Understand email encryption keys
Use GnuPG keys with compatible email software; this is separate from SSL/TLS.
Where Tools → Email → Encryption
Before you start
- Your mail software and recipients must support the same public-key workflow.
- Plan secure private-key and passphrase backups; losing them can make old mail unreadable.
Steps
-
1
Open Encryption. Under Create a New Key, enter Your Name, Your Email and an optional comment.
-
2
Choose a strong unique Key Password and confirm it. Store it privately.
-
3
Use Generate Key only when ready. For an existing key, use Import Key and the expected format instead.
-
4
Share only the public key. Never expose private-key material in screenshots, tickets or public folders.
-
5
Configure the compatible email client and exchange a test with a trusted recipient. Generating keys here does not automatically encrypt all mail.
-
6
Set the expiry and Key Size according to your security requirements rather than simply choosing no expiry.
The key-generation form is separate from mailbox and SSL settings.
Check it worked
- Check the key identity and expiry.
- Confirm decryption and secure backup recovery before relying on the key.