Cannot decrypt messages if signature cannot be verified due to missing public key
I'm using GPGTools 2026.1 (3604n) on Sequoia and find GPGMail fails to decrypt signed+encrypted messages if it cannot verify the signature due to the public key of the signer not being present in the keyring. In previous versions, I believe it would decrypt the message but display a warning about not being able to verify the signature. Now, the below error message pops up and the message remains encrypted in Mail.app
Decryption failed with unknown error!
An unknown error occurred while decrypting this message.
GPG error message:
gpg: encrypted with rsa4096 key, ID
***********************, created YYY-MM-DD
"First Last <emailfdomain.com>"
gpg using
""****************************************"" as default secret key for signing
gpg: Signature made Tue Feb 10 22:27:29 2026 EST gpg:
using RSA key
"****************************************"
gpg: Can't check signature: No public key
Please contact us, including the GPG error message, at https://support.gpgtools.org
Keyboard shortcuts
Generic
| ? | Show this help |
|---|---|
| ESC | Blurs the current field |
Comment Form
| r | Focus the comment reply box |
|---|---|
| ^ + ↩ | Submit the comment |
You can use Command ⌘ instead of Control ^ on Mac
Support Staff 1 Posted by Steve on 09 Jul, 2026 04:22 PM
Hi gpg_dude,
thanks for your patience.
I tried reproducing this issue with GPGSuite 2026.1 (3623n) on macOS 27b3 and macOS 15.7.8.
In both cases the encountered behavior was that GPG Mail decrypted the email in question, showed the lock icon and encrypted info. Signature was not verified and instead of the signature icon a warning is displayed "The key to verify this signature is not in GPG Keychain" along with the "Show Details" button opening a dialog with additional details.
Could you please re-test with GPGSuite 2026.1 (3623n) and let us know your findings and whether the problematic behavior you reported is persisting or not.
Best & have a great day,
Steve
2 Posted by gpg_dude on 09 Jul, 2026 06:31 PM
Hi Steve,
No worries, I found this because a script I run to create new schleuder-based encrypted mailing lists was failing to send me the list's public key, so as a workaround I send it to myself in a way that bypasses the need. Unfortunately, when I tried the original command to send it the old way again I'm still seeing a decryption failure with unknown error in Mail on macOS 15.7.7 (I assume that was a typo from you above, there is no 15.7.8)
Support Staff 3 Posted by Steve on 10 Jul, 2026 11:02 AM
This is unexpected. The 15.7.8 wasn't a typo as I was testing with the development pre-release. But I doubt there were any big changes in Mail app between 15.7.7 and 15.7.8, although with Apples poor documentation that is really hard to tell.
Could you do more testing and see if you are able to reproduce the issue when sending a 1:1 email with no mailing list involved.
And if the issue only happens with the mailing list variant we would have to understand how the mail structure differs and why one triggers the offensive behavior while the other does not. But that is yet to see.
4 Posted by gpg_dude on 10 Jul, 2026 12:29 PM
Ah, good to know they're working on patch for Sequoia. I did some more testing the only time the behavior surfaces is when I receive a signed+encrypted message from the list and I don't have the public key to verify it. I can successfully receive a signed, but unencrypted message from the list and it displays the body of the message and the banner notifying me the signature could not be verified. If it's helpful I could add you to the list and send you a sample email that is signed+encrypted to look at and also send (or tell you how to trigger it to send) you an unencrypted+signed email to compare if that's helpful
Support Staff 5 Posted by Steve on 10 Jul, 2026 03:30 PM
The two mentioned samples would be welcome to have, so that we can dig more into the message structure. Can you use [email blocked] for both test emails please.
6 Posted by gpg_dude on 10 Jul, 2026 03:58 PM
OK - that email should have received a signed+encrypted email from a list address that starts with test3 (leaving out domain since this is a public thread). The list's public key is not published anywhere so GPG Keychain won't be able to auto-download it which might make this behavior particularly rare.
To get a version of the message that is only signed, but not encrypted send a message to test3-sendkey@{THE_DOMAIN} and the list will reply back to you with that in a message