A keyspace you cannot search
A monoalphabetic substitution replaces each letter with another, consistently, using a scrambled alphabet as the key. There are 26 factorial such alphabets — roughly 403 septillion. Trying them all is not an option now and will not be an option ever. And yet these ciphers fall in seconds, because the keyspace does not need to be searched exhaustively; it needs to be climbed.
Hill climbing
The solver starts with a guess built from letter frequencies: the most common
ciphertext letter is provisionally E, the next T, and so on down
the ETAOIN SHRDLU ordering. That guess is usually wrong in detail but roughly
right in shape.
Then it improves. Swap two letters in the key, rescore the decryption with the trigram model, and keep the swap if the score went up. Repeat over every pair until no swap helps. That yields a local optimum — often the answer, sometimes a near-miss where a couple of letters are transposed.
Escaping local optima
To avoid getting stuck, the search restarts repeatedly from perturbed copies of the
best key found so far, keeping whichever run scores highest. A final polish pass changes
the objective, scoring partly on how many genuine English words appear, which is what
separates confusable letters such as B, V and M that
sit in similar trigram contexts.
Doing it by hand
If you would rather solve it yourself: single-letter words are A or
I. The most common three-letter word is THE, which also hands you
the two most common letters. Doubled letters are usually LL, EE,
SS, OO or TT. An apostrophe followed by one letter is
nearly always S or T. From four or five confirmed letters the rest
usually collapses quickly.
Frequently asked questions
How long does the ciphertext need to be?
About 60 letters is the practical minimum and 150 or more is comfortable. Unlike Caesar, there are 26 factorial possible keys, so the search relies on letter statistics and short texts simply do not contain enough of them.
Does it handle keyword-generated alphabets?
Yes, implicitly. The solver searches for the mapping itself and does not care how the key alphabet was produced, so keyword ciphers, random alphabets and keyed Caesar variants are all the same problem to it.
Why is one or two letters wrong in the output?
Rare letters like J, Q, X and Z appear too infrequently for the statistics to place them confidently, so they sometimes swap. The text is usually readable anyway and the correct letter is obvious from context.
Will it solve a newspaper cryptogram?
Usually yes, if you paste the whole puzzle. Cryptograms preserve word boundaries, which makes them easier than the continuous-block ciphertext this solver is designed for.