Gpg4win app icon

System tools

Gpg4win

Encrypt and sign files and email on Windows with the official GnuPG distribution, the Kleopatra certificate manager and Outlook integration.

WindowsFree software (GNU GPL components)

OpenPGP and S/MIME encryption for Windows

Gpg4win is the official Windows distribution of GnuPG, the OpenPGP implementation that has been the reference tool for public-key encryption for decades. It is a bundle rather than a single program: the GnuPG engine does the cryptography, Kleopatra provides a graphical certificate manager and encryption dialogs, GpgOL integrates with Microsoft Outlook, and GpgEX adds a right-click menu inside Windows Explorer for encrypting and decrypting files. Both OpenPGP and S/MIME (X.509) certificates are supported, and the project is maintained by the GnuPG developers.

Keys, signing and encryption in practice

Everything begins with a key pair. Kleopatra generates it, protects the private half with a passphrase, and exports the public half so other people can encrypt to you. A revocation certificate is produced at the same time and should be stored offline: it is the only way to announce that a key has been compromised if the private key is ever lost or stolen. Once correspondents hold your public key, they can send encrypted material that only your private key opens, and you can sign files so recipients can check that nothing changed in transit. File encryption works on any file type through the Kleopatra dialogs or the Explorer context menu, which makes the tool useful for archives, backups and documents that travel by email or chat, not only for mail.

Email, verification and the trust question

GpgOL plugs into classic Outlook and adds buttons for signing and encrypting messages, working over IMAP/SMTP and Exchange accounts. The awkward part of any OpenPGP setup is trust: a key that carries the right email address in its user ID is not proof of identity, so the fingerprint has to be confirmed out of band, in person or over a channel you already trust. Signing incoming mail and verifying fingerprints is what upgrades a key from unverified to trusted. This is a process problem rather than a software feature, and it is the step most people skip.

Configuration, limits and maintenance

The installer is 64-bit and targets Windows 10 version 1809 or later and Windows 11. Configuration lives in GnuPG's own files and Kleopatra dialogs rather than in one settings screen, and the bundled documentation, the Gpg4win Compendium, is genuinely worth reading because OpenPGP concepts do not map neatly onto one-click encryption. Practical limits: encrypted mail requires the other side to use compatible software; webmail interfaces are not covered by GpgOL, which only works with classic Outlook; a lost private key without a backup means permanent loss of access to everything encrypted to it; and passphrase caching by the agent can leave keys usable for a period after unlocking unless the cache timeout is shortened.

When another tool is the better fit

For protecting files on a cloud drive, a container or vault tool is easier than exchanging keys. For a single archive that has to travel, ordinary password-protected archiving is simpler when the recipient is not an OpenPGP user. Gpg4win is the right choice when you specifically need interoperable OpenPGP or S/MIME encryption, when you are dealing with a correspondent who already uses it, or when you need to verify signed software releases and documents.

Best for
Windows users who need interoperable OpenPGP or S/MIME encryption for files and Outlook mail, with a proper certificate manager instead of command-line-only tooling.
Good to know
Create a revocation certificate when you generate your key and store it offline. OpenPGP only proves identity if you verify fingerprints out of band; the software cannot do that part for you.

Gpg4win brings GnuPG, a certificate manager and email integration into one Windows installer.

How to get started

  1. Run the installer and keep the default component selection unless you specifically do not need Outlook integration.
  2. Open Kleopatra and generate a new OpenPGP key pair with a strong passphrase.
  3. Create the revocation certificate when prompted and save it to offline media, not on the same machine only.
  4. Export your public key and publish it to a keyserver or send it directly to the people who need to encrypt to you.
  5. Import a correspondent's public key, verify the fingerprint out of band, and certify it so it shows as trusted.
  6. Encrypt a test file through the Explorer context menu and decrypt it again to confirm the workflow.

Questions & answers

Which email clients are supported?

GpgOL integrates with classic Microsoft Outlook only. Webmail in a browser is not covered, so encrypted mail there needs a different approach.

Is OpenPGP the same as S/MIME?

No, they are different standards. Gpg4win supports both, so the right choice depends on what your correspondents already use.

What if I lose my private key?

Without a backup you lose access to everything encrypted to that key and cannot decrypt old messages. Generate the revocation certificate in advance and keep a backup of the key material offline.

More in system tools

View category