If you've spent any time browsing onion sites, you've probably seen a block of text that starts with "BEGIN PGP SIGNED MESSAGE" or ends with "BEGIN PGP SIGNATURE." Knowing how to verify a PGP signature on an onion site is a practical skill, but it's often misunderstood. A valid signature does not mean a site is safe, trustworthy, or even who it claims to be. It proves something narrower and more useful than that.

What a PGP signature actually is

PGP, short for Pretty Good Privacy, was developed by Phil Zimmermann in 1991 to add encryption and authentication to digital communication. One of its core features is the digital signature.

To sign something, the sender computes a mathematical digest of the message or file, then encrypts that digest with their private key. Anyone holding the matching public key can reverse this process and confirm the digest matches. If it does, two things are true: the content has not been altered since signing, and it was signed by whoever controls that private key.

What verification proves, and what it doesn't

This is the part people get wrong most often. A valid signature confirms integrity and key ownership, but not identity by itself.

The public key you check against still has to belong to the person or organization you think it does. As Wikipedia's entry on OpenPGP notes, users must ensure by some independent means that a public key actually belongs to its claimed owner before relying on any signature made with that key. Skip that step, and a "valid" result only tells you the message matches some key, not whose key it is.

Why this matters more on onion sites

Onion addresses are long, random-looking strings. There is no domain name to eyeball, no visual branding cue, nothing that looks obviously wrong the way a typo'd clearnet domain might. That makes onion services an easy target for lookalike clones.

Tor's own design already encrypts the connection between you and an onion service, using introduction and rendezvous points to negotiate that link. But that protects the channel, not the authenticity of what's published through it. A signature is a separate, additional check on the content itself, not the connection carrying it.

Organizations that publish onion addresses sometimes sign them for exactly this reason, so that someone who already trusts their key can confirm the addresses weren't altered or substituted along the way.

The hard part: getting the right key in the first place

Verification only means something if the key you're checking against is genuine. Discussion in the Whonix support forum makes a blunt point: to get any security benefit from key verification, you need to confirm the key through a channel that doesn't depend on the same TLS certificate or onion connection you're trying to verify. Asking "how do I fix this key error" in a forum thread, or trusting a script someone handed you, doesn't solve that problem. If you have to ask how to verify a key securely, the forum notes, you likely can't do it securely in that moment. The Tails project has reached a similar conclusion.

In practice, the safest approach is straightforward: get the onion address and the signing key directly from an organization's official surface-web presence, one you already trust, rather than from a directory listing, a forum post, or a search result. Cross-check the key fingerprint against more than one source tied to that organization if you can.

A general, low-risk verification workflow

The exact commands vary by tool, but the underlying steps are consistent:

If any step feels rushed, uncertain, or dependent on a source you can't independently confirm, pause rather than push through.

Common mistakes that undermine verification

A few habits defeat the whole point of checking a signature:

Verification is not anonymity

It's worth separating two different goals. PGP verification is about authenticity and integrity: is this really from who it claims, and has it been altered. Tor Browser and the Tor network are about routing and connection privacy.

Neither one makes your actions anonymous by itself. Logging into a personal account, reusing a recognizable username, or downloading and opening files carelessly can undo the protections either tool offers, regardless of how carefully you verified a signature beforehand. Treat PGP verification as one layer of careful habit, not a guarantee that covers everything else you do.