you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 8 min ago 255 onions tracked
home / tools / pgp verify

pgp verify

got a message claiming to be from someone? check it against their public key. a valid signature means that key's owner really wrote it - and that nobody touched a single character on the way.

this tool auto-detects what you paste: clearsigned messages, detached signatures or encrypted blocks.

1

paste what they sent you

a detached signature covers exact bytes - make sure the original text is copied completely and unaltered.

2

paste their public key

get it from the sender's official source - their own site or a profile they control. never from the same channel the suspicious message came through: an attacker who fakes the message can attach a fake key to it just as easily.

a signature is only as trustworthy as the key you check it against. if the "public key" arrived in the same message or the same chat, verifying against it proves nothing.
3

check it

where should this run?

privacy: with javascript enabled, verification runs entirely in your browser - nothing you paste ever leaves your device. without javascript the form posts to the server instead, where your message and key live in memory for the length of that single check - never stored, never logged, discarded when the response is sent. the javascript path is strongly preferred; note the no-javascript path supports rsa signatures only, while the browser handles modern keys too.

faq

what does a valid signature actually prove?
two things: the message was signed by the private key belonging to the public key you checked against, and not one character changed afterwards. it does not prove anything about who controls that key unless you trust where you got the public key from.
signature valid but the fingerprint looks different?
then you are verifying against a different key than intended - possibly an impersonator. always compare fingerprints over a second channel before trusting any result.
"encrypted message detected" - now what?
what you pasted is an encrypted block, not a signature. run it through the decrypt tool first; if it contains a signature you can verify the plaintext here afterwards.
i don't have their public key at all
then verification is impossible - anyone could have written the message. find the key on the person's official page or profile first.
the paste looks mangled and nothing parses?
copy-paste often flattens armor onto one line. this tool auto-repairs the common damage, but for badly broken blocks run it through the armor cleaner first.