What is the GPG file format?
The .gpg file format is used for files created with GNU Privacy Guard (GnuPG), a widely used open-source encryption tool. A .gpg file most commonly contains an encrypted file or message, though the same extension also covers binary keyrings and detached signatures within the same OpenPGP ecosystem.
Data stored in .gpg files follows the OpenPGP standard - originally defined by RFC 2440 (1998) and revised as RFC 4880 in 2007. This is the same standard used by the .pgp format (Pretty Good Privacy), making .gpg and .pgp largely interchangeable at the data level. The standard received a significant update as RFC 9580 (2024), introducing mandatory AEAD encryption and support for modern elliptic curves such as Ed448 and X448. To decrypt a .gpg file you need GnuPG and the recipient's matching private key; binary keyrings are stored in .kbx files.
A .gpg file is binary - it is not human-readable. The ASCII-armored text equivalent, which can be safely shared by email or pasted into a terminal, uses the .asc extension instead. On Windows, Gpg4win with its Kleopatra graphical interface is the most common way to work with .gpg files; on Linux and macOS, the gpg command-line tool handles encryption, decryption, and key management.
Security & safety
RISK: LOWThe .gpg format is a security tool, not a threat - the file is encrypted/signed OpenPGP data and contains no executable code. The real cautions are about keys and secrets: a secring.gpg / secret-key .gpg holds your PRIVATE keys - never share it, and protect it with a strong passphrase. When decrypting, do it locally with GnuPG, not on a website where you'd paste a passphrase or private key. For an encrypted file you received, a successful decrypt only means it decrypted - the plaintext inside should still be treated with normal caution. After decrypting, the recovered file (e.g. an exe or document) carries whatever risk that file type normally would.
Format details
in a nutshellPrograms that open GPG files
Technical details
deep spec| MIME type | application/pgp-encrypted |
| File encoding | Binary OpenPGP packets (not Base64; see .asc for the ASCII-armored text variant) |
| Primary purpose | Encrypting files and messages; also used for binary keyrings and detached signatures |
| Governing standard | OpenPGP - RFC 2440 (1998), RFC 4880 (2007), RFC 9580 (2024) |
| Packet structure | Series of variable-length OpenPGP packets; first byte is a packet-tag byte with the high bit always set |
| Magic bytes | None fixed - first byte is an OpenPGP packet tag; commonly 0x85, 0x84, or 0xC1 for encrypted-data packets |
| Asymmetric algorithms | RSA, ElGamal, ECDH, ECDSA, EdDSA (Ed25519; Ed448 added in RFC 9580) |
| Symmetric ciphers | AES-128/192/256, Camellia-128/192/256, 3DES, Twofish (selected via algorithm preference in the recipient's key) |
| Hash algorithms | SHA-256, SHA-512 (preferred); SHA-1 (legacy); SHA3-256, SHA3-512 (RFC 9580) |
| Pre-encryption compression | Optional - plaintext may be compressed with DEFLATE (ZIP), ZLIB, or BZIP2 before encrypting |
| Symmetric-only mode | Supports passphrase-based encryption without a public key using S2K (string-to-key) derivation |
| Integrity protection | MDC (Modification Detection Code) in RFC 4880; AEAD modes (OCB, EAX, GCM) mandated in RFC 9580 |
| Decryption requirement | Recipient's private key (or passphrase for symmetric-only files) and GnuPG or a compatible OpenPGP tool |
| Key infrastructure | Compatible with Web of Trust (WoT) model and public keyservers such as keys.openpgp.org |
| Released | GnuPG 1.0 in 1999; OpenPGP standardized as RFC 2440 (1998) / RFC 4880 (2007) / RFC 9580 (2024) |
| Open standard | Yes · royalty-free |
| Specification | www.rfc-editor.org |
GPG conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about GPG files.