2026-07-28

How to Use PGP Encryption with Email — Thunderbird and Mailvelope Setup Guide

BY RAJAN MEHTA // Security

Pretty Good Privacy (PGP) isn’t optional if you’re communicating about sensitive topics on the darknet. It’s the floor. Every discussion about market listings, vendor verification, or encrypted messaging inside a marketplace script ultimately depends on the same cryptographic primitive that Phil Zimmermann first released in 1991. Whether you’re using a pre-built marketplace script built on Laravel (which typically includes optional PGP key import during registration) or composing a direct email to a trusted contact, the underlying mechanism is identical: you encrypt with the recipient’s public key, they decrypt with their private key. No intermediary-market admin, law enforcement, or hosting provider-can read the content without that private key.

Why PGP Still Matters for Email in 2025

The cryptographic security of PGP encryption depends on the assumption that the algorithms used are unbreakable by direct cryptanalysis with current equipment and techniques. As of this writing, there is no known method which will allow a person or group to break PGP encryption by cryptographic or computational means. Bruce Schneier characterized an early version as “the closest you’re likely to get to military-grade encryption.” That statement still holds for modern OpenPGP-compliant implementations. The algorithms in current use-RSA for session key encryption, various symmetric ciphers for the bulk data-remain unbroken at the mathematical level.

What does get broken is the human layer. The FBI has already deployed black-bag attacks against PGP, installing keystroke loggers or trojans on target machines to capture encrypted keyrings and their passwords. British police investigators are unable to break PGP, so instead have resorted to using RIPA legislation to demand passwords and keys, with at least one citizen jailed for nine months for refusing. The lesson is clear: PGP protects your message in transit and at rest, but it does nothing against a compromised endpoint or a court order compelling key disclosure.

Despite these operational limitations, PGP remains the only widely deployable tool for end-to-end encrypted email that doesn’t require both parties to use the same proprietary platform. It’s the backbone of darknet market communication, used in account recovery flows, vendor verification via signed messages, and encrypted buyer-vendor conversations that the marketplace operator cannot read even if they wanted to. Learning to use it properly with a standard email client is a core OPSEC skill.

Setting Up PGP with Thunderbird (Desktop)

Installing GnuPG

Thunderbird’s built-in OpenPGP support (introduced in version 78) uses GnuPG under the hood. On Linux, GnuPG is usually pre-installed. On Windows, download GnuPG from the official Gpg4win package. On macOS, use GPG Suite or install GnuPG via Homebrew. Verify the installation by opening a terminal and running gpg --version. You should see output indicating GnuPG 2.x and supported algorithms.

Generating Your Key Pair

In Thunderbird, navigate to Tools → Account Settings → End-to-End Encryption → Add Key. You have two options: create a new OpenPGP key or import an existing one. For a fresh start, choose “Create a new OpenPGP key.” Select RSA key type with a length of 4096 bits. Do not use a shorter key. Set an expiration date-one to two years is reasonable-and add a strong passphrase. This passphrase is your last line of defense if someone gains access to your key file. Write it down on paper, store it securely, and do not reuse it anywhere else.

Once generated, Thunderbird automatically associates this key with your email address. You can view your public key details under OpenPGP Key Management. Export your public key by right-clicking it and selecting “Export Public Key.” This is the file you share with others so they can encrypt messages to you. Never share your private key. Never upload it to a keyserver if you plan to use this identity for darknet communication-keyservers are public and permanent.

Sending an Encrypted Email

To send an encrypted email, you need the recipient’s public key. Import it via OpenPGP Key Management → Import. Thunderbird will ask you to verify the key’s fingerprint. This is critical. If you import the wrong key, your encrypted message will be readable only by the wrong person. Verify the fingerprint through an out-of-band channel-a verified message on a trusted directory, a PGP-signed post on a forum you trust, or a direct conversation via an encrypted messenger.

When composing a new email, look for the security icon in the toolbar. Click it and select “Require Encryption” and “Require Digital Signature.” Type your message and send. Thunderbird will automatically encrypt the body using the recipient’s public key. The recipient, on their end, will need their private key and passphrase to decrypt. If they don’t have their private key loaded, the message will appear as garbled ASCII-armored text.

