Skip to main content
If an API key is accidentally exposed on GitHub or a public URL, act immediately to prevent unauthorized email sending.

Remediation Steps

  1. Revoke the Compromised Key:
  2. Generate a Replacement Key:
    • Click Create API Key.
    • Update your production environment variables (Vercel, AWS, Fly.io, Railway, Heroku).
  3. Audit Activity Logs:
    • Review Activity Logs in the dashboard to check if any unauthorized messages were dispatched while the key was exposed.
    • If spam was dispatched, check your Suppression List and contact Mailofly support.