Onyx Mail Warrant Canary

A periodic PGP-clearsigned statement. Trust state is current only when the artifact is present, within its validity period, signed, and linked to a valid canonical hash-chain state.

Trust State

Current

Fail-closed canonical assessment

Validity Window

28 days

Next update: 2026-08-24

Signing Key

F60C F128 EE34 35F9 A4D5 3850 3421 FCA1 7ADF 0933

Compare all 40 hexadecimal characters

Recent Hash-Chain Records

The latest five rotation records are shown. Local PGP verification of the clearsigned artifact remains the authoritative user procedure.

Rotation Ledger

Most recent record first
#152026-07-2500:00:08 UTCrotation
Current record
Key ID:3421FCA17ADF0933
Hash:dfbc9e26e732d41226984fdbd89b3c95...
Previous:0988b3bbce5e1bcee095c8d2aceabbd5...

Exact Current Clearsigned Artifact

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Onyx Mail Warrant Canary
========================
Status Date: 2026-07-25 00:00:07 UTC
Next Update: 2026-08-24
Rotation: 13

As of July 25, 2026, Onyx Mail affirms:

1. We have received 0 National Security Letters
2. We have received 0 FISA court orders
3. We have received 0 gag orders preventing disclosure
4. We have received 0 law enforcement data requests
5. No backdoors have been installed in our systems
6. We maintain full control of our infrastructure

This statement will be updated monthly.
Absence of update should be considered a dead canary.

VERIFICATION DATA:
Signing Key: 7ADF0933
Current Hash: 6ab582f6cbeb38d1
Previous Hash: 0988b3bbce5e1bce
Chain Position: 13 of 13

Contact: [email protected]
Timestamp: 1784937607
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3KS/uLAo5zWWQhD/i7SThF7ReqwFAmpj/IcACgkQi7SThF7R
eqwk2Q//dH5AMxPlPL8bIfIwlHVJIs1fqhmmNp412BBLya00OYre/my9qiT1U4zZ
ZfAWO91ZiSpf4vZHSLFUFUwA07/Fe1qShezCnIsbppWm9A7YF4zjbhb0lQP8z9Ns
JI8n83t8N7uMDe/nhvEmcRJ9hOkhmThKcONbTPRzSR4+10D1a8gjDvb/3laabcvk
on+XvWH+vzdeaw4ARjuAfCDqMNr3fgg9psQUV5KGsWdMVCMvMW2yYdj5DGcGHVJW
+dxxqz9gN/icMEy+k2PyBE3mt8fr+56XDnRkKSxLmH4sk/6hknFM5mXb1uFmQHSE
s8/Dqb4ToPOvVIe8W0b+Ilhz8Auw2RZANkWqszp4BNbycUBQQ8GCq4SzHX4T6607
4O/FIY8HiQB8hRjDzL/S72G6AuW9jm+jqUf+/Ht9Kg+T+fZOODEbGRrWV/t87WDa
Wkshdo8VXxTCJ6PSO2l/Xk4TxX3ishwUvQ1Y7hpAqN+ypSZBoKG0Z4JAUsWCn1/0
3UZjnw1L1qd5dNVx4qy2aE1miUY4D0pmTdv9qFv2drXzfriAwFNeeszhKv5daCph
cqiLJR9ZhgcdJWhuj0wnR/Vyl72cmba6AiY+wphBfvipLrYMfrkG6j7MTHECHLCm
6d/hiN6t/2gKfAvxiTULkX3+JZItizRZ94q6DRmRpgnRUJmZFss=
=BJ3+
-----END PGP SIGNATURE-----

Verify with GnuPG

1

Retrieve the key

curl -fSLo onyxmail-canary-public.asc https://onyxmail.net/canary/public.asc gpg --show-keys --fingerprint onyxmail-canary-public.asc

Compare the complete fingerprint shown above through another trusted path before import.

2

Retrieve the artifact

curl -fSLo current_clearsigned.asc https://onyxmail.net/.well-known/canary/current_clearsigned.asc

Do not alter whitespace or line endings before verification.

3

Verify locally

gpg --import onyxmail-canary-public.asc gpg --verify current_clearsigned.asc

Confirm a good signature from the expected full fingerprint, then inspect the status and next-update dates inside the signed text.