What is PGP (Pretty Good Privacy)?

PGP (Pretty Good Privacy) is a way to encrypt and sign email and files with public-key cryptography. Each person has a public key to share and a private key to keep. Anyone can encrypt a message with your public key, and only your private key can open it. The open standard behind it is called OpenPGP.

Also called: Pretty Good Privacy, OpenPGP, GPG

Updated October 2026. Sources are numbered and listed at the end.

On this page

How PGP works

  1. You create a key pair. The public key can go to anyone. The private key stays on your device, protected by a passphrase.
  2. Someone writes to you. Their software makes a random one-time key, encrypts the message with it, then locks that one-time key with your public key.
  3. You open it. Your private key unlocks the one-time key, which unlocks the message.
  4. Signing runs the other way. You sign with your private key, and anyone with your public key can check that the message came from you and wasn’t changed.

The hard part is knowing a public key really belongs to the person named on it. PGP leaves that to its users. You compare a key’s fingerprint with its owner directly, or rely on other people who have signed the key to vouch for it, an approach known as the web of trust.

PGP, OpenPGP and GPG

Three names that are often used as if they were one.
NameWhat it is
PGPThe original program, released by Phil Zimmermann in 19912
OpenPGPThe open standard that describes the message and key formats, so different programs can work together1
GPG (GnuPG)A free program that implements the OpenPGP standard3

The standard is still maintained. The IETF published the current version, RFC 9580, in July 2024. It replaces the 2007 version and adds modern algorithms such as X25519 and Ed25519, along with authenticated encryption.1

Why PGP matters

PGP put strong encryption in the hands of ordinary people. Zimmermann wrote that it lets people take their privacy into their own hands.2 It showed that two people can exchange mail that the services carrying it only see as scrambled data, the idea now called end-to-end encryption.

What PGP protects, and what it leaves open

  • It protects the body of a message and its attachments, and it can prove who wrote them.
  • It doesn’t hide who is writing to whom, or when. Mail servers need that information to deliver the message.
  • Keys are long-lived. The same private key opens every message sent to you, so it has to be kept safe for years.
  • Both people need it. Each side has to create keys, exchange them and check them before they can send a protected message.

Where you’ll see PGP

You’ll come across PGP as blocks of text that begin with “BEGIN PGP MESSAGE” or “BEGIN PGP SIGNATURE,” as public keys listed on contact pages, and as signature files next to software downloads, which let you check that a file is the one its developer released.

Sources

  1. IETF, RFC 9580: OpenPGP (July 2024).
  2. Phil Zimmermann, Why I wrote PGP (1991, updated 1999).
  3. GnuPG, The GNU Privacy Guard.

Checked October 2026.

Questions about PGP

Is PGP still secure?

The cryptography in current OpenPGP software is sound, and the standard was updated in 2024 with modern algorithms. Most real-world problems come from handling keys: losing a private key, trusting the wrong public key, or using very old software and settings.

What is the difference between PGP and GPG?

PGP is the original program from 1991. GPG, short for GnuPG, is a free program that follows the same open standard, OpenPGP. Messages made with one can be read with the other.

Is PGP an encryption algorithm?

No. PGP is a system and a message format that combines several algorithms: one to exchange keys, one to encrypt the message, one to sign it and one to hash it.

What is the difference between PGP and S/MIME?

Both encrypt and sign email with public-key cryptography, and they aren’t compatible with each other. With PGP, people create and check keys themselves. With S/MIME, a certificate authority issues each person a certificate that vouches for their address.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail