Appearance
Forwarding means a message passes through our servers in a readable form. PGP removes that.
How to set it up
- Upload your public key to a recipient, under Recipients.
- Enable encryption on that recipient.
From then on, every message forwarded to that address is encrypted to your key before it leaves here.
What it protects
Anything that reads the message after it leaves our relay, including your own mail provider, sees ciphertext. So does anybody who obtains a copy from your provider later, with or without your knowledge.
What it does not protect
The message before it reaches us, because the sender wrote it in the clear. The headers, including who wrote to which alias, because a mail server has to route on them.
It also does not help against somebody reading the message as it arrives at our relay, in that instant. Nothing that involves receiving mail on your behalf can.
The cost, stated plainly
If you lose your private key, the mail is gone. We cannot recover it, we have no copy, and no support conversation changes that.
Your mail app also has to handle PGP, and some do it badly. Try it on one recipient before turning it on for everything.
Exceptions
A rule can disable encryption for a specific sender, which is the escape hatch for a service whose mail you need to read on a device that cannot decrypt. See Rules.
