Encrypt Email with PGP/GPG: A Beginner Guide to Sending Mail No One Can Read

Every email you send travels through several servers before reaching its destination. Without content encryption, anyone who intercepts it along the way can read it as easily as an open postcard. This guide walks you through using PGP/GPG to encrypt your email from the ground up, so only the intended recipient can ever read the content — even if the message is intercepted or leaked in transit.

What Is PGP/GPG?

PGP (Pretty Good Privacy) is an encryption standard created by Phil Zimmermann back in 1991 to protect email content from being read by unauthorized parties. GPG (GNU Privacy Guard) is the free, open-source software that implements the OpenPGP standard (RFC 4880), and it runs on Windows, macOS, and Linux. Today people typically use "PGP" and "GPG" interchangeably since they follow the same principles and their key files are compatible.

The core mechanism is asymmetric encryption, which uses a matched pair of keys: a public key that you share so others can encrypt messages addressed to you, and a private key that only you keep to decrypt them. Even if someone intercepts your email in transit, they can't read the content without the matching private key.

How Public and Private Keys Work Together

When Alice wants to send Bob a confidential message, the process works like this: Alice encrypts the message using Bob's public key, then sends the encrypted email as usual. Only Bob, who holds the matching private key, can decrypt and read it on arrival. Even the email provider or anyone intercepting the traffic sees only meaningless ciphertext.

Beyond encryption, PGP/GPG can also produce digital signatures. Alice signs a message with her own private key, and Bob verifies it using Alice's public key to confirm the email genuinely came from her and wasn't altered in transit. This is an effective defense against phishing attempts that spoof the sender's identity.

Why Encrypt Your Email at All

Tools You Need Before Getting Started

Before using PGP/GPG, install the right software for your platform:

This guide demonstrates using Thunderbird because it's easy to set up and works cross-platform. Use your own business domain email — such as one hosted with AsiaGB Email Hosting — rather than a free webmail address for better credibility.

How to Generate a Key Pair

To create a new key pair in Thunderbird:

  1. Open Thunderbird and go to Account Settings for the email account you want to encrypt.
  2. Select End-to-End Encryption, then click Add Key.
  3. Choose Create a new OpenPGP Key and set the key type to RSA 4096-bit (the longest length recommended for stronger security).
  4. Set an expiration date for the key (1-2 years is recommended, renewing periodically for long-term security).
  5. Choose a strong passphrase — this is the last line of defense if your private key ever falls into the wrong hands.
  6. Click Generate Key and wait a moment while the key pair is created.

After generating your keys, export your public key as an .asc file to share with contacts, or upload it to a public keyserver such as keys.openpgp.org so others can easily look it up.

How to Send Encrypted Email in Thunderbird

Once you have your own key pair and the recipient's public key (imported via the Add Key menu from an .asc file, or found on a keyserver), sending encrypted mail is straightforward: open a new compose window, click the padlock icon in the bottom toolbar, select Encrypt and Digitally Sign, then write and send your email normally. The software automatically encrypts the body and any attachments before sending.

On the recipient's side, Thunderbird automatically decrypts the message using their private key and shows a "Signed and Encrypted" status, confirming both the sender's identity and the integrity of the content.

Web of Trust and Signature Verification

One challenge with PGP is confirming that a public key genuinely belongs to the person it claims to represent, rather than a fake key created by an attacker impersonating them. The Web of Trust concept addresses this by letting users sign each other's public keys after verifying identity offline — for example, comparing key fingerprints in person. The more people you trust sign a given key, the more confidence you can place in it.

For most businesses, a simpler approach is to compare the key fingerprint (a 40-character string) through a separate channel — a phone call or messaging app — to confirm that the public key you received truly matches what your contact intended to share.

Limitations to Keep in Mind

PGP vs. S/MIME

S/MIME is another email encryption standard that uses SSL certificates issued by a Certificate Authority instead of self-generated keys. The key difference is that S/MIME is natively supported by Outlook and Apple Mail without additional software, making it a good fit for organizations with centralized IT issuing certificates to employees. PGP/GPG, on the other hand, is more open — it doesn't depend on a Certificate Authority, and anyone can generate keys for free — making it popular among developers, journalists, and organizations that want full control over their own encryption keys.

Tip: PGP/GPG encryption delivers the most value when paired with your own business domain email, since you have full control over server security and can layer on SPF/DKIM/DMARC to further prevent sender spoofing. AsiaGB Email Hosting supports full configuration of all of these through DirectAdmin.

What's the difference between PGP and GPG?

PGP was the original standard, originally a commercial product. GPG (GNU Privacy Guard) is the free, open-source software that implements the same OpenPGP standard. Today the two are interchangeable, and their key files are cross-compatible.

What software do I need to use PGP?

Install Thunderbird (which has OpenPGP built in), or Gpg4win on Windows and GPG Suite on macOS. Once you generate a public/private key pair, you can start using PGP immediately at no cost.

Can I recover a private key if I forget the passphrase?

No, the passphrase is the only thing that unlocks your private key, and only you know it. If you forget it and have no separate backup, you'll need to generate a brand new key pair and notify all your contacts to switch to your new public key.

Can a recipient without PGP open an encrypted email?

No. An email encrypted with PGP appears as an unreadable .asc attachment or ciphertext. The recipient needs OpenPGP-capable software and the matching private key to decrypt and read it.

Does PGP encrypt the email subject line too?

No. The subject line, sender, and recipient remain visible even though the message body is encrypted. Avoid putting sensitive information in the subject field.

Do I need to use PGP for every email I send?

Not necessarily. It's most valuable for messages containing sensitive information — contracts, passwords, financial data, or customer records. Routine emails without sensitive content can still be sent normally.

Set Up a Business Email on Your Own Domain Today

AsiaGB Email Hosting comes with SPF/DKIM/DMARC and an easy-to-manage DirectAdmin panel, fully compatible with PGP encryption via Thunderbird.

View Email Hosting Plans