Our Emails Are Now PGP-Signed — Verify Them Yourself

Starting today, automated emails from verify@getplasma.org — including node payment notifications — carry a PGP signature inside the message body.

Anyone can verify that an email really came from us. No account, no login, no trusting a third party.

Why?

Phishing is the most common attack against crypto projects. A forged “payment sent” or “verify your wallet” email can cost real money. Our community has been a target for years — so we decided to make forgery cryptographically impossible to hide.

We already sign every outgoing email with DKIM (check dkim=pass in the headers — your mail server verifies this automatically). PGP adds a second, independent proof that lives inside the message itself — verifiable even after forwarding, and independent of any mail server in between.

How to verify

  1. Download our public keys: getplasma.org/pgp-verify.asc
  2. Import them:
gpg --import pgp-verify.asc
  1. Save the email body to a file (e.g. mail.txt) and verify:
gpg --verify mail.txt

You should see a good signature from:

getplasma.org payment signing (server key) <verify@getplasma.org>
fingerprint: ACEE 59B7 9A30 B460 78EC  B0C8 2632 D768 6559 CE31

The server key is certified by our offline master key:

getplasma.org payments master key <verify@getplasma.org>
fingerprint: BB74 FE08 20C8 6169 6D69  56E4 4F31 69DB E3BB 7B

Even stronger: the blockchain

Payment emails contain a transaction hash. That hash is the strongest proof of all — it exists on our own blockchain and can only have been created by us. Every payment email now links directly to the matching transaction on our explorer, e.g. kc-explorer2.getplasma.org.

An email can be forged. A blockchain transaction cannot.

The short version

  • âś… DKIM-signed (automatic, already active)
  • âś… PGP-signed body (new — verify manually if you want)
  • âś… On-chain proof for every payment (impossible to fake)

If a “getplasma.org” email fails verification — it isn’t from us.