Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

PGP secures a message or file by encrypting its contents with a one-time symmetric key, then encrypting that key with the recipient’s public key. The recipient’s matching private key unlocks the content. PGP can also add a digital signature, which helps detect changes and verifies that the signer controlled a particular private key—but it does not, by itself, prove who that person is.

Today, “PGP” is often used informally for OpenPGP, the interoperable standard for encrypted and signed data. GnuPG, commonly run with the gpg command, is one implementation. OpenPGP remains a current standard: RFC 9580 was published in July 2024, but not every application supports every feature in that specification.

What PGP protects—and what it does not

PGP can protect the contents of files and messages from people who do not have the necessary decryption key. When used with a digital signature, it can also reveal whether signed content changed and whether the signing key matches the key used to verify it. These protections can apply to stored files as well as data sent between people.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is not the same as making a device, email account, or conversation completely secure. PGP does not automatically hide sender and recipient addresses, message timing, size, routing information, or—in many email workflows—the subject line. It cannot protect plaintext from malware that reads it before encryption or after decryption, or stop a recipient from copying or forwarding it. Its practical security depends on sound software, secure devices, protected private keys, and confidence that the public key belongs to the intended person.

#1 Best Overall

PGP, OpenPGP, and GnuPG: what is the difference?

Term What it means
PGP Originally, Pretty Good Privacy, software created by Phil Zimmermann. The name is also used informally for OpenPGP-style encryption.
OpenPGP An open, interoperable format and standard family for encrypting and signing messages and data. RFC 9580 is the current IETF specification.
GnuPG (GPG) A free implementation of OpenPGP. gpg is its commonly used command-line program.
Public key A shareable key used to encrypt data for its owner or verify that owner’s signatures.
Private key A secret key used to decrypt data or create signatures. It must be protected.
Key pair The mathematically related public and private keys.
Fingerprint A compact identifier for a public key, used to check that a key is the one you intended to use.
Session key A randomly generated symmetric key used to encrypt one message or file.
Keyring A local collection of keys and associated information managed by OpenPGP software.

OpenPGP also supports signatures, certificates, compression, key transfer, and key-management features. Implementations can differ in supported versions, algorithms, and workflows, so the label “PGP-compatible” does not guarantee every feature will interoperate.

Why PGP uses two kinds of encryption

Symmetric encryption uses the same secret key to encrypt and decrypt data. It is efficient for large files, but the sender and recipient need a secure way to share the key. Public-key encryption avoids that initial secret-sharing problem: a sender can use a recipient’s public key, while only the corresponding private key can recover what it protects. Public-key operations are not the efficient choice for encrypting a large file directly.

PGP combines the two approaches. This is called hybrid encryption:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. The sender’s software generates a random session key.
  2. It encrypts the file or message with that session key.
  3. It encrypts the session key with the recipient’s public key.
  4. It sends the encrypted content along with the encrypted session key.
  5. The recipient uses their private key to recover the session key, then uses that key to decrypt the content.

In simplified form:

Plaintext or file
   │
   ├── encrypted with a random session key ──► encrypted content
   │
   └── session key encrypted with recipient's public key
                                               │
                                               ▼
                     encrypted session key + encrypted content

This design lets fast symmetric encryption handle the payload while public-key cryptography solves the problem of delivering the session key. The construction is described in RFC 9580; the GNU Privacy Handbook also explains the hybrid approach.

What happens when you encrypt a file

Before encrypting, the sender needs the recipient’s public key and should authenticate it: importing a key is not proof that it belongs to the named person. Once the key is selected, OpenPGP software creates the session key, encrypts the content, and encrypts the session key for the recipient. Depending on the workflow, the content may also be compressed or signed.

To open the result, the recipient’s software finds the matching private key, uses it to decrypt the session key, and then decrypts the content. If the recipient has lost that private key, another public key cannot be used to recover the file. A sender may choose to encrypt a copy of the session key for an additional recovery key or for themselves, but that means another key holder can also decrypt the data.

A file sent to several people does not normally need to be encrypted separately for each one. OpenPGP can encrypt the same session key separately to each recipient’s public key, then send those encrypted key packets with the one encrypted payload. Removing a person from future exchanges does not take back files they already received.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How PGP digital signatures work

Encryption and signing address different questions. Encryption asks, “Who can read this?” A signature asks, “Has the signed content changed, and does the signature verify with this public key?” They can be used independently or together.

