
Every email you send travels through several servers before reaching its destination. Without content encryption, anyone who intercepts it along the way can read it as easily as an open postcard. This guide walks you through using PGP/GPG to encrypt your email from the ground up, so only the intended recipient can ever read the content — even if the message is intercepted or leaked in transit.
What Is PGP/GPG?
PGP (Pretty Good Privacy) is an encryption standard created by Phil Zimmermann back in 1991 to protect email content from being read by unauthorized parties. GPG (GNU Privacy Guard) is the free, open-source software that implements the OpenPGP standard (RFC 4880), and it runs on Windows, macOS, and Linux. Today people typically use "PGP" and "GPG" interchangeably since they follow the same principles and their key files are compatible.
The core mechanism is asymmetric encryption, which uses a matched pair of keys: a public key that you share so others can encrypt messages addressed to you, and a private key that only you keep to decrypt them. Even if someone intercepts your email in transit, they can't read the content without the matching private key.
How Public and Private Keys Work Together
When Alice wants to send Bob a confidential message, the process works like this: Alice encrypts the message using Bob's public key, then sends the encrypted email as usual. Only Bob, who holds the matching private key, can decrypt and read it on arrival. Even the email provider or anyone intercepting the traffic sees only meaningless ciphertext.
Beyond encryption, PGP/GPG can also produce digital signatures. Alice signs a message with her own private key, and Bob verifies it using Alice's public key to confirm the email genuinely came from her and wasn't altered in transit. This is an effective defense against phishing attempts that spoof the sender's identity.
Why Encrypt Your Email at All
- Defend against interception — public Wi-Fi networks or compromised relay servers can expose unencrypted email content to eavesdroppers.
- Protect sensitive business data — contracts, passwords, customer data, or financial documents sent by email should always be encrypted.
- Verify sender identity — digital signatures give the recipient confidence the message wasn't spoofed or tampered with.
- Meet compliance requirements — businesses subject to data protection laws or security standards often must encrypt sensitive information sent via email.
Tools You Need Before Getting Started
Before using PGP/GPG, install the right software for your platform:
- Windows — install Gpg4win (gpg4win.org), which bundles Kleopatra for graphical key management.
- macOS — install GPG Suite (gpgtools.org), which integrates directly with Apple Mail.
- Linux — most distributions ship with GnuPG already installed; check with
gpg --version. - Thunderbird — the free mail client has built-in OpenPGP support since version 78, no plugin required, making it the easiest option for beginners.
This guide demonstrates using Thunderbird because it's easy to set up and works cross-platform. Use your own business domain email — such as one hosted with AsiaGB Email Hosting — rather than a free webmail address for better credibility.
How to Generate a Key Pair
To create a new key pair in Thunderbird:
- Open Thunderbird and go to Account Settings for the email account you want to encrypt.
- Select End-to-End Encryption, then click Add Key.
- Choose Create a new OpenPGP Key and set the key type to RSA 4096-bit (the longest length recommended for stronger security).
- Set an expiration date for the key (1-2 years is recommended, renewing periodically for long-term security).
- Choose a strong passphrase — this is the last line of defense if your private key ever falls into the wrong hands.
- Click Generate Key and wait a moment while the key pair is created.
After generating your keys, export your public key as an .asc file to share with contacts, or upload it to a public keyserver such as keys.openpgp.org so others can easily look it up.
How to Send Encrypted Email in Thunderbird
Once you have your own key pair and the recipient's public key (imported via the Add Key menu from an .asc file, or found on a keyserver), sending encrypted mail is straightforward: open a new compose window, click the padlock icon in the bottom toolbar, select Encrypt and Digitally Sign, then write and send your email normally. The software automatically encrypts the body and any attachments before sending.
On the recipient's side, Thunderbird automatically decrypts the message using their private key and shows a "Signed and Encrypted" status, confirming both the sender's identity and the integrity of the content.
Web of Trust and Signature Verification
One challenge with PGP is confirming that a public key genuinely belongs to the person it claims to represent, rather than a fake key created by an attacker impersonating them. The Web of Trust concept addresses this by letting users sign each other's public keys after verifying identity offline — for example, comparing key fingerprints in person. The more people you trust sign a given key, the more confidence you can place in it.
For most businesses, a simpler approach is to compare the key fingerprint (a 40-character string) through a separate channel — a phone call or messaging app — to confirm that the public key you received truly matches what your contact intended to share.
Limitations to Keep in Mind
- Subject lines are never encrypted — PGP only encrypts the body and attachments, so never put sensitive information in the subject line.
- Both parties need PGP — if the recipient has no public key or doesn't support PGP, the message either sends unencrypted or fails to send at all.
- A lost private key means lost access forever — back up your private key in multiple secure locations, since it can't be recovered if the passphrase is forgotten or the key file is lost.
- Metadata is still visible — your email provider can still see who emailed whom and when, even though the content itself is encrypted.
PGP vs. S/MIME
S/MIME is another email encryption standard that uses SSL certificates issued by a Certificate Authority instead of self-generated keys. The key difference is that S/MIME is natively supported by Outlook and Apple Mail without additional software, making it a good fit for organizations with centralized IT issuing certificates to employees. PGP/GPG, on the other hand, is more open — it doesn't depend on a Certificate Authority, and anyone can generate keys for free — making it popular among developers, journalists, and organizations that want full control over their own encryption keys.
Tip: PGP/GPG encryption delivers the most value when paired with your own business domain email, since you have full control over server security and can layer on SPF/DKIM/DMARC to further prevent sender spoofing. AsiaGB Email Hosting supports full configuration of all of these through DirectAdmin.
What's the difference between PGP and GPG?
PGP was the original standard, originally a commercial product. GPG (GNU Privacy Guard) is the free, open-source software that implements the same OpenPGP standard. Today the two are interchangeable, and their key files are cross-compatible.
What software do I need to use PGP?
Install Thunderbird (which has OpenPGP built in), or Gpg4win on Windows and GPG Suite on macOS. Once you generate a public/private key pair, you can start using PGP immediately at no cost.
Can I recover a private key if I forget the passphrase?
No, the passphrase is the only thing that unlocks your private key, and only you know it. If you forget it and have no separate backup, you'll need to generate a brand new key pair and notify all your contacts to switch to your new public key.
Can a recipient without PGP open an encrypted email?
No. An email encrypted with PGP appears as an unreadable .asc attachment or ciphertext. The recipient needs OpenPGP-capable software and the matching private key to decrypt and read it.
Does PGP encrypt the email subject line too?
No. The subject line, sender, and recipient remain visible even though the message body is encrypted. Avoid putting sensitive information in the subject field.
Do I need to use PGP for every email I send?
Not necessarily. It's most valuable for messages containing sensitive information — contracts, passwords, financial data, or customer records. Routine emails without sensitive content can still be sent normally.
Set Up a Business Email on Your Own Domain Today
AsiaGB Email Hosting comes with SPF/DKIM/DMARC and an easy-to-manage DirectAdmin panel, fully compatible with PGP encryption via Thunderbird.
View Email Hosting Plans