Skip to main content
Werkzeu.ge
Dashboard
Keys, encryption and signatures are created in your browser only. The format exists only on Werkzeu.ge (not OpenPGP, not S/MIME): Thunderbird or Outlook cannot read it, both sides need Werkzeu.ge.
ProБезпека

Шифрування е-пошти

Encrypt messages so that only the recipient can truly read them - with RSA and AES-256, entirely in your browser. Create keys, encrypt, decrypt, sign and verify signatures. The format exists only on Werkzeu.ge: it is not OpenPGP and not S/MIME, Thunderbird or Outlook cannot read it, both sides need Werkzeu.ge.

Погляд усередину

DatenschutzШифрування е-поштиВигадана демонстрація | Pro
✓Захищено
Контроль захисту даних

Hybrid of RSA and AES-256

1Hybrid of RSA and AES-256
2Generate a key pair
3Digital signatures
4Verify signatures
Перегляд лише для читання. Щоб користуватися, відкрий інструмент.

Цей безпечний перегляд показує, для чого потрібен інструмент, не виконуючи дій, що потребують акаунта.

Що вміє Шифрування е-пошти

A normal email is about as private as a postcard: anyone who gets their hands on it in transit can read along. Email Encryption puts your message into an envelope that only the right recipient can open. The content becomes unreadable to everyone else - to the mail provider, to eavesdroppers on the network, to anyone without the matching key.

Technically this is a hybrid scheme, the kind the security world has used for decades. Your actual message is encrypted with AES-256-GCM, a fast and very secure symmetric method. The key needed for that is in turn encrypted with RSA-OAEP using the recipient's public key. So you get the best of both worlds: the speed of AES and the key distribution of RSA.

It all starts with your own key, created by your browser - with 2048 or 4096 bits, one key pair to encrypt and one to sign. The public keys may and should be passed around: anyone who wants to write to you encrypts with them. The private keys are encrypted with your passphrase and live in this browser only. Back them up as a file, because without them no message addressed to you can be opened again.

Alongside encryption there are digital signatures (RSA-PSS). You sign a message with your private key, and anyone can verify with your public key that it really came from you and was not altered on the way. Encryption protects the content, the signature protects authenticity.

The key management keeps your contacts' public keys in one place and shows a fingerprint for each, so you can check that you really have the right key. Because encryption is only as good as the certainty that the public key truly belongs to who you think it does.

The crucial point: all cryptographic operations run through your browser's Web Crypto API, so locally on your device. Your private key, your passphrase and your plaintext are never sent to a server, and messages are not saved as drafts. The format is Werkzeu.ge's own: not OpenPGP, not S/MIME. Thunderbird, Outlook or GnuPG cannot open it, both sides need Werkzeu.ge.

Функції

Hybrid of RSA and AES-256

Messages are encrypted with AES-256-GCM, the key with RSA-OAEP - fast and secure at once.

Generate a key pair

Create your RSA key pair with 2048 or 4096 bits right in the tool.

Digital signatures

Sign messages with your private key so recipients can verify origin and integrity.

Verify signatures

Check with the public key whether a message is genuine and was not altered in transit.

Key management

Collect your contacts' public keys and check them via their fingerprint.

Усе в браузері

Encryption and decryption run locally via the Web Crypto API - your private key never leaves your device.

Як це працює

  1. 1

    Generate a key pair

    Create your RSA key pair. Share the public key, keep the private key secret.

  2. 2

    Exchange public keys

    Give your counterpart your public key and store theirs in the key management.

  3. 3

    Encrypt or sign

    Encrypt your text with the recipient's public key or sign it with your private key.

  4. 4

    Decrypt and verify

    Decrypt received messages with your private key and verify signatures with the public one.

Кому це потрібно

→People who want to exchange sensitive messages truly confidentially.
→Teams and families who all use Werkzeu.ge and do not want to mail confidential things in plain text.
→Anyone who wants to prove the authenticity of a message via a signature.
→Privacy-conscious people who never hand their private key out.
→Anyone wanting to understand and try how RSA and AES encryption work together.

Поширені запитання

How does the encryption work technically?

It is a hybrid scheme: your message is encrypted with AES-256-GCM, and the key used for it is protected with RSA-OAEP and the recipient's public key. This combines the speed of AES with the secure key distribution of RSA.

Does my private key ever leave my computer?

No. All cryptographic operations run through the Web Crypto API in your browser, so locally. Neither your private key nor your passphrase nor your plaintext is sent to a server. The private key is stored only in this browser, encrypted with your passphrase; the backup you download stays encrypted too.

What is the difference between encrypting and signing?

Encrypting makes the content unreadable to everyone but the recipient. Signing does not hide the content but proves the message came from you and was not altered. The two are often combined.

What is a key fingerprint for?

The fingerprint is a short, unique checksum of a public key. You can compare it over a second channel to make sure you really have your counterpart's genuine key and not a substituted one.

Is this compatible with PGP or GnuPG?

No. The tool uses proven building blocks (RSA and AES) but its own format, not OpenPGP and not S/MIME. Thunderbird, Outlook or GnuPG cannot open the messages. Both sides need Werkzeu.ge.

Псевдоніми е-пошти

Werkzeu.ge leitet keine Post weiter: Das Werkzeug schlägt Alias-Namen vor und zeigt die Schri…

Сховище паролів

Verwalte Passwörter verschlüsselt im lokalen Speicher deines Browsers. Web Crypto API, AES-25…

Генератор паролів

Erzeuge kryptographisch sichere Passwörter und Passphrasen. Länge und Zeichensatz einstellbar…

Перевірка хешу

Berechne MD5, SHA-1, SHA-256, SHA-384, SHA-512 Hashes und HMAC. Dateien und Texte hashen, ver…

Поштова скринька

Verbinde IMAP-Postfächer, lies Ordner und durchsuche Nachrichten. Kein Versand, Antworten, We…

Починаємо з Шифрування е-пошти?

Без встановлення. Входить від Pro. Відкривається прямо в браузері.

Відкрити зараз