Our Emails Are Now PGP-Signed — Verify Them Yourself
Starting today, automated emails from verify@getplasma.org — including node payment notifications — carry a PGP signature inside the message body.
Anyone can verify that an email really came from us. No account, no login, no trusting a third party.
Why?
Phishing is the most common attack against crypto projects. A forged “payment sent” or “verify your wallet” email can cost real money. Our community has been a target for years — so we decided to make forgery cryptographically impossible to hide.
We already sign every outgoing email with DKIM (check dkim=pass in the headers — your mail server verifies this automatically). PGP adds a second, independent proof that lives inside the message itself — verifiable even after forwarding, and independent of any mail server in between.
How to verify
- Download our public keys: getplasma.org/pgp-verify.asc
- Import them:
gpg --import pgp-verify.asc
- Save the email body to a file (e.g.
mail.txt) and verify:
gpg --verify mail.txt
You should see a good signature from:
getplasma.org payment signing (server key) <verify@getplasma.org>
fingerprint: ACEE 59B7 9A30 B460 78EC B0C8 2632 D768 6559 CE31
The server key is certified by our offline master key:
getplasma.org payments master key <verify@getplasma.org>
fingerprint: BB74 FE08 20C8 6169 6D69 56E4 4F31 69DB E3BB 7B
Even stronger: the blockchain
Payment emails contain a transaction hash. That hash is the strongest proof of all — it exists on our own blockchain and can only have been created by us. Every payment email now links directly to the matching transaction on our explorer, e.g. kc-explorer2.getplasma.org.
An email can be forged. A blockchain transaction cannot.
The short version
- âś… DKIM-signed (automatic, already active)
- ✅ PGP-signed body (new — verify manually if you want)
- âś… On-chain proof for every payment (impossible to fake)
If a “getplasma.org” email fails verification — it isn’t from us.