PGP and Autocrypt
PGP encrypts mail end to end: only you and the other side can read it: not the mail server, not your provider, nobody in between. PGP can also sign mail, making it provable that it really came from you and was not altered on the way.
The price: both sides need PGP. You can only encrypt to people whose public key you have.
The principle in three sentences
Section titled “The principle in three sentences”Every participant has a key pair. The public key may be held by anyone, and it is used to encrypt mail to you. The private one stays with you, and only it can decrypt and sign.
Your own key pair
Section titled “Your own key pair”Under Settings → Security → PGP Encryption:
- Generate a new key: YouniqMail creates the pair for your address right on the device. The private key never leaves it.
- Or import an existing key, pasted as ASCII text (anyone who has worked with GnuPG, Thunderbird or ProtonMail simply brings their pair along).
Exporting works at any time, say for backup or the second machine. Treat the private key’s export file like a password.
Other people’s keys
Section titled “Other people’s keys”Four ways to get public keys:
Autocrypt, the convenient one: Mail programs with Autocrypt (Thunderbird, K-9 Mail, Delta Chat and others) place the public key into every email automatically. YouniqMail reads it out and remembers it. After the first email from an Autocrypt user you can reply encrypted without fetching their key separately. You still need a key pair of your own for that, since YouniqMail encrypts every mail for you as well.
Key servers: In the Keyserver section of the same settings page you search public directories for an address and import the match. That does not confirm the key yet, since anyone can upload a key under any address to a key server. Compare the fingerprint with its owner and click Trust key under Trusted public keys. Only then does YouniqMail encrypt to it.
By hand: Paste a key block someone sent you.
As an attachment: If someone sends you their key as a file (.asc,
.gpg, .pgp or .key), YouniqMail usually picks it up during the
sync already. Otherwise click Import key on the attachment. That
does not confirm the key yet: compare the fingerprint in the notice with
the sender, and only then click Trust. YouniqMail never takes
private keys from emails.
Encrypting and signing
Section titled “Encrypting and signing”In the compose window, the switches for Encrypt and Sign sit in the footer. If a key is on file for every recipient, the mail can be encrypted; if one is missing, YouniqMail tells you whose.
Sign follows Encrypt on its own: an encrypted mail is signed
too, any other is not. You can still sign only, for any mail:
tick Sign on its own, and Signed only appears next to the
switches. The mail goes out as PGP/MIME, the format Thunderbird and
other mail programs check. Recipients with PGP can see that it really
comes from you and was not changed on the way. Anyone without PGP
reads it as usual and sees the signature as an attachment named
OpenPGP_signature.asc. A mail that is only signed can still be read
on its way: the signature protects against changes, not against
prying eyes.
If a key is missing or was revoked, you find out when you click Send, not later in the outbox. If a key has expired, YouniqMail asks whether you want to send anyway.
Received mail
Section titled “Received mail”Encrypted mail opens as usual, and decryption happens automatically with your private key. If it is protected by a passphrase you have not saved, YouniqMail asks for it when you open the mail.
YouniqMail checks signatures on its own, in encrypted and in signed
only mail alike. That includes mail whose text stands between
BEGIN PGP SIGNED MESSAGE and the signature, as mailing lists often
send it; it is shown without that frame. Above the text you see what
the check found:
- PGP signature verified: the signature holds, and the key belongs to the sender and is marked as trusted on your side.
- PGP signature valid, key not confirmed: the signature holds, but you have not confirmed the key yet, for example because it came by Autocrypt or with the mail itself. Compare the fingerprint with the sender and mark the key as trusted: open the sender’s contact details from the mail and click Trust next to the key.
- PGP signature from someone else: the signature holds, but the key does not belong to the sender’s address, or you rejected it.
- PGP signature invalid: the mail was changed after signing, or the key had expired or was revoked when it signed.
- PGP signature not checked: the sender’s key is not on this device.
The mail list shows the same as a small badge, and the signature file itself does not appear as an attachment. When you import a key later or change whether you trust it, YouniqMail checks the mails signed with it again: an open mail right away, all others the next time you open them.
Signed-only messages in the BEGIN PGP MESSAGE format, as
gpg --sign --armor creates them, are checked too, and their text is
shown readable. An encrypted block that a mail only quotes or attaches
as a file does not take the mail’s place. The mail stays readable as
it was written.
Mail that arrives in bulk with the first sync of a folder is checked the first time you open it, fetching the original from the server once. If the server cannot be reached, it says PGP signature not checked yet, and the check runs again the next time you open it.
Limits, named honestly
Section titled “Limits, named honestly”PGP encrypts the content, not the metadata: subject, sender and recipients stay readable. And search can only look into encrypted content as far as it is available decrypted locally. For confidential communication, PGP remains the standard that has held up for decades.