Encryption and Security
From the Delta Chat FAQ.
Encryption and Security
Which standards are used for end-to-end encryption?
Delta Chat uses a secure subset of the OpenPGP standard to provide automatic end-to-end encryption using these protocols:
-
Secure-Jointo exchange encryption setup information through QR-code scanning or “invite links”. -
Autocryptis used for automatically establishing end-to-end encryption between contacts and all members of a group chat. -
Autocrypt v2, scheduled for full implementation in 2026, will bring post-quantum resistant encryption and forward secrecy. -
Sharing a contact to a chatenables receivers to use end-to-end encryption with the contact.
Delta Chat does not query, publish or interact with any OpenPGP key servers.
How can I know if messages are end-to-end encrypted?
All messages in Delta Chat are end-to-end encrypted by default. Since the Delta Chat Version 2 release series (July 2025) there are no lock or similar markers on end-to-end encrypted messages, anymore.
Can I still receive or send messages without end-to-end encryption?
If you use default chatmail relays,
it is impossible to receive or send messages without end-to-end encryption.
If you instead use a classic email server,
you can send and receive messages with or without end-to-end encryption.
Messages lacking end-to-end encryption are marked with an email icon
.
What happened to the green checkmark in contact profiles?
Older Delta Chat versions showed a green checkmark
and an “Introduced by” line in some contact profiles.
This line is no longer present.
Since Delta Chat V2
contacts are identified by their cryptographic key (“public key”),
and there is never any possibility for the relay operator
to exchange a key in order to execute a man-in-the-middle (MitM) attack
(in fact, the operator does not even see the key at any point).
It is still possible for an attacker to give you an invite link
that impersonates someone else, and an attacker who has your Delta Chat contact
(because they are in a group chat with you)
could try to start a chat with you under a wrong name.
These kinds of attacks are present in all messengers,
and we are planning future improvements in order to mitigate them.
Are attachments (pictures, files, audio etc.) end-to-end encrypted?
Yes.
When we talk about an “end-to-end encrypted message” we always mean a whole message is encrypted, including all the attachments and attachment metadata such as filenames.
Is OpenPGP secure?
Yes, Delta Chat uses a secure subset of OpenPGP requiring the whole message to be properly encrypted and signed. For example, “Detached signatures” are not treated as secure.
OpenPGP is not insecure by itself.
Most publicly discussed OpenPGP security problems
actually stem from bad usability or bad implementations of tools or apps (or both).
It is particularly important to distinguish between OpenPGP, the IETF encryption standard,
and GnuPG (GPG), a command line tool implementing OpenPGP.
Many public critiques of OpenPGP actually discuss GnuPG which Delta Chat has never used.
Delta Chat rather uses the OpenPGP Rust implementation rPGP,
available as an independent “pgp” package,
and security-audited in 2019 and 2024.
We aim, along with other OpenPGP implementors,
to further improve security characteristics by implementing the
new IETF OpenPGP Crypto-Refresh
which was thankfully adopted in summer 2023.
Did you consider using alternatives to OpenPGP for end-to-end-encryption?
Yes, we are following efforts like MLS
but adopting them would mean breaking end-to-end encryption interoperability.
So it would not be a light decision to take
and there must be tangible improvements for users.
Delta Chat takes a holistic “usable security” approach
and works with a wide range of activist groupings as well as
renowned researchers such as TeamUSEC
to improve actual user outcomes against security threats.
The wire protocol and standard for establishing end-to-end encryption is
only one part of “user outcomes”,
see also our answers to device-seizure
and message-metadata questions.
Is Delta Chat vulnerable to EFAIL?
No, Delta Chat never was vulnerable to EFAIL
because its OpenPGP implementation rPGP
uses Modification Detection Code when encrypting messages
and returns an error
if the Modification Detection Code is incorrect.
Delta Chat also never was vulnerable to the “Direct Exfiltration” EFAIL attack
because it only decrypts multipart/encrypted messages
which contain exactly one encrypted and signed part,
as defined by the Autocrypt Level 1 specification.
Are messages marked with the mail icon exposed on the Internet?
If you are sending or receiving email messages without end-to-end encryption (using a classic email server), they are still protected from cell or cable companies who can not read or modify your email messages. But both your and your recipient’s email providers may read, analyze or modify your messages, including any attachments.
Delta Chat by default uses strict
TLS encryption
which secures connections between your device and your email provider.
All of Delta Chat’s TLS-handling has been independently security audited.
Moreover, the connection between your and the recipient’s email provider
will typically be transport-encrypted as well.
If the involved email servers support MTA-STS
then transport encryption will be enforced between email providers
in which case Delta Chat communications will never be exposed in cleartext to the Internet
even if the message was not end-to-end encrypted.
How does Delta Chat protect metadata in messages?
Unlike most other messengers, Delta Chat apps do not store any metadata about contacts or groups on servers, also not in encrypted form. Instead, all group metadata is end-to-end encrypted and stored on end-user devices, only.
Servers can therefore only see:
- Sender and receiver addresses, randomly generated by default
- Message size
All other message, contact and group metadata resides in the end-to-end encrypted part of messages.
How to protect metadata and contacts when a device is seized?
Both for protecting against metadata-collecting servers
as well as against the threat of device seizure
we recommend to use a chatmail relay
to create chat profiles using random addresses for transport.