  1. The sender’s software calculates a cryptographic hash of the content.
  2. The sender’s private signing key creates a signature associated with that hash.
  3. The recipient’s software calculates a hash of the received content and verifies the signature with the signer’s public key.
  4. If verification succeeds, the signed content matches what was signed and the signature corresponds to that key.

A valid signature is evidence that the signer controlled the relevant private key; it is not proof that the key belongs to the real-world person named in its user ID. Identity still needs to be established. “Non-repudiation” should also be understood cautiously: mathematical verification alone does not establish who had access to a key, how it was protected, or the legal significance of a signature.

Fingerprints and the problem of trusting a key

A public key can be copied or substituted. An attacker who persuades you to use their key in place of your contact’s could receive messages encrypted for that contact, even if the key displays a familiar name or email address. Encryption may work perfectly while sending the data to the wrong person.

Compare the key’s full fingerprint with the intended recipient using an independent, trusted route: for example, in person, by calling a previously verified number, through a separate secure messaging channel, or through an authenticated organizational directory. A key received by email or downloaded automatically is not authenticated just because its name looks right.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenPGP supports different ways of representing and building trust, including certifications and webs of trust. Some software and organizations also use directory-based discovery or mechanisms such as Web Key Directory. These methods can make finding keys easier, but they are not all the same as independently confirming a person’s identity. A key can be cryptographically valid while its claimed identity remains unverified.

Using GnuPG to encrypt, decrypt, sign, and verify a file

The following examples use GnuPG on a Unix-like command line. Prompts, defaults, and output filenames may vary by installed version and operating system. Install GnuPG from a trusted source and check the documentation for your version before using it in a production workflow. The official GnuPG site links to Gpg4win for Windows, which includes graphical tools and Outlook-related components.

Create a key pair

gpg --full-generate-key

Follow the prompts to choose the offered key type and settings, provide a name and email address if appropriate, and set a strong passphrase. Available algorithms and defaults differ between releases; do not assume a particular choice is right for every recipient or use case.

List keys and check a fingerprint

gpg --list-keys
gpg --fingerprint [email protected]

Check the fingerprint with the recipient over an independent trusted channel before relying on the key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Export and import public keys

gpg --armor --export [email protected] > public-key.asc
gpg --import recipient-public-key.asc

Export only the public key for sharing. Importing another person’s public key makes it available locally; it does not authenticate the identity attached to it. Verify its fingerprint.

Encrypt a file

gpg --encrypt --armor --recipient [email protected] document.pdf

This typically creates an ASCII-armored encrypted file alongside the original. ASCII armor encodes the encrypted data as text for easier transfer; it does not add security. To create a binary OpenPGP output instead, omit --armor:

gpg --encrypt --recipient [email protected] document.pdf

Decrypt a file

gpg --decrypt document.pdf.asc > document.pdf

The recipient needs the matching private key and, if it is protected, its passphrase. Be careful not to overwrite an important file when choosing an output path.

Sign and verify a file

gpg --armor --detach-sign document.pdf
gpg --verify document.pdf.asc document.pdf

A detached signature is distributed separately from the file. A successful verification indicates that the content matches the signature made by the corresponding signing key; authenticate that key’s fingerprint before treating the signer’s identity as established.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encrypt and sign together

gpg --encrypt --sign --armor 
  --recipient [email protected] 
  document.pdf

When you have multiple signing keys, select the intended one explicitly, for example with --local-user [email protected]. Test commands on non-sensitive files first. A successful test on the same computer does not establish that you can restore a backup, decrypt on another device, or help a recipient who has a different software profile.

PGP and email

Email clients commonly handle OpenPGP using PGP/MIME, which can protect structured message content and attachments, or inline PGP, which places armored text in the body. Inline formatting can be fragile with line wrapping, quoted replies, and attachments; PGP/MIME is generally better suited to full email messages when both clients support it.

Both sender and recipient need compatible software and the right keys. For an external recipient, the sender may need to obtain and verify the recipient’s public key, configure the client, and confirm that the recipient can decrypt and verify a test message. Ordinary email recipients cannot necessarily open an OpenPGP message without this setup.

