← Docs

Encryption & signatures

S/MIME and PGP: add keys, send encrypted, verify signatures — and where the limits are.

What is encrypted — and what is not

Astreo supports S/MIME and OpenPGP. Both protect the content of a message end to end: it is encrypted by the sender and decrypted by the recipient. Nobody in between can read it — not even a mail server.

That is different from the two layers that always apply anyway:

What is not protected: the subject and the addresses. They live in the headers every mail server needs for delivery and therefore stay outside the encryption. This applies to S/MIME and PGP alike and is not an Astreo peculiarity. If someone sends you a message using protected headers (Thunderbird and others do), Astreo shows the real inner subject instead of the placeholder on the outer envelope.

Adding your own key

Everything lives under Settings → Encryption. You need a key of your own in order to sign and to read encrypted mail addressed to you.

Every key can be bound to a mailbox or kept personal. The first key of your own per method automatically becomes the default; use Make default to change that at any time. The list shows the method, address, fingerprint, validity and whether it is your own key or a recipient's. Expired keys are marked as such.

Private keys never come back out: Astreo does not display them again after import and does not hand them out through the APIs.

Your correspondents' keys

You can only encrypt to recipients whose public key you hold. Astreo usually collects those on its own:

Signing & sending encrypted

The composer has toggles for Sign and Encrypt plus the choice of method (S/MIME or PGP). Either can be used on its own or both together.

Encrypted sending works across all connected mailbox types — SMTP as well as Microsoft 365 via Graph.

Reading encrypted mail

Astreo detects incoming protected messages by itself, decrypts them with your stored key and verifies any signature. At the top of the message you will see:

Encryption details expands to show the method, signer, fingerprint and expiry date. If no matching key is available for decryption, Astreo says so plainly instead of showing an empty message.

Limits — a deliberate choice

So you know what you are relying on: