Step-by-Step PGP Verification
Step 1 — Install GPG
Install GNU Privacy Guard on your system. On Linux: sudo apt install gnupg. On Windows: download Gpg4win from gpg4win.org. On macOS: install GPGTools from gpgtools.org. GPG is the standard tool for PGP key management and signature verification.
Step 2 — Import the Nexus Market PGP Key
Obtain the official Nexus Market administrator PGP public key from the official Dread subdread (d/NexusMarket). Import it into your GPG keyring. Verify the key fingerprint against multiple independent sources before trusting it.
Step 3 — Find the Signed Mirror Announcement
Navigate to the official Nexus Market Dread subdread and locate the most recent PGP-signed mirror announcement posted by the verified admin account. The post will contain a PGP signed block with the current list of official onion addresses.
Step 4 — Verify the Signature
Copy the entire PGP signed block including the BEGIN and END markers. Save it as a text file and run: gpg --verify signed_announcement.txt. A valid signature will show "Good signature from Nexus Market Admin". If verification fails, do not use the listed addresses.
Step 5 — Compare Onion Addresses
After successful signature verification, compare the onion addresses in the signed announcement character by character against the addresses shown on this page. v3 onion addresses are 56 characters long — verify every single character. A single character difference indicates a phishing clone.
Red Flags — Signs of a Phishing Clone
| Red Flag | What It Means | Action |
|---|---|---|
| Address not in PGP-signed post | Not an official Nexus Market mirror | Do not use |
| Invalid PGP signature | Message tampered or wrong key | Do not use |
| Address shared via chat/forum | Cannot verify source authenticity | Verify first |
| Login page looks different | Possible phishing clone | Verify address |
| Asks for unusual information | Likely phishing or scam | Exit immediately |