Hello, I have two problems:

  1. I read in the website this : You should only trust downloads from our official website or GitHub page:
    2.Official website:*
    3.GitHub:* But the trezor suite installer is downloaded from: I should be absolutely sure I am downloading from the correct site and this does not looks ok.
  2. Also I can not verify the download: "the signature of this message is valid but untrusted” Thanks for your help.
Hi @Bitcoiner65,

If you only need the latest publicly released version, download the desktop version from or use the web version at

That’s a GPG thing. What it’s saying is:

  1. You gave me a public key…
  2. That public key does match the download.
  3. So whoever owns that public key actually did sign the package.
  4. However, I don’t know where you found the public key in the first place
  5. By default, I don’t trust it unless you explicitly tell me to.

See this:
Check that the key fingeprint matches. If yes, that’s your confirmation that this is OK.

I have the same problem as @Bitcoiner65 mentioned at 2.nd point.
The “Trezor-Suite-23.4.2-win-x64.exe.asc” file shows that the Trezor-Suite-23.4.2-win-x64.exe was not manipulated, but the signature (public key) from the creator (Trezor) is missing.
Could You(Trezor support) upload the public key on the page?
To check that the “satoshilabs-2021-signing-key.asc” was created from Trezor.