Encryption and Security

From the Delta Chat FAQ.

Encryption and Security

Which standards are used for end-to-end encryption?

Delta Chat uses a secure subset of the OpenPGP standard to provide automatic end-to-end encryption using these protocols:

Delta Chat does not query, publish or interact with any OpenPGP key servers.

How can I know if messages are end-to-end encrypted?

All messages in Delta Chat are end-to-end encrypted by default. Since the Delta Chat Version 2 release series (July 2025) there are no lock or similar markers on end-to-end encrypted messages, anymore.

Can I still receive or send messages without end-to-end encryption?

If you use default chatmail relays, it is impossible to receive or send messages without end-to-end encryption.

If you instead use a classic email server, you can send and receive messages with or without end-to-end encryption. Messages lacking end-to-end encryption are marked with an email icon email.

What happened to the green checkmark in contact profiles?

Older Delta Chat versions showed a green checkmark green checkmark and an “Introduced by” line in some contact profiles.

This line is no longer present. Since Delta Chat V2 contacts are identified by their cryptographic key (“public key”), and there is never any possibility for the relay operator to exchange a key in order to execute a man-in-the-middle (MitM) attack (in fact, the operator does not even see the key at any point).

It is still possible for an attacker to give you an invite link that impersonates someone else, and an attacker who has your Delta Chat contact (because they are in a group chat with you) could try to start a chat with you under a wrong name. These kinds of attacks are present in all messengers, and we are planning future improvements in order to mitigate them.

Are attachments (pictures, files, audio etc.) end-to-end encrypted?

Yes.

When we talk about an “end-to-end encrypted message” we always mean a whole message is encrypted, including all the attachments and attachment metadata such as filenames.

Is OpenPGP secure?

Yes, Delta Chat uses a secure subset of OpenPGP requiring the whole message to be properly encrypted and signed. For example, “Detached signatures” are not treated as secure.

OpenPGP is not insecure by itself. Most publicly discussed OpenPGP security problems actually stem from bad usability or bad implementations of tools or apps (or both). It is particularly important to distinguish between OpenPGP, the IETF encryption standard, and GnuPG (GPG), a command line tool implementing OpenPGP. Many public critiques of OpenPGP actually discuss GnuPG which Delta Chat has never used. Delta Chat rather uses the OpenPGP Rust implementation rPGP, available as an independent “pgp” package, and security-audited in 2019 and 2024.

We aim, along with other OpenPGP implementors, to further improve security characteristics by implementing the new IETF OpenPGP Crypto-Refresh which was thankfully adopted in summer 2023.

Did you consider using alternatives to OpenPGP for end-to-end-encryption?

Yes, we are following efforts like MLS but adopting them would mean breaking end-to-end encryption interoperability. So it would not be a light decision to take and there must be tangible improvements for users.

Delta Chat takes a holistic “usable security” approach and works with a wide range of activist groupings as well as renowned researchers such as TeamUSEC to improve actual user outcomes against security threats. The wire protocol and standard for establishing end-to-end encryption is only one part of “user outcomes”, see also our answers to device-seizure and message-metadata questions.

Is Delta Chat vulnerable to EFAIL?

No, Delta Chat never was vulnerable to EFAIL because its OpenPGP implementation rPGP uses Modification Detection Code when encrypting messages and returns an error if the Modification Detection Code is incorrect.

Delta Chat also never was vulnerable to the “Direct Exfiltration” EFAIL attack because it only decrypts multipart/encrypted messages which contain exactly one encrypted and signed part, as defined by the Autocrypt Level 1 specification.

Are messages marked with the mail icon exposed on the Internet?

If you are sending or receiving email messages without end-to-end encryption (using a classic email server), they are still protected from cell or cable companies who can not read or modify your email messages. But both your and your recipient’s email providers may read, analyze or modify your messages, including any attachments.

Delta Chat by default uses strict TLS encryption which secures connections between your device and your email provider. All of Delta Chat’s TLS-handling has been independently security audited. Moreover, the connection between your and the recipient’s email provider will typically be transport-encrypted as well. If the involved email servers support MTA-STS then transport encryption will be enforced between email providers in which case Delta Chat communications will never be exposed in cleartext to the Internet even if the message was not end-to-end encrypted.

