---
title: "What Is a Warrant Canary? How to Read and Verify One"
description: "A warrant canary is a signed statement that a provider has received no secret orders. What a good one contains, how to verify it with GnuPG, and its limits."
url: https://offshoreserv.com/blog/what-is-a-warrant-canary
lang: en
updated: 2026-09-26
source: HTML page at the url above (canonical); this is its Markdown version
---

[Privacy & payments](https://offshoreserv.com/blog/category/privacy-payments)

# What is a warrant canary? How to read and verify one

A warrant canary lets a provider's silence speak when a gag order forbids words. Here is what one contains, how to verify ours with GnuPG, and what a missing canary does and does not prove.

26 September 2026 9 min read By the OffshoreServ team

Key takeaways

- A warrant canary says what a provider has not received. When a secret order arrives, it stops being renewed.
- It rests on an untested theory: a gag can compel silence, but courts have not upheld compelled false statements.
- To verify one, check the key's fingerprint, then the signature with gpg, then the dates.
- A late or missing canary is a reason to investigate, not proof of a raid.

**A warrant canary is a statement, published on a regular schedule, that a service provider has not received certain secret legal orders, such as gagged requests for user data.** If such an order arrives, the provider stops renewing the statement instead of lying. Readers who notice the missing update learn what the provider is not allowed to say.

OffshoreServ, which runs [offshore VPS](https://offshoreserv.com/offshore-vps), dedicated, RDP and GPU servers in seven countries, publishes a PGP-signed canary every quarter. Below: what a good canary contains, how to verify ours with GnuPG, and what a stale one does and does not prove.

## Warrant canary meaning

The name comes from the canaries that coal miners once carried underground: a bird that stopped singing warned of gas. A warrant canary works the same way. The provider says "we have received no secret orders" on a fixed schedule. On the day it can no longer say so truthfully, it says nothing, and the silence is the warning.

The Electronic Frontier Foundation defines it as "a regularly published statement that a service provider has not received legal process that it would be prohibited from saying it had received".

## Why warrant canaries exist

Some legal orders forbid the recipient to mention them. In the United States, the FBI can obtain subscriber and transactional records from a communications provider with a National Security Letter. When the FBI certifies that secrecy is needed, [18 U.S.C. § 2709](https://www.law.cornell.edu/uscode/text/18/2709) forbids the provider to "disclose to any person" that the FBI sought or obtained them. [EFF's warrant canary FAQ](https://www.eff.org/deeplinks/2014/04/warrant-canary-faq) adds orders of the Foreign Intelligence Surveillance Court and subpoenas that come with a gag order.

A canary rests on the difference between silence and speech. A gag can compel silence. EFF argues that it cannot compel a lie, because the First Amendment protects against compelled speech: its example is a ruling that New Hampshire could not require drivers to display "Live Free or Die" on their license plates. Courts, it notes, have not upheld compelled false statements.

Timing does the rest. In EFF's words, "the gag order only attaches after the ISP has been served with the gagged legal process." Before that, a provider may say "none". Afterwards, a US provider may publish national security requests only in ranges, such as 0 to 999 per half-year, under [50 U.S.C. § 1874](https://www.law.cornell.edu/uscode/text/50/1874), added by the USA FREEDOM Act of 2015.

## What a good warrant canary contains

Look for five elements. The last column shows how ours measures up.

| Element | Why it matters | In our canary |
| --- | --- | --- |
| A date | Shows how current it is | 25 September 2026 |
| The next update date | Makes a missed renewal obvious | By 25 December 2026, then every quarter |
| Specific statements | Shows what the silence would cover | No national security letters, FISA or similar secret orders, gag orders, warrants or orders for customer data, or requests for monitoring or backdoors; no customer data handed to any third party |
| A signature | Proves who wrote it and that nothing changed | PGP, in a separate file, canary.txt.asc |
| A proof of freshness | Shows it was written on or after its date | Not included: ours relies on the signed date and the schedule |

A freshness proof is something nobody could know earlier, such as that day's news headlines or a recent Bitcoin block hash. Without one, a provider could sign future canaries in advance. The time stamp in a PGP signature does not settle this, because it comes from the signer's own clock.