Note that Delta Chat apps on all platforms support multiple profiles
so you can easily use situation-specific profiles next to your “main” profile
with the knowledge that all their data, along with all metadata, will be deleted.
Moreover, if a device is seized then chat contacts using short-lived profiles
can not be identified easily.
Who sees my IP Address?
The used relays need to know your IP Address, as well as sometimes your contact’s devices if you have a call or use apps together.
IP Addresses are needed for connectivity and efficiency. Delta Chat neither persists nor exposes them. Note that IP Addresses are not like an address you give to a delivery service, but typically less precise, often defining city or region only.
If you see your IP Address as a risk, we recommend to use a VPN for the whole system. Per-app options leave gaps across your system. For example, tapping a link can expose IP Addresses to unknown parties, which is by far the larger risk.
Does Delta Chat support “Sealed Sender”?
No, not yet.
The Signal messenger introduced “Sealed Sender” in 2018
to keep their server infrastructure ignorant of who is sending a message to a set of recipients.
It is particularly important because the Signal server knows the mobile number of each account,
which is usually associated with a passport identity.
Even if chatmail relays
do not ask for any private data (including no phone numbers),
it might still be worthwhile to protect relational metadata between addresses.
We don’t foresee bigger problems in using random throw-away addresses for sealed sending
but an implementation has not been agreed as a priority yet.
Does Delta Chat support Perfect Forward Secrecy?
Not yet, but it’s coming with Autocrypt v2.
Delta Chat today doesn’t support Perfect Forward Secrecy (PFS). This means that if your private decryption key is leaked, and someone has collected your prior in-transit messages, they will be able to decrypt and read them using the leaked decryption key. Note that Forward Secrecy only increases security if you delete messages. Otherwise, someone obtaining your decryption keys is typically also able to get all your non-deleted messages and doesn’t even need to decrypt any previously collected messages.
Autocrypt v2, scheduled for full implementation in 2026,
will provide reliable deletion (forward secrecy) through automatic key rotation.
This approach is specified in the Autocrypt v2 OpenPGP Certificates draft.
Does Delta Chat support Post-Quantum-Cryptography?
Not yet, but it’s coming with Autocrypt v2.
Autocrypt v2, scheduled for full implementation in 2026,
will bring post-quantum resistant encryption to protect against quantum computer attacks.
Delta Chat uses the Rust OpenPGP library rPGP
which supports the latest IETF Post-Quantum-Cryptography OpenPGP draft.
The implementation is specified in the Autocrypt v2 OpenPGP Certificates draft.
How can I manually check encryption information?
You may check the end-to-end encryption status manually in the “Encryption” dialog (user profile on Android/iOS or right-click a user’s chat-list item on desktop). Delta Chat shows two fingerprints there. If the same fingerprints appear on your own and your contact’s device, the connection is safe.
Can I reuse my existing private key?
No.
Delta Chat generates secure OpenPGP keys according to the Autocrypt specification 1.1. We do not recommend or offer users to perform manual key management. We want to ensure that security audits can focus on a few proven cryptographic algorithms instead of the full breadth of possible algorithms allowed with OpenPGP. If you want to extract your OpenPGP key, there only is an expert method: you need to look it up in the “keypairs” SQLite table of a profile backup tar-file.
Was Delta Chat independently audited for security vulnerabilities?
Yes, multiple times. The Delta Chat project continuously undergoes independent security audits and analysis, from most recent to older:
-
2024 December, an
NLNET-commissioned Evaluation of rPGPbyRadically Open Securitytook place. rPGP serves as the end-to-end encryptionOpenPGPengine of Delta Chat. Two advisories were released related to the findings of this audit:“Panics on Malformed Untrusted Input”CVE-2024-53856“Potential Resource Exhaustion when handling Untrusted Messages”CVE-2024-53857
The issues outlined in these advisories have been fixed and are part of Delta Chat releases on all appstores since December 2024.
-
2024 March, we received a deep security analysis from the Applied Cryptography research group at ETH Zuerich and addressed all raised issues. See our blog post about
Hardening Guaranteed End-to-End encryptionfor more detailed information and theCryptographic Analysis of Delta Chatresearch paper published afterwards. -
2023 April, we fixed security and privacy issues with the “web apps shared in a chat” feature, related to failures of sandboxing especially with Chromium. We subsequently got an independent security audit from Cure53 and all issues found were fixed in the 1.36 app series released in April 2023. See
here for the full background story on end-to-end security in the web. -
2023 March,
Cure53analyzed both the transport encryption of Delta Chat’s network connections and a reproducible mail server setup asrecommended on this site. You can read more about the auditon our blogor read the full report here. -
2020,
Include Securityanalyzed Delta Chat’s Rustcore,IMAP,SMTP, andTLSlibraries. It did not find any critical or high-severity issues. The report raised a few medium-severity weaknesses - they are no threat to Delta Chat users on their own because they depend on the environment in which Delta Chat is used. For usability and compatibility reasons, we can not mitigate all of them and decided to provide security recommendations to threatened users. You can read the full report here. -
2019,
Include Securityanalyzed Delta Chat’sPGPandRSAlibraries. It found no critical issues, but two high-severity issues that we subsequently fixed. It also revealed one medium-severity and some less severe issues, but there was no way to exploit these vulnerabilities in the Delta Chat implementation. Some of them we nevertheless fixed since the audit was concluded. You can read the full report here.