Evaluation of Email Communication Security Using OpenPGP-Based End-to-End Encryption on Mozilla Thunderbird

DOI: https://doi.org/10.33650/jeecom.v8i1.16094
Authors

(1) * Bagus Setya Putra   (Universitas Stikubank)  
        Indonesia
(2)  Siska Yunitasari   (Universitas Stikubank)  
        Indonesia
(3)  Suci Larasati   (Universitas Stikubank)  
        Indonesia
(4)  Fani Indra Gunawan   (Universitas Stikubank)  
        Indonesia
(5)  Eka Ardhianto   (Universitas Stikubank)  
        Indonesia
(6)  Aji Supriyanto   (Universitas Stikubank)  
        Indonesia
(*) Corresponding Author

Abstract


Email remains a primary communication channel across academic, professional, governmental, and personal domains. Despite its widespread adoption, conventional email infrastructure continues to exhibit fundamental security vulnerabilities, including susceptibility to phishing attacks, unauthorized message interception, identity spoofing, and unintended data disclosure. Although Transport Layer Security (TLS) has become the de facto standard for securing email transmission between clients and servers, its protection is confined to the transport layer and does not extend to message content stored on mail servers or processed by third-party providers. This study presents an empirical evaluation of OpenPGP-based end-to-end encryption implemented through Mozilla Thunderbird as a mechanism to address the limitations of transport-layer-only security. The research employs a comparative experimental design, contrasting standard TLS-only communication against OpenPGP-encrypted communication across multiple message size scenarios using packet-level analysis via Wireshark. Evaluation parameters encompass confidentiality, message integrity, sender authentication, payload visibility in TCP stream analysis, and transmission overhead across varied email payloads. The results demonstrate that while TLS-only communication still exposes identifiable SMTP metadata during packet inspection, OpenPGP transforms email content into high-entropy ASCII-armored ciphertext that resists direct interpretation even under deep packet inspection. Furthermore, cryptographic digital signatures successfully verified sender identity and ensured message integrity across all tested scenarios. Although OpenPGP introduces measurable transmission overhead averaging approximately 117% depending on message size, the security benefits substantially outweigh this trade-off. These findings establish OpenPGP as a robust and practical solution for enhancing end-to-end email security in modern communication environments.


Keywords

OpenPGP; End-to-End Encryption; Email Security; Mozilla Thunderbird; Digital Signature



Full Text: PDF



References


F. Greco, G. Desolda, P. Buono, and A. Piccinno, ‘Enhancing Phishing Defenses: The Impact of Timing and Explanations in Warnings for Email Clients’, Computer Standards & Interfaces, vol. 93, p. 103982, Apr. 2025, doi: 10.1016/j.csi.2025.103982.

M. F. Veit, O. Wiese, F. L. Ballreich, M. Volkamer, D. Engels, and P. Mayer, ‘SoK: The past decade of user deception in emails and today’s email clients’ susceptibility to phishing techniques’, Computers & Security, vol. 150, p. 104197, Mar. 2025, doi: 10.1016/j.cose.2024.104197.

Y. Sakurai, T. Watanabe, T. Okuda, M. Akiyama, and T. Mori, ‘Identifying the Phishing Websites Using the Patterns of TLS Certificates’, JCSANDM, Apr. 2021, doi: 10.13052/jcsm2245-1439.1026.

J. S. Buruaga, R. B. Méndez, J. P. Brito, and V. Martin, ‘Hybrid Quantum-Safe integration of TLS in SDN networks’, Computer Networks, vol. 267, p. 111355, Jul. 2025, doi: 10.1016/j.comnet.2025.111355.

J. A. Montenegro, R. Rios, and J. Lopez-Cerezo, ‘A performance evaluation framework for post-quantum TLS’, Future Generation Computer Systems, vol. 175, p. 108062, Feb. 2026, doi: 10.1016/j.future.2025.108062.

C. Döberl, W. Eibner, S. Gärtner, M. Kos, F. Kutschera, and S. Ramacher, ‘Quantum-resistant End-to-End Secure Messaging and Email Communication’, in Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento Italy: ACM, Aug. 2023, pp. 1–8. doi: 10.1145/3600160.3605049.

E. D. Ansong, S. B. Osei, and G. Agyapong, ‘The Evolution of Email Encryption: From PGP to Modern Standards’, IJCA, vol. 186, no. 56, pp. 28–34, Dec. 2024, doi: 10.5120/ijca2024924283.

A. Reuter, A. Abdelmaksoud, K. Boudaoud, and M. Winckler, ‘Usability of End-to-End Encryption in E-Mail Communication’, Front. Big Data, vol. 4, p. 568284, Jul. 2021, doi: 10.3389/fdata.2021.568284.

M. Z. Sabir and M. Yousaf, ‘Design and Implementation of an End-to-End Web based Trusted Email System’, Procedia Computer Science, vol. 141, pp. 231–238, 2018, doi: 10.1016/j.procs.2018.10.176.

J. Barbosa, D. Gomez, O. Yadgar, M. Fauser, and P. Zhang, ‘Application of Digital Signature to Attack Detection in a DC Motor Control System’, IFAC-PapersOnLine, vol. 58, no. 4, pp. 723–728, 2024, doi: 10.1016/j.ifacol.2024.07.305.

M. Al-Khalidi, R. Al-Zaidi, T. Ali, S. Khan, and A. K. Bashir, ‘AI-optimized elliptic curve with Certificate-Less Digital Signature for zero trust maritime security’, Ad Hoc Networks, vol. 166, p. 103669, Jan. 2025, doi: 10.1016/j.adhoc.2024.103669.

