Skip to content

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

7 watching

Forks

Repository files navigation

RNP

RNP

OpenPGP for your Mac — keys, files, and Mail. librnp also powers Thunderbird's end-to-end encryption.

Download the latest release →


RNP is a native macOS app for OpenPGP key management, file encryption, and Apple Mail integration. The app is RNP; the Apple Mail extension that ships inside it is RNP for Mail.

Under the hood: librnp (the same engine used by Thunderbird for end-to-end encryption) and swift-rnp (Swift bindings + MailKit integration).

Features

  • Sign and encrypt outgoing mail from the compose window — Mail shows the lock icon automatically. Provided by the RNP for Mail extension that ships inside RNP.
  • Decrypt and verify incoming PGP/MIME mail inline — the message body renders as readable text, signatures show green/red in Mail's security banner. (RNP for Mail.)
  • Encrypt and decrypt files — open File → Files… (⌘⇧F) for a dedicated window. Drop any file to encrypt it for people in your keyring, or drop a .pgp/.gpg/.asc file to decrypt it. Same keyring RNP for Mail uses — no separate app, no GPG Suite.
  • Auto-discover keys via WKD — when you compose to a recipient whose key isn't in your keyring, RNP fetches it automatically from Web Key Directory (WKD) or keys.openpgp.org. No manual keyserver lookup needed.
  • Import from existing keyrings — auto-detects ~/.gnupg and ~/.rnp, lets you pick which keys to import. Read-only — never touches your source keyring.
  • Touch ID — keyring passphrase stored in macOS Keychain with biometric protection. Unlock once per session; no password typing on every message.
  • Trust-on-first-use (TOFU) — records the first key seen for each contact. If the key changes, RNP warns you before you encrypt to the new one.
  • Key lifecycle — generate, rotate subkeys, extend expiry, revoke, archive, and migrate to a new primary key — all from the Tools hub.
  • Recovery — export paper keys and revocation certificates for offline disaster recovery.
  • 11 locales — English, German, Spanish, French, Italian, Japanese, Korean, Portuguese, Russian, Simplified Chinese, Traditional Chinese.
  • macOS 14+ — runs on Sonoma and Sequoia. Universal binary (Apple Silicon + Intel).

Install

From the DMG (recommended)

  1. Download the latest RNP-X.Y.Z.dmg from the Releases page.
  2. Open the DMG and drag RNP.app to Applications.
  3. Launch RNP once to complete onboarding (generate or import a key).
  4. Open Mail → Settings → General → Manage Plug-ins… and tick RNP OpenPGP. Mail will restart.
  5. Done. Encrypted mail now shows the lock icon; compose windows have sign/encrypt toggles.

Verify the install

pluginkit -m -v -i com.rnpgp.RNPForMail.MailExtension
# Should show a line starting with "+" (enabled).

If the extension doesn't appear in Mail's plug-in list, see docs/mail-icon-diagnostic.md.

Build from source

git clone https://github.com/rnpgp/rnp-mailapp-extension.git
cd rnp-mailapp-extension
./scripts/build-rnp-framework.sh    # builds librnp xcframework (cached after first run)
open MailApp/RnpMail.xcodeproj
# In Xcode: select the "RNP" scheme, build (Cmd+B), run (Cmd+R).

Requires Xcode 16.4 and macOS 15 (Sequoia) for building. The built app runs on macOS 14+ (Sonoma).

Architecture

┌─────────────────────────────────────────────────────┐
│                   RNP.app (host)                     │
│  ┌──────────┐  ┌────────────┐  ┌─────────────────┐ │
│  │ Keyring  │  │ Tools Hub  │  │ Import from     │ │
│  │ Manager  │  │ (Health,   │  │ ~/.gnupg/~/.rnp │ │
│  │ (SwiftUI)│  │ Recovery)  │  │                 │ │
│  └────┬─────┘  └─────┬──────┘  └────────┬────────┘ │
│       │               │                   │          │
│  ┌────▼───────────────▼───────────────────▼────────┐│
│  │           swift-rnp (SPM package)               ││
│  │  ┌──────────────┐ ┌───────────┐ ┌────────────┐ ││
│  │  │ MailSecurity │ │ KeyServer │ │ TrustStore │ ││
│  │  │ Engine       │ │ Client    │ │ (TOFU)     │ ││
│  │  └──────┬───────┘ └─────┬─────┘ └────────────┘ ││
│  │         │               │                        ││
│  │  ┌──────▼───────────────▼────────────────────┐  ││
│  │  │            Rnp (FFI → librnp)              │  ││
│  │  └───────────────────────────────────────────┘  ││
│  └──────────────────────────────────────────────────┘│
│  ┌─────────────────────────────────────────────────┐│
│  │          MailPlugin.appex (extension)            ││
│  │  MEMessageSecurityHandler → MailSecurityEngine   ││
│  └─────────────────────────────────────────────────┘│
└─────────────────────────────────────────────────────┘
  • RNP.app — the container app: keyring management, tools hub, onboarding. Runs as a normal macOS app.
  • MailPlugin.appex — the Mail extension: intercepts incoming and outgoing mail, delegates to MailSecurityEngine.
  • swift-rnp — the Swift library: everything crypto-related (separate repo).

Contributing

  • Translations: see TRANSLATING.md.
  • Bug reports: include the diagnostics from docs/mail-icon-diagnostic.md.
  • Pull requests: open against main. CI runs one job per PR (ci.yml) with build + UI tests + release dry-run.

License

BSD-2-Clause (same as librnp). Bundled dependencies retain their own licenses — see About → Licenses in the app or Vendor/SOURCES.md.

Related projects

RNP sits at the top of the OpenPGP stack:

  • librnp — the C library that does the actual OpenPGP work. It is the official end-to-end encryption engine of Thunderbird. The macOS app here is one of its downstream consumers; Thunderbird is the largest.
  • swift-rnp — Swift bindings + MailKit integration that this app uses.
  • Thunderbird — for cross-platform encrypted email outside Apple Mail, RNP itself recommends Thunderbird. Same engine (librnp), same keys, different mail client.

Credits

RNP for Mail's host app and Mail extension are developed by Ribose Inc. using librnp.

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages