A SendGrid API key lets whoever holds it send email through your SendGrid account, from your verified domains and senders. The mail looks legitimate because it is: it is signed with your domain’s authentication and comes from your sending infrastructure. That makes a leaked key attractive for phishing and spam, and the real cost is usually your domain’s sending reputation, not the bill. What the key can do depends on the permissions it was created with.
Check your GitHub account for leaked secrets — free
- Provider
- SendGrid
- Severity
- High
- Impact
- SaaS account access and billing
- Checked live by LeakWatch
- No
What a SendGrid API key looks like
SendGrid keys have a fixed prefix and two dot-separated parts:
SG.…XXXX.…XXXX SendGrid API key (masked)
The first segment is a short identifier of the key and the second is the secret part; both are needed. The identifier alone, which SendGrid shows in its key list, is not enough to authenticate.
Two things are not this secret. A SendGrid SMTP password is usually the same key used with the username apikey, so the key still has to be revoked. A Twilio account credential is a different product, see the Twilio API key guide. If you leaked a key for another email provider, the Mailgun API key page covers that one.
How SendGrid API keys get leaked
- Application config.
SENDGRID_API_KEYin.env,settings.py,appsettings.jsonor a Docker Compose file committed with the code. - SMTP settings. Mail configuration for a CMS, a framework or a monitoring tool, where the key is the SMTP password and
apikeyis the username. - Transactional email scripts. A quick “send a test email” snippet, copied from the docs with the real key pasted in.
- Server and CI configuration. Postfix relay configs, Kubernetes manifests, Terraform variables and pipeline files.
- Support threads and logs. Debug output of an HTTP request with its
Authorization: Bearerheader.
What to do in the first hour
- Create a replacement key. In the SendGrid dashboard, open Settings → API Keys → Create API Key. Choose Restricted Access and enable only what the app needs, typically just Mail Send. Avoid Full Access unless something truly requires it.
- Deploy the new key to your secret manager or environment variables and send a test message to confirm production works.
- Delete the exposed key from Settings → API Keys. Mail sending with the old value stops once it is deleted.
- Audit what was sent. Open Email Activity and review messages since the exposure: unfamiliar recipients, subjects or sending volume. Also open Stats and compare the volume with your usual level. Bounce and spam-report spikes are a sign that someone sent to a purchased list.
- Check the account settings an attacker could have changed. Review Sender Authentication for domains or senders you did not add, then Settings → Mail Settings for BCC or footer rules, and the list of other API keys and teammates. Keys with the right permissions can also create more keys, so delete any you do not recognize.
- Harden the account. Turn on two-factor authentication for every user, and give each application its own key, so you can revoke one without breaking the rest.
- Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.
Not sure what else leaked? Run a free scan.
Revoke it at SendGrid
SendGrid has no one-click link that is safe to rely on, so use the menu path. Sign in to the SendGrid dashboard and go to Settings → API Keys. The list shows each key’s name and permissions. Find the exposed key, which you can identify by its name or by the first characters of the value, and delete it from the actions menu on its row. If you use subusers, check them too: keys are created per account and a subuser has its own list. Deleting is permanent and a new key gets a new value.
How LeakWatch detects it
The rule is called “SendGrid API Key”. It looks for the literal SG. prefix, then a 22-character segment, a dot, and a 43-character segment, all made of letters, digits, hyphens and underscores. The exact lengths keep false positives low. LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.
LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.
FAQ
Can an attacker read my contact lists or email history?
That depends on the key’s permissions. A key restricted to Mail Send cannot read your marketing contacts or templates, while a full-access key can. Open the key’s details before you delete it so you know which one you had, then review the matching areas of the account.
My domain's reputation dropped after the leak. What now?
Stop the abuse first by deleting the key, then watch your bounce, block and spam-report figures over the following days. Mailbox providers recover trust with clean sending over time; a new key and consistent volume are the best way to help.
Do I need to tell the people who received the messages?
If someone sent phishing from your domain, a short notice to your own users that they may have received messages they should ignore is reasonable. If personal data was involved, a qualified adviser can help you decide on your obligations.