How does Delta Chat protect metadata in messages?

Unlike most other messengers, Delta Chat apps do not store any metadata about contacts or groups on servers, also not in encrypted form. Instead, all group metadata is end-to-end encrypted and stored on end-user devices, only.

Servers can therefore only see:

All other message, contact and group metadata resides in the end-to-end encrypted part of messages.

How to protect metadata and contacts when a device is seized?

Both for protecting against metadata-collecting servers as well as against the threat of device seizure we recommend to use a chatmail relay to create chat profiles using random addresses for transport. Note that Delta Chat apps on all platforms support multiple profiles so you can easily use situation-specific profiles next to your “main” profile with the knowledge that all their data, along with all metadata, will be deleted. Moreover, if a device is seized then chat contacts using short-lived profiles can not be identified easily.

Who sees my IP Address?

The used relays need to know your IP Address, as well as sometimes your contact’s devices if you have a call or use apps together.

IP Addresses are needed for connectivity and efficiency. Delta Chat neither persists nor exposes them. Note that IP Addresses are not like an address you give to a delivery service, but typically less precise, often defining city or region only.

If you see your IP Address as a risk, we recommend to use a VPN for the whole system. Per-app options leave gaps across your system. For example, tapping a link can expose IP Addresses to unknown parties, which is by far the larger risk.

Does Delta Chat support “Sealed Sender”?

No, not yet.

The Signal messenger introduced “Sealed Sender” in 2018 to keep their server infrastructure ignorant of who is sending a message to a set of recipients. It is particularly important because the Signal server knows the mobile number of each account, which is usually associated with a passport identity.

Even if chatmail relays do not ask for any private data (including no phone numbers), it might still be worthwhile to protect relational metadata between addresses. We don’t foresee bigger problems in using random throw-away addresses for sealed sending but an implementation has not been agreed as a priority yet.

Does Delta Chat support Perfect Forward Secrecy?

Not yet, but it’s coming with Autocrypt v2.

Delta Chat today doesn’t support Perfect Forward Secrecy (PFS). This means that if your private decryption key is leaked, and someone has collected your prior in-transit messages, they will be able to decrypt and read them using the leaked decryption key. Note that Forward Secrecy only increases security if you delete messages. Otherwise, someone obtaining your decryption keys is typically also able to get all your non-deleted messages and doesn’t even need to decrypt any previously collected messages.

Autocrypt v2, scheduled for full implementation in 2026, will provide reliable deletion (forward secrecy) through automatic key rotation. This approach is specified in the Autocrypt v2 OpenPGP Certificates draft.

Does Delta Chat support Post-Quantum-Cryptography?

Not yet, but it’s coming with Autocrypt v2.

Autocrypt v2, scheduled for full implementation in 2026, will bring post-quantum resistant encryption to protect against quantum computer attacks. Delta Chat uses the Rust OpenPGP library rPGP which supports the latest IETF Post-Quantum-Cryptography OpenPGP draft. The implementation is specified in the Autocrypt v2 OpenPGP Certificates draft.

How can I manually check encryption information?

You may check the end-to-end encryption status manually in the “Encryption” dialog (user profile on Android/iOS or right-click a user’s chat-list item on desktop). Delta Chat shows two fingerprints there. If the same fingerprints appear on your own and your contact’s device, the connection is safe.

Can I reuse my existing private key?

No.

Delta Chat generates secure OpenPGP keys according to the Autocrypt specification 1.1. We do not recommend or offer users to perform manual key management. We want to ensure that security audits can focus on a few proven cryptographic algorithms instead of the full breadth of possible algorithms allowed with OpenPGP. If you want to extract your OpenPGP key, there only is an expert method: you need to look it up in the “keypairs” SQLite table of a profile backup tar-file.

Was Delta Chat independently audited for security vulnerabilities?

Yes, multiple times. The Delta Chat project continuously undergoes independent security audits and analysis, from most recent to older: