HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Destinations
Docs
Destinations
PGP Encryption for Destinations

PGP Encryption for Destinations

Secure your forwarded emails with zero server-side secrets. Learn how to add your PGP public key and enable auto-encryption.

4 min read
Updated June 20, 2026

Traditional email was never designed with privacy in mind. When an email is forwarded from your aliases to your destination inbox, it travels across multiple intermediate networks and mail relays in cleartext. Any server along that path can potentially read, log, or scan your message.

For users on our Pro or Business plans, AliasFleet solves this by supporting Pretty Good Privacy (PGP). By encrypting forwarded emails at the gateway with your public key, we ensure your messages remain fully confidential from the moment they leave our system until they arrive safely in your hands.


The Zero-Knowledge Security Model

We believe privacy isn't privacy unless it's absolute. That's why AliasFleet uses a strict zero-knowledge model:

  1. You generate a PGP key pair locally on your own device.
  2. You upload only your PGP Public Key to your AliasFleet dashboard.
  3. Our mail engine encrypts forwarded emails with your public key as they pass through.
  4. You decrypt them on your own computer or phone using your PGP Private Key.
Important

We don't want, and can't use, your private key. Because your private key never leaves your local device, nobody except you—not even AliasFleet—can read your encrypted emails.


How to Set Up PGP Encryption

Step 1: Get Your PGP Public Key

If you don't have a key pair yet, you can generate one using standard open-source tools:

  • GnuPG (GPG): The standard command-line utility for Windows, macOS, and Linux.
  • GPG Suite (macOS) / Kleopatra (Windows): User-friendly desktop apps for managing PGP keys.
  • Mail Client Tools: Modern email clients like Mozilla Thunderbird have PGP generators built right in.

Once generated, export your key as an Armored Public Key (this is a text block beginning with -----BEGIN PGP PUBLIC KEY BLOCK-----).

Step 2: Upload Your Key

  1. Open your dashboard and head to Settings > Destinations.
  2. Find the verified destination address you want to encrypt and click PGP Settings.
  3. Paste your armored PGP public key into the field.
  4. We'll instantly validate the key, check its expiration date, and show you its fingerprint.
  5. Click Save PGP Settings. Your emails are now secured.

Tailoring Your Encryption Settings

You can customize how AliasFleet handles your encrypted emails:

1. Choose Your Encryption Mode

  • PGP/MIME (Recommended): This encrypts the entire email structure (RFC 3156). Rich HTML styling, layout, embedded images, and attachments remain completely secure. Most modern clients like Thunderbird and Canary Mail handle this seamlessly.
  • Inline PGP: Only encrypts the plain text body. If an inbound email contains HTML, we automatically convert it to plain text before encrypting. Use this option only if your email client doesn't support PGP/MIME.

2. Encrypt Your Subject Lines

By default, email subject lines stay unencrypted so mail servers can route them. If you want to hide your subjects from snooping eyes:

  • Toggle Encrypt Subject on.
  • Enter a Subject Replacement (e.g., [Secure Email] or ...).
  • We'll swap out the subject in transit and tuck the original subject safely inside the encrypted envelope.

Decrypting and Reading Your Mail

To read your forwarded emails, you'll need an email client that handles PGP decryption. Here are some popular, reliable options:

  • Mozilla Thunderbird: Built-in native PGP support. Just import your private key into the End-to-End Encryption settings.
  • Apple Mail (macOS): Best paired with the GPG Suite extension.
  • Outlook (Windows): Fully supported when configured with Gpg4win.
  • Mobile Clients: Apps like Canary Mail, FairEmail, or K-9 Mail (integrated with OpenKeychain on Android) provide excellent mobile PGP support.

Want to learn how to automatically encrypt outbound replies and new emails too? Check out our guide on WKD Auto-Encryption.

Frequently Asked Questions

How does destination PGP encryption work?

When enabled, AliasFleet encrypts all forwarded emails using your PGP public key before sending them to your inbox. You decrypt them locally.

Does AliasFleet hold my private PGP key?

No. AliasFleet only stores your public PGP key. Your private key stays on your local device, ensuring zero-knowledge privacy.

Can I encrypt the subject line?

Yes. You can enable subject line encryption, which replaces the transport subject with a placeholder and hides the original inside the encrypted envelope.

Was this article helpful?

Related articles

What Is a Destination?

What destinations are, why you need them, and how they relate to aliases

Adding a Destination

How to add a new destination email address to your account

Verifying a Destination

How the verification process works and what to do if it fails

Setting a Default Destination

How to choose which destination new aliases forward to by default

Reply from Aliases

How to reply to forwarded emails so recipients see your alias, not your real address

Content

The Zero-Knowledge Security ModelHow to Set Up PGP EncryptionStep 1: Get Your PGP Public KeyStep 2: Upload Your KeyTailoring Your Encryption Settings1. Choose Your Encryption Mode2. Encrypt Your Subject LinesDecrypting and Reading Your Mail

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket