Verify a Thunderbird OpenPGP Recipient Key Before Accepting It
An imported OpenPGP public key can carry a familiar name and email address without belonging to that person. Before trusting it for confidential correspondence, establish the key's identity independently. Thunderbird's acceptance setting records a decision; clicking it is not the verification itself.
Compare the complete fingerprint
Open the candidate public key's details in Thunderbird and locate its fingerprint. Arrange a comparison through a channel where you can establish that you are speaking with the intended correspondent, such as an already trusted phone contact or an in-person conversation. Do not rely solely on another message arriving through the channel whose key is being checked.
Have the correspondent inspect their own key's fingerprint and compare the complete value. A matching name, short key identifier or the first few characters is insufficient. If the fingerprints differ, leave the candidate unverified and investigate whether the wrong key was supplied or a legitimate replacement is being confused with an older one.
For an organisation, record the verification date, correspondent and public fingerprint in the appropriate contact-security record. Do not put secret keys or their passwords into that note. A future key change should prompt a fresh comparison rather than automatic acceptance because the address is unchanged.
Record acceptance only after the comparison
Mark the key as verified only when the independent comparison succeeds. Thunderbird's OpenPGP guidance distinguishes accepting a correspondent's key from merely obtaining it. Accepted keys are used for encryption and influence how signatures are presented.
Review the intended recipients in an unsent draft. Thunderbird requires a suitable accepted public key for every recipient of an encrypted message, alongside the sender's own configured key. Do not remove encryption simply to get past a missing-key warning when the material requires confidentiality.
Keep the draft pending if any recipient's key remains unresolved. Successful key verification establishes which public key belongs to that correspondent; it does not confirm that the eventual message reached them or that their device is secure. Content approval and any authorised delivery test remain separate from this identity check.
Source: Thunderbird documentation.
Additional reference: Thunderbird OpenPGP acceptance FAQ.