We include a signature.asc file with all account notification emails and company announcement emails.
To verify the integrity of each email, you will need to:
(0) Import our public key and sign it
This is a one-time setup you need to do before you can verify emails from Kraken:
(1) Check if the email is signed
However, anyone can create a PGP key for any email address. That's why the next step is critical.
(2) Check if the signature is trusted
If you click on the signed checkmark to open the signature details, you should see it say "This signature can be trusted".
If the signature details say "This signature is not to be trusted", this most likely means:
- you forgot to sign our public key, and/or
- you forgot to set the "Ownertrust" of your own private key to "Ultimate"
If you've done both and the signature is still not showing as trusted, it may be a fake email. Please immediately reach out to our support team.