Note to reader: I consider this procedure to be in beta. If you encounter difficulties, I want to know about it. Please leave a comment or get in touch with me.
It turns out that you most desktop email clients support end-to-end encryption using S/MIME. These work using public/private key encryption. You generate a key pair with a private key (which you store securely on your computer) and a public key (which you can share freely).
Using the private key, you can sign your emails so that anyone with the public key knows that the email came from you and hasn’t been modified along the way. Once someone has your public key, they can encrypt an email such that only someone holding the private key (you) can read it. Crucially, the email servers (and your email provider) do not have the ability to decrypt the email because they do not have the key.
Continue reading