HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Destinations
Docs
Destinations
WKD Auto-Encryption for Replies & Sends

WKD Auto-Encryption for Replies & Sends

Learn how to automatically discover recipient PGP keys and encrypt outbound replies and sends using Web Key Directory (WKD).

3 min read
Updated June 20, 2026

Asymmetric encryption is incredibly secure, but it has historically suffered from one major friction point: key distribution. If you wanted to send an encrypted email to a contact, you first had to manually ask for their PGP public key, verify their fingerprint, and save it in your keyring.

Web Key Directory (WKD) solves this distribution problem by allowing domains to securely publish their users' PGP public keys at a standard, predictable URL on their website.

For users on our Pro and Business plans, AliasFleet uses WKD to automatically discover your recipient's PGP public key and encrypt your outbound replies or sends on-the-fly—giving you hands-off, seamless security.


How WKD Auto-Discovery Works

When you send a new email from an alias, or reply to an email forwarded by AliasFleet, our gateway does the heavy lifting in the background:

  1. WKD Discovery Query: Our mail engine hashes the local part of the recipient's email address and queries their domain's well-known directory (e.g., https://openpgpkey.recipient-domain.com/.well-known/openpgpkey/...).
  2. Global Keyserver Fallback: If their domain doesn't host a WKD service, our engine automatically searches highly secure, verified global registries like keys.openpgp.org as a backup.
  3. Smart Encryption: If a valid public key is found, we encrypt the outbound email before sending it. If no key is found, the email is sent normally (unencrypted). No delivery attempt is aborted.

Setting Up WKD Auto-Encryption

Since outbound emails originate from your real email inbox, WKD auto-encryption settings are tied directly to your verified destination addresses:

  1. Go to your Dashboard and navigate to Settings > Destinations.
  2. Locate your destination and click WKD Settings (represented by the globe/lock icon).
  3. Switch Enable WKD Auto-Discovery to on.
  4. Choose your encryption format and subject-line options (see below).
  5. Click Save WKD Settings.

Outbound Encryption Preferences

We offer several options to tailor how your encrypted outbound emails are sent:

1. Encryption Mode

  • PGP/MIME (Recommended): This encrypts the entire email packet (RFC 3156). Outgoing attachments, embedded files, and rich HTML formatting remain secure. This is supported by modern secure mail clients.
  • Inline PGP: Only encrypts the text content of your email. Choose this if you're frequently emailing recipients with older clients that don't support modern PGP MIME formatting.

2. Subject Line Encryption

To protect your recipient's metadata as well as the email body:

  • Turn Encrypt Subject on.
  • Add a Subject Replacement (e.g., [Encrypted Message]).
  • Mail relays will only see the placeholder, but once your recipient decrypts the email, their client will automatically restore your original subject line.

Behind the Scenes

  • High Performance Caching: To prevent outbound mail delays, we cache discovered public keys in memory for 1 hour. We won't keep hitting your recipient's domain for consecutive messages.
  • Zero Transmission of Private Keys: Key discovery is an outbound, read-only query. At no point do we generate, store, or transmit PGP private keys.
  • Delivery Verification: All successfully encrypted outbound emails will contain the transport header X-AliasFleet-PGP: encrypted-wkd so you can verify the secure transmission.

Want to learn how to encrypt incoming forwarded emails to your inbox? Take a look at our PGP Encryption Guide.

Frequently Asked Questions

What is WKD auto-encryption?

It automatically finds your recipient's public PGP key on-the-fly and encrypts your outgoing emails to them when you reply or send from an alias.

How does AliasFleet find recipient keys?

AliasFleet queries the recipient's domain Web Key Directory (WKD) standard endpoint, and if not found, falls back to secure keyservers like keys.openpgp.org.

Do I need to manage recipient keys?

No. The lookup and encryption happen fully in the background at runtime. You do not need to upload or keep track of external public keys.

Was this article helpful?

Related articles

What Is a Destination?

What destinations are, why you need them, and how they relate to aliases

Adding a Destination

How to add a new destination email address to your account

Verifying a Destination

How the verification process works and what to do if it fails

Setting a Default Destination

How to choose which destination new aliases forward to by default

Reply from Aliases

How to reply to forwarded emails so recipients see your alias, not your real address

Content

How WKD Auto-Discovery WorksSetting Up WKD Auto-EncryptionOutbound Encryption Preferences1. Encryption Mode2. Subject Line EncryptionBehind the Scenes

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket