To use OpenPGP encryption in Thunderbird, select a personal key for each sending account or identity, obtain and verify a public key for every recipient, then explicitly enable encryption when composing a message. Back up your secret key before relying on it: without that key, you may be unable to read encrypted mail sent to you, including saved messages.
Set up your personal OpenPGP key
- In Thunderbird, open Account Settings, select the email account or identity you want to configure, and choose End-To-End Encryption.
- Select Add Key…. Import an existing OpenPGP key if you have one, or create a new key. Thunderbird accepts an imported key for this use when it is not expired or revoked, supports both signing and encryption, and has a user ID that includes the email address configured for the account. See Mozilla’s Thunderbird OpenPGP setup guide.
- Select the key as the personal key for that account or identity. Configure each account and identity separately; selecting a key for one does not configure the others.
- Back up the secret key and protect the backup with a strong password. Never send or publish your secret key. Thunderbird protects imported secret keys within the application, and Mozilla recommends setting a Primary Password. Losing the secret key can leave encrypted messages—including archived messages—unreadable. Mozilla explains setup and backup considerations in its introduction to end-to-end encryption.
Use the same key on your other devices
If you use Thunderbird on more than one device, Mozilla recommends creating or choosing one key, backing it up, and importing that same key on your other devices. Separate keys can complicate access to messages encrypted for you.
Get and verify each recipient’s public key
You need a suitable public key for every recipient before Thunderbird can encrypt a message to them. Keys may come from an email attachment, Autocrypt headers, a web server, or WKD (Web Key Directory) discovery. You can import a key through Thunderbird’s OpenPGP controls or Key Manager. Mozilla describes these sources and the prerequisites in its OpenPGP FAQ.
Before accepting or trusting a key, check that it belongs to the person you intend to contact. A key that merely claims someone’s email address is not proof of identity; trusting the wrong key can expose the message to a person-in-the-middle attack.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
Compose and send an encrypted message
- Start a message from the account or identity that has your personal key selected.
- In the message’s security or encryption controls, enable OpenPGP encryption. Encryption is not automatic. The composer’s exact control and wording can vary between Thunderbird versions, so use the current interface rather than relying on an old button label.
- Check every address in To, Cc, and Bcc. Each recipient must have an available, suitable key using the same encryption technology as the message. If a recipient is missing a key or has an invalid one, Thunderbird may prevent sending. OpenPGP and S/MIME cannot be combined in one encrypted message.
- Optionally enable a digital signature, then send. A signature can let recipients check that the message matches your key; they need access to your public key and should verify its identity. Signing does not encrypt or conceal the message.
Test your configuration
Send an encrypted message to yourself from the configured account or identity. Retrieve it and check the security indication in the message header. If the message cannot be encrypted or read, confirm that the sending identity has the correct personal key selected, that the recipient key is valid and available, and that you are using the same technology for all recipients.
Understand what OpenPGP does not hide
OpenPGP protects message contents, but it does not necessarily conceal email metadata. Sender and recipient addresses or names, the send time, and information about the sending and receiving computers may remain visible. The subject may also remain exposed. Avoid putting sensitive details in the subject line.
Rank #2
Company or alias keys change the trust boundary
Thunderbird’s alias-key feature can allow a public key to be used even when its address does not match the usual email-address rule. Mozilla cautions that a corporate shared key may let a company server decrypt a message and forward the plaintext. That arrangement is not the same as end-to-end encryption to an individual correspondent; use it only when you understand and trust who can access the decrypted message. See Mozilla’s guidance on alias keys.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Export or import a key when needed
Thunderbird’s OpenPGP controls and Key Manager provide ways to manage, export, and import keys. Keep exported secret-key material private and password-protected; share only your public key. Consult Mozilla’s OpenPGP FAQ for key-management help and the setup guide for account configuration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

