file and your public key to verify the signature. Signing proves authenticity and integrity; encryption provides confidentiality. If you want both you and the recipient to be able to decrypt the file, specify both public keys with --recipient:

Sign emails

GPG can also sign emails. Most email clients with OpenPGP support can use your GPG key automatically. Once your key is configured, choose the Sign option when composing an email. The recipient can then use your public key to verify the signature. There are quite a few email clients that support OpenPGP/PGP:

You can also learn

📤 How to export GPG keys

📥 How to import GPG keys

If this tutorial saved you time, sanity, or a mild existential crisis... consider fueling future chaos with a small donation:

☕ Buy me a Ko-Fi

🔐 How to use GPG keys

🎓 Back to my tutorials

🚶 Back to my homepage