+ <h3>Verification of Downloads</h3>
+
+ <p>
+ All published tarballs are cryptographically signed with an OpenPGP implementation (such as GnuPG).
+ The signatures are distributed alongside the tarballs.
+ The signatures are created with keys belonging to the developers.
+ The keys can be found in our
+ <a href="https://downloads.exim.org/Exim-Maintainers-Keyring.asc">maintainers keyring</a>.
+ (Please crosscheck these keys with keys you can find at other sources.)
+ </p>
+ <p>
+ The exim.org domain supports <a href="https://wiki.gnupg.org/WKD">the WKD mechanism</a> for OpenPGP key retrieval.
+ </p>
+