Blog Articles 186–186

E-mail Signatures (GnuPG/PGP)

In God we trust—all others must submit an X.509 certificate.

 — Charles Forsythe

If you’ve gotten an e-mail from me recently, you’ve likely noticed a strange attachment accompanying it. Perhaps you’ve even reached this page from my signature, wondering what that file is and what you’re supposed to do with it. This page will serve to explain what these files are, and why they’re a good idea.

I cryptographically sign my e-mails (well, most of them anyway). It is a way of providing proof that I am the author of a message, and a way to verify that you have received an authentic message from me. Further, I encourage everyone to sign their e-mails; I will also willingly accept encrypted e-mail. Information on obtaining my keys is provided at the end of this document.