How to Verify an Onion Address with a PGP Signature
Trusting a published list is optional. Checking the math behind it takes five minutes. By Mara Kestrel ·
A PGP signature on an address list is only useful if you actually check it rather than trusting that a green checkmark or a "verified" label means someone else already did. This walkthrough covers what the signature confirms, and how to check it yourself in either a command-line GPG setup or the Kleopatra GUI, using the Torzon address list as a working example.
What a PGP Signature Actually Confirms
A valid signature confirms two things: the signed text matches exactly what the key holder signed, and whoever controls that private key produced it. It does not confirm that the key holder is honest, that the addresses in the message are safe to use in some broader sense, or that the message hasn't been superseded by a newer one. It's a narrow, mechanical guarantee — treat it as exactly that.
Verifying in GPG (Command Line)
- Import the public key:
gpg --import torzon-public-key.asc - Save the full signed message — including the
-----BEGIN PGP SIGNED MESSAGE-----header and the signature block at the end — into a text file exactly as published, with no extra line breaks added. - Run
gpg --verify signed-message.txt(orgpg --decryptdepending on the message format). - Check the output for
Good signature fromfollowed by the expected key ID. ABAD signatureor a mismatched key ID means stop and don't trust the addresses in that file.
Verifying in Kleopatra (Windows GUI)
- Import the public key file through File → Import Certificates.
- Save the signed message as a
.txtfile on disk. - Right-click the file and choose Decrypt/Verify, or drag it into the Kleopatra window.
- Kleopatra displays the result directly — a green confirmation for a valid signature from the known key, or a red warning if the signature doesn't match.
What a Valid Signature Looks Like vs a Failed One
A valid result names the specific key and fingerprint that produced the signature, with no warnings about untrusted keys (assuming you've verified the fingerprint separately, which GPG's trust model doesn't do for you automatically). A failed result — whether from a bad signature, wrong key, or altered text — should be treated as a full stop, not a "close enough." Any single character changed in the signed text invalidates the whole signature.
Applying This to Torzon's Address List
The links page publishes the current signed message and the key fingerprint used to check it. Running the steps above against that message is the actual verification step referenced throughout this site — everything else, including the "Matches signed list" status shown on that page, is downstream of this check having already been done.
Frequently Asked Questions
What does a valid PGP signature actually prove?
That the message hasn't changed since it was signed with a specific private key. It doesn't prove the signer is trustworthy or who they claim to be beyond controlling that key.
Do I need to verify every time, or just once?
Verify whenever the address list changes or you're unsure your copy is current. A prior verification only covers the message you checked, not future updates.
What if GPG reports a bad signature?
Stop using any address from that message. It means the text was altered, you used the wrong key, or something was copied incorrectly — resolve which one before proceeding.
Last reviewed: by Mara Kestrel.