OpenPGP – publish your public key
Create or import the key pair in your email application. Meil does not generate private keys for you. See, for example, Thunderbird's end-to-end encryption guide.
Publish your key
- Set up your account in a compatible application using IMAP and SMTP.
- Create or import an OpenPGP key for the address you want to use. Make a protected backup of the private key.
- Export only the public key as text. It begins with
-----BEGIN PGP PUBLIC KEY BLOCK-----. - Open Settings, and find OpenPGP encryption under Login & Security.
- Select your email address, paste the public key and choose Publish key.
- Check the address and fingerprint in the list of published keys.
The address must belong to your account and appear in the key. The key must be valid and usable for encryption. Publish one key at a time, and only for a domain with WKD enabled.
Publication makes the public key available to others. It does not turn on automatic encryption. Ask a correspondent to fetch the key in their client and send a non-sensitive encrypted test message. Confirm an unexpected fingerprint change through a known channel.
Replace or remove
Publish the new public key for the same address to replace the old one in the directory. Keep the old private key if you need to read older messages.
Remove stops further publication from Meil. It does not withdraw copies already downloaded by others and is not cryptographic revocation. If you suspect compromise, also revoke the key in your OpenPGP application and notify your contacts.
If publication fails
- Address mismatch: Select the correct address or add it to the key in your client.
- Invalid or expired key: Export a valid public key with encryption capability.
- WKD is not enabled: Follow the domain guide; DNS alone does not activate the feature.
- Temporary error: Try later. Do not upload the private key as an alternative.
See also backup and recovery.