Back Up Your Own Thunderbird OpenPGP Secret Key Before Retiring a Computer
Before replacing a computer used for encrypted correspondence, identify the OpenPGP key that lets you read the retained messages. A public-key export is useful for correspondents, but it is not the secret-key backup needed for your own recovery.
Identify the key and the required artifact
In Thunderbird's account settings, inspect End-to-End Encryption for the relevant address. Note the personal key's public fingerprint in your recovery inventory. If the account has used several keys over time, investigate which ones protected the older correspondence you must retain.
Open Tools, OpenPGP Key Manager, select your own key, and use File, Backup secret key. Export public key is a different choice. Thunderbird also exposes these actions through the personal key's details in the account's encryption settings.
Store the secret backup in an appropriately protected location separate from the computer being retired. Follow the backup dialog's protection prompts and retain any required recovery password securely. Do not attach the secret file to a support request or publish it alongside a public fingerprint.
Check recovery while the working installation still exists
Arrange an approved recovery test on a trusted destination that does not overwrite the working setup. Thunderbird's account encryption settings provide Add Key and an import option. Import only your own backed-up secret key and compare its identity with the inventory.
Use retained encrypted correspondence that you are entitled to access to check that the recovered setup can actually read the expected material. Choose examples from different periods if keys changed. Merely seeing an email address beside an imported key is weaker evidence than opening the intended message.
If the test fails, keep the original computer and key material intact while investigating. Creating a fresh key should not be treated as proof that historical messages are recoverable.
Record which examples passed, the destination used and where the protected backup is held. Keep passwords and secret-key contents out of that record. Preserve the messages themselves through the appropriate mailbox backup process as well: exporting a key does not collect the correspondence. Retire the original installation only after both the retained messages and their required keys have a verified recovery path.
Sources: Thunderbird documentation, Thunderbird documentation.