The Real-World Blast Radius of a Leaked Email API Key
Email API credentials are prime targets for automated credential scrapers. Automated scanners continuously crawl public GitHub repositories, Docker container registries, and paste sites. Within 90 seconds of an API key being pushed to a public branch, automated botnets begin utilizing the key to dispatch hundreds of thousands of cryptocurrency phishing, malware, or spam campaigns.
Because the sending domain has valid SPF, DKIM, and DMARC authentication configured by your engineering team, these spam campaigns achieve high inbox placement initially. Within 4 hours, however, the mailbox providers react: your domain is placed on Spamhaus and Barracuda blacklists, Google Postmaster reputation collapses to "Bad", and all legitimate customer transactional emails (password resets, invoices) land in spam for weeks.
Defense in Depth: The 4-Tier Security Engineering Architecture
| Defense Tier | Mechanism | Failure Mode Prevented |
|---|---|---|
| Tier 1: Scoped Keys | Restrict keys to specific domains or recipient regex allowlists | Prevents sending to external arbitrary spam lists |
| Tier 2: Concurrency & Rate Limits | Hard threshold of 50–250 sends/hour on developer keys | Prevents massive bot spam floods |
| Tier 3: Automated Secret Scanning | GitHub Secret Scanning integration for instant revocation | Invalidates leaked keys within seconds of public commit |
| Tier 4: Anomaly Detection | Sudden recipient divergence alarms and honeypot traps | Freezes compromised keys automatically |
How SadaSend Per-Key Recipient Allowlists Eliminate the Threat
Traditional email providers (SendGrid, Resend, Mailgun) operate under an all-or-nothing security model: if an API key has sending permissions, it can email anyone in the world. A compromised developer key or rogue AI agent loop has an infinite blast radius.
SadaSend introduces per-key recipient allowlists enforced directly at the edge API gateway. You can restrict staging and agent keys to specific domains (*@yourcompany.com) or specific developer addresses. If an attacker or looping agent attempts to send outside the allowlist, the API immediately rejects the request with HTTP 403 before a single message enters the outbound queue.
{
"error": "Forbidden",
"status": 403,
"code": "RECIPIENT_ALLOWLIST_VIOLATION",
"message": "Recipient 'victim@external-domain.com' is not permitted by API key allowlist constraint: '*@yourcompany.com'"
}Building AI agents that send email?
Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.