# Leaked SendGrid API Key? Delete It and Check Sending

> SendGrid API key exposed on GitHub? Delete it, create a scoped replacement, check email activity and sender settings. Step-by-step guide.

Source: https://leakwatch.net/secrets/sendgrid-api-key

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  SendGrid API Key

Messaging · Secret guide

# Leaked SendGrid API Key: what to do in the first hour

High severityDetected onlyLast verified October 2, 2026 · 4 min read

A SendGrid API key lets whoever holds it send email through your SendGrid account, from your verified domains and senders. The mail looks legitimate because it is: it is signed with your domain’s authentication and comes from your sending infrastructure. That makes a leaked key attractive for phishing and spam, and the real cost is usually your domain’s sending reputation, not the bill. What the key can do depends on the permissions it was created with.

[Check your GitHub account for leaked secrets — free](/)

Provider

SendGrid

Severity

High

Impact

SaaS account access and billing

Checked live by LeakWatch

No

## What a SendGrid API key looks like

SendGrid keys have a fixed prefix and two dot-separated parts:

```text
SG.…XXXX.…XXXX   SendGrid API key (masked)
```

The first segment is a short identifier of the key and the second is the secret part; both are needed. The identifier alone, which SendGrid shows in its key list, is not enough to authenticate.

Two things are not this secret. A **SendGrid SMTP password** is usually the same key used with the username `apikey`, so the key still has to be revoked. A **Twilio account credential** is a different product, see the [Twilio API key](/secrets/twilio-api-key) guide. If you leaked a key for another email provider, the [Mailgun API key](/secrets/mailgun-api-key) page covers that one.

## How SendGrid API keys get leaked

-   **Application config.** `SENDGRID_API_KEY` in `.env`, `settings.py`, `appsettings.json` or a Docker Compose file committed with the code.
-   **SMTP settings.** Mail configuration for a CMS, a framework or a monitoring tool, where the key is the SMTP password and `apikey` is the username.
-   **Transactional email scripts.** A quick “send a test email” snippet, copied from the docs with the real key pasted in.
-   **Server and CI configuration.** Postfix relay configs, Kubernetes manifests, Terraform variables and pipeline files.
-   **Support threads and logs.** Debug output of an HTTP request with its `Authorization: Bearer` header.

## What to do in the first hour

1.  **Create a replacement key.** In the SendGrid dashboard, open *Settings* → *API Keys* → *Create API Key*. Choose *Restricted Access* and enable only what the app needs, typically just *Mail Send*. Avoid *Full Access* unless something truly requires it.
2.  **Deploy the new key** to your secret manager or environment variables and send a test message to confirm production works.
3.  **Delete the exposed key** from *Settings* → *API Keys*. Mail sending with the old value stops once it is deleted.
4.  **Audit what was sent.** Open *Email Activity* and review messages since the exposure: unfamiliar recipients, subjects or sending volume. Also open *Stats* and compare the volume with your usual level. Bounce and spam-report spikes are a sign that someone sent to a purchased list.
5.  **Check the account settings an attacker could have changed.** Review *Sender Authentication* for domains or senders you did not add, then *Settings* → *Mail Settings* for BCC or footer rules, and the list of other API keys and teammates. Keys with the right permissions can also create more keys, so delete any you do not recognize.
6.  **Harden the account.** Turn on two-factor authentication for every user, and give each application its own key, so you can revoke one without breaking the rest.
7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

Not sure what else leaked? [Run a free scan](/).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at SendGrid

SendGrid has no one-click link that is safe to rely on, so use the menu path. Sign in to the SendGrid dashboard and go to *Settings* → *API Keys*. The list shows each key’s name and permissions. Find the exposed key, which you can identify by its name or by the first characters of the value, and delete it from the actions menu on its row. If you use subusers, check them too: keys are created per account and a subuser has its own list. Deleting is permanent and a new key gets a new value.

## How LeakWatch detects it

The rule is called “SendGrid API Key”. It looks for the literal `SG.` prefix, then a 22-character segment, a dot, and a 43-character segment, all made of letters, digits, hyphens and underscores. The exact lengths keep false positives low. LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does **not** check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

## FAQ

Can an attacker read my contact lists or email history?

That depends on the key’s permissions. A key restricted to *Mail Send* cannot read your marketing contacts or templates, while a full-access key can. Open the key’s details before you delete it so you know which one you had, then review the matching areas of the account.

My domain's reputation dropped after the leak. What now?

Stop the abuse first by deleting the key, then watch your bounce, block and spam-report figures over the following days. Mailbox providers recover trust with clean sending over time; a new key and consistent volume are the best way to help.

Do I need to tell the people who received the messages?

If someone sent phishing from your domain, a short notice to your own users that they may have received messages they should ignore is reasonable. If personal data was involved, a qualified adviser can help you decide on your obligations.

## Related

-   [Telegram Bot Token](/secrets/telegram-bot-token)
-   [Discord Bot Token](/secrets/discord-bot-token)
-   [Mailgun API Key](/secrets/mailgun-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with SendGrid.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