Hosted services can automate some of the work. Proton says messages between Proton Mail users are automatically end-to-end encrypted and documents ways to use PGP with external addresses. It also provides information about key management and using PGP with Proton Mail. A managed workflow can be easier than operating a local keyring, but it changes the user’s relationship with the service and does not remove the need to consider recipient identity, account security, and device security.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Key management is part of the security design

  • Generate keys on a trusted device. Choose settings that work with the recipients’ software and your security requirements.
  • Protect the private key. Use a strong passphrase, keep software updated, and consider a hardware token or offline storage where appropriate.
  • Plan recovery. Make encrypted backups of private key material and recovery information, store them securely, and test that you can restore them. A public key cannot decrypt data.
  • Record and authenticate fingerprints. Know how recipients can verify your key and how you will verify theirs.
  • Set an expiration and replacement process. Expiration can signal that a key should no longer be used, but it does not erase copies or make old data unreadable.
  • Create a revocation certificate early. If a key is lost or compromised, a revocation certificate helps tell others to stop trusting it. It does not recall messages already sent.
  • Plan for people and organizational change. Decide what happens to keys when a device is lost or a staff member leaves, and who can decrypt archived files.

Experienced users may separate certification, signing, and encryption functions into subkeys, sometimes keeping the primary certification key offline. This can limit exposure but makes backup, rotation, and recovery more involved; follow the specific implementation’s guidance.

Common failures and what to do

The recipient cannot decrypt

Possible causes include encrypting to the wrong key, the recipient lacking the matching private key, using a different keyring or device, an expired or revoked key, an unsupported algorithm or packet format, or a missing passphrase. Confirm the recipient’s fingerprint and exact key, check that the matching private key is available, and test with a small non-sensitive file. Do not send confidential material in plaintext as a troubleshooting shortcut.

A signature is valid but marked untrusted or unknown

These statuses can refer to different things. A signature may be mathematically valid while the software has no reason to trust that the public key belongs to the claimed signer. Authenticate the fingerprint and review the key’s status, including whether it is expired or revoked.

The private key is lost or exposed

If the only private key capable of decrypting a file is lost, the data may be unrecoverable. If a private key may have been exposed, stop using it, revoke it, distribute the revocation status, and create and authenticate a replacement key. Re-encrypt data that still needs protection. Treat signatures made during the compromise window as potentially suspect, and investigate whether plaintext or passphrases were exposed too.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A file was encrypted to the wrong key

The sender generally cannot decrypt the result unless they were included as a recipient or another recovery key was used. For important organizational exchanges, an approved archival or recovery key can improve recoverability, but it also expands who or what can decrypt the content. Make that trade-off explicit rather than adding recovery access casually.

Limitations and compatibility to weigh

  • Metadata remains. Content encryption does not automatically conceal email routing details, addresses, timing, message size, or every subject line.
  • Endpoints matter. Malware can capture plaintext or passphrases, and a compromised device can expose keys. PGP cannot compensate for an unsafe endpoint.
  • Key handling is demanding. Discovery, fingerprint checks, backups, expiration, revocation, and recovery can be confusing for occasional users.
  • Compatibility varies. Applications may support different OpenPGP versions, algorithms, key types, and packet formats. Test with intended recipients before relying on a workflow.
  • Forward secrecy is not generally automatic. Traditional OpenPGP file and email workflows usually do not provide the same automatic forward-secrecy properties as modern messaging protocols. If a long-term private key is later stolen, previously captured encrypted material may be at risk, depending on the scheme and circumstances.
  • Open source is not a guarantee by itself. Inspectability can help, but security still depends on implementation quality, configuration, updates, key custody, and user decisions.

RFC 9580 is the current IETF OpenPGP specification, but applications do not all implement the same version or features. OpenPGP.org discusses differences involving GnuPG and the specification’s development at GnuPG and OpenPGP. For a real deployment, verify the exact versions, key formats, algorithms, and discovery methods used by every party; then test interoperability. Do not assume that choosing a newer feature or algorithm will work with every recipient.

Is PGP still useful?

Yes—when the need is interoperable encryption or verifiable signatures for files and email, and the people involved can manage keys. It is particularly useful where parties use different providers or need control over their own keys. Its main cost is operational: users must find the right keys, verify identities, safeguard private keys, and plan recovery.

For casual conversations, a modern end-to-end encrypted messaging app may be easier because it handles contact setup and key changes within a more integrated workflow. For managed enterprise email, S/MIME may fit an organization with certificate infrastructure. For simpler file-encryption needs, a purpose-built file-encryption tool or an encrypted file-sharing service may be easier for recipients. TLS protects connections in transit between systems; by itself, it is not end-to-end encryption between the sender and recipient.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hosted encrypted email can reduce hands-on key administration, but it introduces reliance on the provider’s implementation and account controls. Self-managed GnuPG offers more direct control and automation options, with greater responsibility for key operations. Choose according to the threat model, recipient capability, metadata needs, and recovery requirements—not on the assumption that any one tool makes every part of communication secure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.