J. Wei, X. Chen, J. Wang, X. Hu, and J. Ma, ‘Enabling (End-to-End) Encrypted Cloud Emails With Practical Forward Secrecy’, IEEE Trans. Dependable and Secure Comput., vol. 19, no. 4, pp. 2318–2332, Jul. 2022, doi: 10.1109/TDSC.2021.3055495.

M. T. Adithia, N. Elianora, and M. Veronica, ‘Document Verification And Authentication By Using Password Based Qr Code Signature With Rsa 2048, Aes Encryption, And Sha-256’, J. Tek. Inform. (JUTIF), vol. 7, no. 2, pp. 1981–1995, Apr. 2026, doi: 10.52436/1.jutif.2026.7.2.5484.

F. Nuraeni, D. Kurniadi, and D. N. Rahayu, ‘IMPLEMENTATION OF RSA AND AES-128 SUPER ENCRYPTION ON QR-CODE BASED DIGITAL SIGNATURE SCHEMES FOR DOCUMENT LEGALIZATION’, J. Tek. Inform. (JUTIF), vol. 5, no. 3, pp. 675–684, May 2024, doi: 10.52436/1.jutif.2024.5.3.1426.

V. Mulder, A. Mermoud, V. Lenders, and B. Tellenbach, Eds, Trends in Data Protection and Encryption Technologies. Cham: Springer Nature Switzerland, 2023. doi: 10.1007/978-3-031-33386-6.

L. Bruseghini, D. Huigens, and K. G. Paterson, ‘Victory by KO: Attacking OpenPGP Using Key Overwriting’, in Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Los Angeles CA USA: ACM, Nov. 2022, pp. 411–423. doi: 10.1145/3548606.3559363.

L. De Feo, B. Poettering, and A. Sorniotti, ‘On the (In)Security of ElGamal in OpenPGP’, in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event Republic of Korea: ACM, Nov. 2021, pp. 2066–2080. doi: 10.1145/3460120.3485257.

A. Faruq, K. Khaeruddin, and M. Lestandy, ‘Sistem Keamanan Multi Mail Server dengan Teknik Enkripsi OPENPGP pada Zimbra Exchange Open Source Software’, JTIIK, vol. 7, no. 3, p. 493, May 2020, doi: 10.25126/jtiik.2020731869.

F. Armknecht and A. Dewald, ‘Privacy-preserving email forensics’, Digital Investigation, vol. 14, pp. S127–S136, Aug. 2015, doi: 10.1016/j.diin.2015.05.003.

A. Bruen, M. Forcinito, and J. McQuillan, Cryptography, Information Theory, and Error‐Correction: A Handbook for the 21st Century, 1st edn. Wiley, 2021. doi: 10.1002/9781119582397.

A. Anugurala and A. Chopra, ‘Securing and preventing man in middle attack in grid using open pretty good privacy (PGP)’, in 2016 Fourth International Conference on Parallel, Distributed and Grid Computing (PDGC), Waknaghat, India: IEEE, 2016, pp. 517–521. doi: 10.1109/PDGC.2016.7913249.

Z. Zhu, W. Xu, and J. Xu, ‘CoD-DSSE: A practical efficient dynamic searchable symmetric encryption with lightweight clients’, Journal of King Saud University - Computer and Information Sciences, vol. 36, no. 6, p. 102106, Jul. 2024, doi: 10.1016/j.jksuci.2024.102106.

O. A. Qasim and S. Golshannavaz, ‘Data protection enhancement in smart grid communication: An efficient multi-layer encrypting approach based on chaotic techniques and steganography’, e-Prime - Advances in Electrical Engineering, Electronics and Energy, vol. 10, p. 100834, Dec. 2024, doi: 10.1016/j.prime.2024.100834.

B. E. Widodo and A. S. Purnomo, ‘IMPLEMENTASI ADVANCED ENCRYPTION STANDARD PADA ENKRIPSI DAN DEKRIPSI DOKUMEN RAHASIA DITINTELKAM POLDA DIY’, Jurnal Teknik Informatika, vol. 1, no. 2, pp. 69–77, Dec. 2020, doi: 10.20884/1.jutif.2020.1.2.21.

D. Sudha, B. Unhelkar, S. Shankar, and G. Nagarajan, ‘Designing low-power encryption algorithms for end-to-end vehicular data protection in sustainable IoT networks’, Results in Engineering, vol. 28, p. 107474, Dec. 2025, doi: 10.1016/j.rineng.2025.107474.

Y. Filaly, N. Berros, F. El Mendili, and Y. El Bouzekri El Idrissi, ‘A comprehensive survey on big data privacy and Hadoop security: Insights into encryption mechanisms and emerging trends’, Results in Engineering, vol. 27, p. 106203, Sep. 2025, doi: 10.1016/j.rineng.2025.106203.

N. Ricchizzi, P. Alig, N. Schmitz, and J. Pelzl, ‘When classical encryption fails: A non-invasive post-quantum security layer for medical image transfers’, Informatics in Medicine Unlocked, vol. 61, p. 101747, Mar. 2026, doi: 10.1016/j.imu.2026.101747.


Dimensions, PlumX, and Google Scholar Metrics

10.33650/jeecom.v8i1.16094


Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Bagus Setya Putra, Siska Yunitasari, Suci Larasati, Fani Indra Gunawan, Eka Ardhianto, Aji Supriyanto

 
This work is licensed under a Creative Commons Attribution License (CC BY-SA 4.0)

Journal of Electrical Engineering and Computer (JEECOM)
Published by LP3M Nurul Jadid University, Indonesia, Probolinggo, East Java, Indonesia.