Join the Official Discord

Playfair cipher

Enter the keyword to build the 5×5 square, then encode or decode. Every pair is shown.

Mode
Result
Key square

Pair by pair

    How the Playfair cipher works

    Playfair encrypts letters in pairs, not one at a time. That flattens the letter frequencies a simple substitution leaves behind, and it's why the British used it as a field cipher into the First World War. Charles Wheatstone invented it in 1854. It's named after Lord Playfair, who promoted it.

    1. Build the square

    Write the keyword into a 5×5 grid, skipping any letter you've already used, then fill the rest of the grid with the remaining letters in order. There are only 25 cells, so I and J share one. The tool draws the square for your keyword and highlights the letters that came from it.

    2. Split the message into pairs

    Break the message into two-letter pairs. If a pair would be a doubled letter, put an X between them: BALLOON becomes BA LX LO ON. If one letter is left over at the end, pad it with X.

    3. Encrypt each pair

    • Same row: take the letter to the right of each, wrapping round.
    • Same column: take the letter below each, wrapping round.
    • Anywhere else: the two letters mark opposite corners of a rectangle. Take the other two corners, keeping each letter's own row.

    Decoding runs the same rules backwards: left instead of right, up instead of down. Rectangles work the same both ways. The “Pair by pair” strip under the tool shows each step.

    Spotting Playfair

    An even number of letters, no J anywhere, and no pair that's the same letter twice. Ciphertext is often written in pairs as well. Breaking Playfair without the keyword is much harder than breaking a Caesar or Vigenère cipher, so in a puzzle the keyword is usually hidden somewhere else. Look for it.

    Step-by-step guide How to solve a Playfair Cipher by hand, with a worked example

    Questions

    How does the Playfair cipher work?

    The keyword, followed by the rest of the alphabet, fills a 5×5 square with I and J sharing a cell. The message is split into pairs. Pairs on the same row shift right, pairs in the same column shift down, and anything else swaps to the other corners of its rectangle.

    Why is there an X in my decoded message?

    Playfair can't encode a pair of identical letters, so an X goes between them (BALLOON becomes BA LX LO ON), and another X pads an odd-length message. Read past the X's when you decode.

    What happened to the J?

    The square only has 25 cells, so J is merged with I. A decoded I may have been a J.

    How do I recognise a Playfair cipher?

    Even number of letters, no J, and no pair (letters 1–2, 3–4, …) made of the same letter twice. The cipher identifier checks for all three.

    More cipher tools

    See all cipher tools →