Verifying Signed Messages

A PGP signature mathematically proves that the message came from the claimed sender-assuming you trust their public key. This is how darknet directories like Tor.Taxi and Dark.Fail protect users from link-swapping attacks. If a hacker compromises the Tor.Taxi server and replaces marketplace links with phishing URLs, the user who verifies the PGP signature on the signed message will see that the signature is invalid. The rule is simple: never use a link for financial transactions without verifying its PGP signature.

In Thunderbird, a signed message shows a yellow or green banner. Click the icon to see the signature details: which key signed it, the signature time, and whether the key is trusted. If the signature is valid and the key belongs to the expected person, the message is authentic. If not, assume the message has been tampered with and discard it.

Setting Up PGP with Mailvelope (Browser Extension)

Mailvelope is a browser extension that adds PGP functionality to web-based email services like Gmail, Outlook.com, ProtonMail, and others. It works as a middleman: when you compose a message in your webmail interface, Mailvelope intercepts the text field and encrypts it before the email is sent. The recipient sees the encrypted blob, not the readable message.

Installation and Key Generation

Install Mailvelope from the Chrome Web Store or Firefox Add-ons site. Verify the extension’s integrity by checking its signature (available on the developer’s website). Open Mailvelope from the browser toolbar and go to Settings → Key Management. Generate a new key pair: RSA 4096 bits, with your email address, name, and a strong passphrase. You can also import existing keys from Thunderbird or GnuPG by exporting them as .asc files and importing them here.

Encrypting a Webmail Message

Log into your webmail service as usual. Click “Compose.” You’ll see a Mailvelope icon or a “Start encryption” button in the compose window. Click it, and a separate pop-up window appears. Write your message in that pop-up. If you have the recipient’s public key imported, Mailvelope will automatically encrypt when you click “Send.” The encrypted text appears in the webmail compose field. Send it normally.

For the recipient, the process reverses: they receive the encrypted message in their inbox, click the Mailvelope icon, enter their passphrase, and the readable text appears. This works across any email provider because the encryption and decryption happen entirely inside the browser extension. No provider ever sees the plaintext.

Verifying Keys in a Darknet Context

When you find a vendor on a darknet market or a directory listing, they typically provide their PGP public key. Import it into Mailvelope. But before using it, verify the key’s fingerprint through at least two independent sources. For example, if Tor.Taxi lists a key fingerprint for a marketplace, cross-check it against the marketplace’s own signed message on a forum like Dread. If they match, you are likely dealing with the real operator. If they don’t, abort.

This verification process is non-negotiable. Darknet market scripts accept PGP public key import during registration, and many vendors use PGP-signed messages to prove their identity. A phishing site can copy the vendor’s public key and list it on a fake profile. Without fingerprint verification, you cannot distinguish the real key from the fake one.

Operational Considerations

Key Lifespan and Compromise

Set expiration dates on your keys. If you lose your private key or it gets compromised, expired keys are useless to an attacker. Revocation certificates are your safety net: generate one immediately after creating your keypair and store it offline. If you suspect compromise, publish the revocation certificate to keyservers and inform your contacts through an alternate channel.

Backup and Storage

Back up your private key and revocation certificate to a USB drive stored in a secure location-preferably a safe deposit box or a fireproof safe. Do not store them on cloud drives, email drafts, or any internet-connected device in plaintext. Encrypt the backup with a strong passphrase before storing it. If you use a password manager, store the passphrase there separately from the key file.

The Legal Reality

PGP encryption does not make you invisible. Law enforcement agencies that cannot break the math will target the endpoints. In the UK, refusal to provide encryption keys under RIPA legislation has resulted in jail time. In the US, the FBI has used physical access and malware to capture keys. PGP protects your communications against passive eavesdropping and mass surveillance. It does not protect against a targeted operation that compromises your machine or compels you to unlock it. Keep that distinction clear in your threat model.

Used correctly, PGP with Thunderbird or Mailvelope gives you the same cryptographic assurance that darknet market operators rely on when they sign their messages and verify their links. The math is sound. The human factors-key management, verification discipline, endpoint security-are where most people fail. Get those right, and you have a tool that still lives up to its original promise: pretty good privacy, for practical purposes, as close to military-grade as you can deploy on a consumer device.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-10-10
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026