Onyx Mail Warrant Canary

A periodic PGP-clearsigned statement. Trust state is current only when the artifact is present, within its validity period, signed, and linked to a valid canonical hash-chain state.

Trust State

Current

Fail-closed canonical assessment

Validity Window

13 days

Next update: 2026-09-23

Signing Key

F60C F128 EE34 35F9 A4D5 3850 3421 FCA1 7ADF 0933

Compare all 40 hexadecimal characters

Recent Hash-Chain Records

The latest five rotation records are shown. Local PGP verification of the clearsigned artifact remains the authoritative user procedure.

Rotation Ledger

Most recent record first
#162026-08-2400:00:15 UTCrotation
Current record
Key ID:3421FCA17ADF0933
Hash:7f10de19c8b0d866ae474a35cd60d56c...
Previous:dfbc9e26e732d41226984fdbd89b3c95...

Exact Current Clearsigned Artifact

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Onyx Mail Warrant Canary
========================
Status Date: 2026-08-24 00:00:14 UTC
Next Update: 2026-09-23
Rotation: 13

As of August 24, 2026, Onyx Mail affirms:

1. We have received 0 National Security Letters
2. We have received 0 FISA court orders
3. We have received 0 gag orders preventing disclosure
4. We have received 0 law enforcement data requests
5. No backdoors have been installed in our systems
6. We maintain full control of our infrastructure

This statement will be updated monthly.
Absence of update should be considered a dead canary.

VERIFICATION DATA:
Signing Key: 7ADF0933
Current Hash: ef9f420452c1f6b0
Previous Hash: dfbc9e26e732d412
Chain Position: 13 of 13

Contact: [email protected]
Timestamp: 1787529614
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3KS/uLAo5zWWQhD/i7SThF7ReqwFAmqLiY4ACgkQi7SThF7R
eqylOA/+KwqgB2VQAWDliwGgDNADjQ8QGEOjpD3ZFAdAsOA/ARS0ntvg1kJoFo3c
Ni9P3jA2UNyxSirngMsw+8yeQfxOZsz2K/53aMcrLia8ShIxN++g5NuBNR2a+z84
myZeQAXvJKNu4+ItNQV5upPdZ2Q2AZZeht8Rs6xYLZcYhADfdSLbrUn2wfnVcgxf
p/CRPFvvEcKFdQ2ivuRu2pFdDztKYo7ruH5BmATijF/B0T/GtgB9cqbgh+rIq93u
rlUr0v4WdHNM60CADo10mGfbfusw7lbqnf9hW78T1IypAkZ/4JAWRvJAK3ClRo2M
PxAX7IS+0CujGIYQsf+eoxWy8/zVOe3ZAjUHgghuEVDqVGg83VWl2RY61UkFXfry
6OzreSXursSet6OUljfgiiC/dsHoEugVVdFhleUPvGJ089IRrkAXLrJIPIWxPKWY
70fqPIr9WicawickdNOwrAdAd1O4vrhxZj+Pe8jJmdrRv0/j5AzAkJp6eQtE/ey0
7FA7Zsoxs25bUIWLCD54LAeh9jQVEkTrgoz7UATwpon08Xi4Dx3JMQIiXH0NvckM
uO562FEzYUTg43jLBsRnyaY6zhwZWHjBPwQdo60rGLtum1hMAjf1mOhEWIs3csEg
gH+iYoStduhNuOzqE8t6v4jwoGoT9EruILs/X7tZjAu97UcGEzU=
=nYm6
-----END PGP SIGNATURE-----

Verify with GnuPG

1

Retrieve the key

curl -fSLo onyxmail-canary-public.asc https://onyxmail.net/canary/public.asc gpg --show-keys --fingerprint onyxmail-canary-public.asc

Compare the complete fingerprint shown above through another trusted path before import.

2

Retrieve the artifact

curl -fSLo current_clearsigned.asc https://onyxmail.net/.well-known/canary/current_clearsigned.asc

Do not alter whitespace or line endings before verification.

3

Verify locally

gpg --import onyxmail-canary-public.asc gpg --verify current_clearsigned.asc

Confirm a good signature from the expected full fingerprint, then inspect the status and next-update dates inside the signed text.