### Warrant canary examples

- **rsync.net**, a cloud storage provider, publishes a [weekly signed canary](https://www.rsync.net/resources/notices/canary.txt) with news headlines and sports scores, which "serves to demonstrate that that update could not have been created prior to that date".
- **Riseup** missed a renewal in 2016 and later explained why, as described below.
- **Apple** once wrote a canary into a transparency report. EFF's FAQ quotes it: "Apple has never received an order under Section 215 of the USA Patriot Act."

## How to verify a warrant canary, step by step

You need GnuPG. [gnupg.org](https://gnupg.org/download/) notes that it is part of the base system of common Linux distributions; on Windows, use Gpg4win, and on macOS a build such as Mac GPG. The method works for any provider; our [warrant canary page](https://offshoreserv.com/warrant-canary) sets out our schedule.

### 1. Import our key and check its fingerprint

```
curl -sO https://offshoreserv.com/pgp/security.asc
gpg --import security.asc
gpg --fingerprint 9115B17ECE0944BCC461285FF3826B4FF2F38213
```

gpg prints the fingerprint in ten groups of four characters:

```
pub   ed25519 2026-09-25 [SC] [expires: 2028-09-24]
      9115 B17E CE09 44BC C461  285F F382 6B4F F2F3 8213
uid           [ unknown] OffshoreServ (offshoreserv.com)
sub   cv25519 2026-09-25 [E] [expires: 2028-09-24]
```

Compare it character by character with our [PGP key page](https://offshoreserv.com/pgp) and the canary itself. A fingerprint read on the same page as the key only proves that the page was not altered in transit, so also check it through a second channel, such as the page loaded over Tor or a canary you verified before.

### 2. Download the canary and its signature

```
curl -sO https://offshoreserv.com/canary.txt
curl -sO https://offshoreserv.com/canary.txt.asc
```

`canary.txt` is the statement. `canary.txt.asc` is a detached signature, a separate file that signs it. Some providers publish a clearsigned file instead, with text and signature together.

### 3. Verify the signature

```
gpg --verify canary.txt.asc canary.txt
```

Name the signature file first and the text file second: the [GnuPG manual](https://www.gnupg.org/documentation/manuals/gnupg/Operational-GPG-Commands.html) calls letting gpg guess the data file "strongly discouraged". A valid canary gives these lines, with the time in your own time zone:

```
gpg: Signature made Fri Sep 25 17:35:24 2026 GMT
gpg:                using EDDSA key 9115B17ECE0944BCC461285FF3826B4FF2F38213
gpg: Good signature from "OffshoreServ (offshoreserv.com)" [unknown]
Primary key fingerprint: 9115 B17E CE09 44BC C461  285F F382 6B4F F2F3 8213
```

gpg also warns that the key "is not certified with a trusted signature". That only means you have not certified it in your own web of trust, as the [GnuPG FAQ](https://www.gnupg.org/faq/gnupg-faq.html) explains; your fingerprint check is what establishes trust. Change one character of `canary.txt` and gpg reports `BAD signature` and exits with an error.

### 4. Check the dates

`canary.txt` states its date, 25 September 2026, and the next one, due by 25 December 2026; the "Signature made" date should match. Past the due date with no new statement, the canary is stale. Keep the files you verified, so you can see whether the next canary quietly drops a statement.

## What a missing or stale canary means

Three changes deserve attention: no renewal by the due date, a canary that disappears or stops verifying against the published key, and a new version that drops a statement. Any of them may mean that the provider can no longer make the statement truthfully.

It proves no more than that. Canaries lapse for ordinary reasons too, such as a holiday, an expired key or a mistake. Riseup's canary was "not updated on time" in the winter of 2016. In a [statement of February 2017](https://riseup.net/en/about-us/press/canary-statement), Riseup explained that it had complied with two sealed FBI warrants, about an account used by an international DDoS extortion ring and one used for ransomware, and that "the canary was so broad that any attempt to issue a new one would be a violation of a gag order". It then narrowed its canary to "significant events that could compromise the security of Riseup users".

Treat a stale canary as a prompt, not a verdict: verify again from a fresh download, read the provider's transparency report and notices, allow a short grace period, then decide whether to move what matters to you. Never rely on a screenshot or someone else's copy.

## The legal limits of warrant canaries

In the United States, a truthful canary is legal: "there is no law that prohibits a service provider from reporting all the legal processes that it has not received," EFF writes. What happens after a gagged order arrives is untested. Asked whether any case has upheld warrant canaries, EFF answered "Not yet", and it advises a provider whose canary is triggered to ask a court to rule that it cannot be required to publish false information.

