Leaked secret · Email
Your SendGrid key
is exposed in .env?
Don't panic — but move fast. A committed or client-side SENDGRID_API_KEY gives anyone your SendGrid account — sending email as your domain. Rotate it now, then make sure nothing else leaked.
Looks like
SENDGRID_API_KEY=SG.…
What an attacker can do with a leaked SendGrid key
⚠
Send phishing and spam from your verified domain
⚠
Destroy your sender reputation and deliverability
⚠
Read contacts, templates and email activity
Fix it right now — rotate your SendGrid key
- 1SendGrid → Settings → API Keys → delete the leaked key and create a new one.
- 2Update SENDGRID_API_KEY in your env and redeploy.
- 3Check Activity Feed for emails you didn't send and review domain auth.
- 4Remove the key from git history.
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.