WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Meitar v0.8.0

WP PGP Encrypted Emails

Signs and encrypts emails using PGP/GPG keys or X.509 certificates. Provides OpenPGP and S/MIME functions via WordPress plugin API.

WP PGP Encrypted Emails

The facts

Rating
4.6★ from 16
Active installs
400+
Price
Free
Last updated
25 May 2021
Added
Jan 2016
Requires WP
4.4
Tested up to
WP 5.7.17
Downloads
27,053

Our analysis

AI-assisted

WP PGP Encrypted Emails is a WordPress plugin that automatically signs and encrypts emails sent to your site's admin and users. It requires the recipient's OpenPGP public key or S/MIME certificate to function, ensuring that only intended recipients can read the emails. This enhances privacy and helps users verify the authenticity of emails from your site.

The plugin is designed for users who prioritize email security and privacy, including site administrators and developers. It supports multisite installations and integrates with various third-party contact form plugins, making it versatile for different WordPress setups.

Best for: This plugin is suitable for WordPress sites that need enhanced email privacy and security.

What it does well

  • Automatically signs and encrypts outgoing emails
  • Supports per-user encryption keys and certificates
  • Compatible with many third-party contact form plugins
  • No binaries required; everything is included in the plugin
  • Multisite compatible without additional configuration

Where it falls short

  • Limited information on specific features and performance
  • Requires users to manage their own encryption keys

Verdict

WP PGP Encrypted Emails offers essential email encryption features for WordPress users, though it may require some user management for encryption keys.

From the developer

Meitar's own description of WP PGP Encrypted Emails, lightly tidied.

WP PGP Encrypted Emails can automatically sign and encrypt any email that WordPress sends to your site’s admin email address or your users’s email addresses. You give it a copy of the recipient’s OpenPGP public key and/or their S/MIME certificate, and it does the rest. You can even automatically generate an OpenPGP signing keypair for your site to use.

Encrypting outgoing emails protects your user’s privacy by ensuring that emails intended for them can be read only by them, and them alone. Moreover, signing those emails helps your users verify that email they receive purporting to be from your site was actually sent by your server, and not some imposter. If you’re a plugin or theme developer, you can encrypt and/or sign arbitrary data using this plugin’s OpenPGP and S/MIME APIs, which are both built with familiar, standard WordPress filter hooks. This enables you to develop highly secure communication and publishing tools fully integrated with your WordPress install. See the README.markdown file for details on cryptographic implementation and API usage.

Donations for this and my other free software plugins make up a chunk of my income. If you continue to enjoy this plugin, please consider making a donation. 🙂 Thank you for your support!

Plugin features:

  • Processes all email your site generates, automatically and transparently.
  • Configure outbound signing: sign email sent to all recipients, or just savvy ones.
  • Per-user encryption keys and certificates; user manages their own OpenPGP keys and S/MIME certificates.
  • Compatible with thousands (yes, thousands) of third-party contact form plugins.
  • Full interoperability with all standards-compliant OpenPGP and S/MIME implementations.
  • Options to enforce further privacy best practices (e.g., removing Subject lines).
  • Fully multisite compatible, out of the box. No additional configuration for large networks!
  • No binaries to install or configure; everything you need is in the plugin itself.
  • Bells and whistles included! For instance, visitors can encrypt comments on posts so only the author can read them.
  • Built-in, customizable integration with popular third-party plugins, such as WooCommerce.
  • Always FREE. Replaces paid email encryption “upgrades,” and gets rid of yearly subscription fees. (Donations appreciated!)
  • And more, of course. 😉

The plugin works transparently for all email your site generates, and will also sign and encrypt outgoing email generated by other plugins (such as contact form plugins) or the built-in WordPress notification emails. All you have to do is add one or more OpenPGP keys or an S/MIME certificate to the Email Encryption screen (WordPress Admin Dashboard → Settings → Email Encryption). Each user can opt to also remove envelope information such as email subject lines, which encryption schemes cannot protect. With this plugin, there’s no longer any need to pay for the “pro” version of your favorite contact form plugin to get the benefit of email privacy.

Each of your site’s users can supply their own, personal OpenPGP public key and/or X.509 S/MIME certificate for their own email address to have WordPress automatically encrypt any email destined for them. (They merely need to update their user profile.) They can choose which encryption method to use. Once set up, all future emails WordPress sends to that user will be encrypted using the standards-based OpenPGP or S/MIME technologies.

The OpenPGP-encrypted emails can be decrypted by any OpenPGP-compatible mail client, such as MacGPG (macOS), GPG4Win (Windows), Enigmail (cross-platform), OpenKeychain (Android), or iPGMail (iPhone/iOS). For more information on reading encrypted emails, generating keys, and other uses for OpenPGP-compatible encryption, consult any (or all!) of the following guides:

The S/MIME-encrypted emails can be decrypted by any S/MIME-compatible mail client. These include Apple’s Mail on macOS and iOS for iPhone and iPad, Microsoft Outlook, Claws Mail for GNU/Linux, and more.

For developers, WP PGP Encrypted Emails provides an easy to use API to both OpenPGP and S/MIME encryption, decryption, and integrity validation operations through the familiar WordPress plugin API so you can use this plugin’s simple filter hooks to build custom OpenPGP- or S/MIME-based encryption functionality into your own plugins and themes.

Security Disclaimer

Security is a process, not a product. Using WP PGP Encrypted Emails does not guarantee that your site’s outgoing messages are invulnerable to every attacker, in every possible scenario, at all times. No single security measure, in isolation, can do that.

Do not rely solely on this plugin for the security or privacy of your webserver. See the Frequently Asked Questions for more security advice and for more information about the rationale for this plugin.
If you like this plugin, please consider making a donation for your use of the plugin or, better yet, contributing directly to my Cyberbusking fund. Your support is appreciated!

Themeing

Theme authors can use the following code snippets to integrate a WordPress theme with this plugin.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for building forms.

WPForms

WPForms

98

The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, paymen...

Free 5M+ installs 4.8★ (14,369)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Fluent Forms

Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features...

Free 700k+ installs 4.8★ (790)
Forminator Forms

Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrati...

Free 600k+ installs 4.8★ (2,117)
Database Addon for Contact Form 7

Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 databas...

Free 600k+ installs 5★ (1,874)
MetForm

MetForm

93

Elementor forms builder to create WordPress forms like contact form, booking form, feedback form, survey form,...

Free 600k+ installs 4.7★ (504)