The closest US case concerns transparency reports, and the provider lost. In [*Twitter v. Garland*](https://cdn.ca9.uscourts.gov/datastore/opinions/2023/03/06/20-16174.pdf), decided in March 2023, the Ninth Circuit upheld the FBI's redactions of the aggregate numbers of national security requests that Twitter wanted to publish for July to December 2013.

Elsewhere, canaries are untested in court in most countries, and secrecy rules differ. A canary is a signal, not a guarantee: it covers only the orders it lists, it cannot speak for the data centers and networks a provider relies on, and it is only as honest as the people who sign it. This is general information, not legal advice; check the law of your own jurisdiction. Our guide to [whether offshore hosting is safe](https://offshoreserv.com/blog/is-offshore-hosting-safe) covers other signals worth checking.

## Warrant canary vs transparency report

A transparency report counts the requests a provider received and what it did about them. A canary covers what a report may not mention at all.

| Aspect | Warrant canary | Transparency report |
| --- | --- | --- |
| What it says | That certain secret orders have not been received | How many requests arrived, by type, and how many were actioned |
| What silence means | A missed renewal is itself the signal | Nothing; the counts are published either way |
| Legal pressure point | Gag orders attached to specific requests | Limits on disclosing numbers, such as US reporting ranges |
| How you check it | A signature you verify yourself | Figures you compare over time |
| At OffshoreServ | Quarterly; next due by 25 December 2026 | Quarterly, within 15 days of quarter end; first report covers Q3 2026 |

Our [transparency report](https://offshoreserv.com/transparency-report) publishes counts only, never customer data. Our [law enforcement guidelines](https://offshoreserv.com/law-enforcement) explain that we act on valid orders from an authority competent where the server runs, and tell the customer in the client area unless the law forbids it. Our [privacy policy](https://offshoreserv.com/privacy-policy) lists what exists to hand over: an email address, billing and service records, sign-in records without IP addresses, and no traffic logs.

## Frequently asked questions

### What is a warrant canary?

A warrant canary is a statement that a service provider publishes on a fixed schedule, saying it has not received certain secret legal orders. If such an order arrives, the provider stops renewing the statement instead of lying, so the missing update itself warns readers. A good canary is dated, signed and specific.

### How do I verify a warrant canary?

Import the provider's public key and check its fingerprint through a second channel. Download the canary and its signature, run `gpg --verify` with the signature file first, and look for "Good signature" from the expected key. Then check that the signed date is recent and the announced renewal date has not passed.

### What does it mean if a warrant canary disappears?

It may mean that the provider received an order it cannot mention, but it proves nothing on its own: canaries also lapse through mistakes, expired keys or holidays, and a lapse says nothing about how many users are concerned. Verify again from a fresh download and allow a short grace period before you act.

### Are warrant canaries legal?

In the United States, publishing a truthful canary is legal: no law forbids a provider to list orders it has not received, and a gag attaches only once an order is served. Whether a court could force a provider to keep renewing its canary afterwards remains untested. Other countries have their own secrecy rules, so check your jurisdiction.

### How often should a warrant canary be updated?

Often enough that a missed update is noticed quickly, and always on a published schedule. rsync.net renews weekly; we renew every quarter, with the next statement due by 25 December 2026. EFF suggests leaving a few months between a report and the period it covers, so that a triggered canary can be taken to court in time.

**Host it where the law is on your side.**

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

## More from the blog.

- [Privacy & payments How to buy a VPS anonymously (and legally), step by step Five steps to a VPS that is not tied to your name, what the host can still see, and the mistakes that quietly undo your privacy.26 September 2026 9 min read](https://offshoreserv.com/blog/buy-a-vps-anonymously)
- [Privacy & payments How to buy a VPS with crypto: BTC, ETH, XMR, USDT and SOL From the deploy page to a running server: which coin to pick, how the top-up, rate lock and bonus work, and what to do when a payment goes wrong.26 September 2026 9 min read](https://offshoreserv.com/blog/buy-a-vps-with-crypto)
- [Privacy & payments No-KYC hosting explained: what it is and why it's legal What KYC means at a hosting company, why most hosts ask for ID, what no-KYC hosting really covers, and why it is legal in most countries.26 September 2026 9 min read](https://offshoreserv.com/blog/no-kyc-hosting-explained)

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
