Tooleux

Verify an RSA signature using only the public key.

Runs in your browser. Nothing leaves your device.
Verify an RSA signature with a public key. Free, offline, runs entirely in your browser. Read more Show less

What is RSA signature verification?

Verification uses the public key to check that a signature was produced by the matching private key over the given message. If the message or signature has been altered, or if a different key was used, verification fails.

How to use

Paste an RSA public key in PEM format, the original message, and the signature (Base64 or Hex). Choose the same hash and padding used during signing. Click Verify.

FAQ

Why does verification fail?

Common causes: the message has been modified, the signature is corrupted, the wrong public key was used, or the padding/hash scheme doesn't match what was used to sign.

Can I verify with only the public key?

Yes. That's the entire point of public-key signatures: the public key is sufficient for verification, and it does not reveal the private key.

Is my data sent anywhere?

No. Everything runs locally.

Cross-check with openssl

If openssl says the signature is invalid but this tool says it is valid (or vice versa), check the hash algorithm and padding scheme. PSS with a specific salt length is not the same as PKCS#1 v1.5. The signature is also sensitive to any byte difference in the message, including trailing newlines.

Public key (PEM)
Message
Signature (Base64 or Hex)
Result