# Leaked Mailgun API Key? Rotate It and Audit Your Sending

> Mailgun private API key exposed on GitHub? Regenerate it, check sending logs and domains, and protect your reputation. Step-by-step guide.

Source: https://leakwatch.net/secrets/mailgun-api-key

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Mailgun API Key

Messaging · Secret guide

# Leaked Mailgun API Key: what to do in the first hour

High severityDetected onlyLast verified October 2, 2026 · 5 min read

A Mailgun private API key lets whoever holds it send email through your account, as your verified domains. That makes it a phishing tool with your reputation behind it: messages that pass SPF and DKIM for your own domain, delivered to inboxes that trust you. The key can usually also read logs, suppression lists and mailing lists, which contain your customers’ addresses. Replace the key first, then read what was sent.

[Check your GitHub account for leaked secrets — free](/)

Provider

Mailgun

Severity

High

Impact

SaaS account access and billing

Checked live by LeakWatch

No

## What a Mailgun API key looks like

The private API key is a `key-` prefix followed by a 32-character lowercase hexadecimal string:

```text
key-…XXXX   Mailgun private API key (masked)
```

Mailgun has several values that look alike, and only one of them is this secret:

-   The **public validation key** (`pubkey-…`) is only used for the email address validation endpoint from client-side code. It is not meant to be secret.
-   The **webhook signing key** is a separate value used to verify that webhook calls come from Mailgun. If it leaks, an attacker can forge events to your endpoint, but cannot send mail.
-   **SMTP credentials** are a per-domain username and password. They also let someone send mail, but are rotated separately from the API key.

If the value you found is an email-sending key from another provider, see the [SendGrid API key](/secrets/sendgrid-api-key) or [Twilio API key](/secrets/twilio-api-key) guides.

## How Mailgun API keys get leaked

-   **Application config.** A `.env` file, `settings.py` or `config.js` with the key beside the domain name, committed with the rest of a web app.
-   **Transactional email code.** Password-reset and welcome-email helpers written with the key inline to get started.
-   **`curl` examples.** A command passing the private API key to `curl -u` in a README, a runbook, or a cron script.
-   **CI and deployment files.** Workflow files, `docker-compose.yml` and Helm values that pass the key into a container.
-   **Old keys in old branches.** A key that was rotated in the code but remains in history, or that was never rotated at all.

## What to do in the first hour

1.  **Regenerate the private API key.** In the Mailgun dashboard open the account’s *API security* (API keys) settings and regenerate the private key, or delete the exposed key if your account lists several. The old value stops working, so be ready to deploy the new one straight away.
2.  **Deploy the new key.** Put it in a secret manager or environment variable, update every app, cron job and plugin that sends mail, and send a test message.
3.  **Read the sending logs.** In the *Sending* section open *Logs* and look at the period since the exposure. Messages you did not send, unfamiliar recipients, odd subject lines, or a sudden volume spike are the signs. Bounces and spam complaints coming back are another.
4.  **Check domains and credentials.** Under *Sending* → *Domains*, make sure no domain was added that you do not recognize and review each domain’s SMTP credentials. Delete any you did not create, and reset the ones tied to the exposed project.
5.  **Review webhooks and routes.** An attacker with account access can add a webhook or route that copies your incoming mail elsewhere. Check both lists and remove anything unfamiliar.
6.  **Rotate the webhook signing key if it was in the same file.** Anything committed next to the API key should be treated as exposed.

Not sure what else leaked? [Run a free scan](/).

7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

If spam or phishing went out under your domain, tell your recipients and keep an eye on your domain’s reputation for the following weeks.

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Mailgun

There is no single link to give you, because Mailgun’s account settings are reorganized from time to time. Sign in to the Mailgun dashboard, open your account menu, then the *API security* or API keys page. Find the private API key (or the specific key you leaked) and regenerate or delete it. For SMTP credentials, go to the sending domain’s settings and reset the password for the exposed login. If you use several Mailgun accounts or regions, make sure you are signed in to the one that owns the key. After the change, requests with the old value are rejected.

## How LeakWatch detects it

The rule is called Mailgun Private API Token. It looks for a `key-` value with a 32-character hexadecimal body written next to the word “mailgun” and an assignment such as `=` or `:`. A bare `key-` string with no Mailgun context is not reported, since the shape alone is too common. LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does **not** check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

## FAQ

Can someone read my emails with the API key?

Not your mailbox: Mailgun sends and receives for your domain but does not host inboxes. They can, however, read logs and stored messages that Mailgun keeps, and any inbound mail routed through Mailgun.

Do I need to warn my customers?

If messages were sent in your name, yes: tell your recipients not to trust them. If only the key leaked and the logs show nothing, a notice is usually not needed, but check the logs carefully.

Is the public validation key a leak?

No. It is designed to appear in front-end code. Look for the private key and the webhook signing key instead.

## Related

-   [Telegram Bot Token](/secrets/telegram-bot-token)
-   [Discord Bot Token](/secrets/discord-bot-token)
-   [SendGrid API Key](/secrets/sendgrid-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Mailgun.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
