How should a compromised SendGrid account be contained and recovered?
Treat suspected SendGrid compromise as an active security incident because attackers can send phishing, spoofing, or spam and damage sender reputation. Change account credentials, replace and delete exposed API keys, and contact SendGrid support immediately. Pause sending until exposed access is contained and any pending malicious mail is addressed.
First 15 minutes
- Change the SendGrid account username and password immediately and update the sending application.
- Contact SendGrid support so it can investigate, involve Compliance, temporarily deactivate the account, or delete pending messages as needed.
- Create a replacement for every exposed API key, update applications, and delete the compromised key.
Now
- Change account credentials, replace exposed API keys, delete compromised keys, and update the sending applications.
Next 24 hours
- Work with SendGrid support on investigation, Compliance involvement, temporary deactivation, and deletion of messages still pending.
Next 7 days
- Complete credential and application recovery after the support investigation identifies the affected account state.
Technical checks
Security
- Confirm exposed API keys have replacements and the compromised keys are deleted.
- If stable approved egress addresses exist, review IP Access Management coverage for the UI, API, and SMTP relay.
- Review SendGrid Teammate access and limit each teammate to features required for core job functions.
Verification criteria
- Confirm SendGrid rejects API calls that use each deleted compromised key.
- Where IP Access Management is enabled, confirm legitimate approved addresses work and other access attempts are blocked.
Escalation criteria
- Escalate immediately to SendGrid support for investigation, Compliance involvement, temporary deactivation, and deletion of pending messages.
Prevention
- Use IP Access Management only with stable approved egress addresses, limiting the UI, API, and SMTP relay to allowed IPs.
- Review Teammate access regularly and restrict each teammate to the features required for core job functions.
Business impact
- An attacker can use a compromised SendGrid account for phishing, spoofing, or spam and damage the sender's reputation.
Provider notes
- SendGrid support can investigate a compromise, involve Compliance, temporarily deactivate the account, and delete messages still pending.
- Deleting a compromised API key causes SendGrid to reject later API calls that use it.
Open questions
- The affected credentials, teammates, subusers, IPs, templates, contacts and unauthorized send window require account logs and Twilio's investigation.
- Whether queued malicious messages remain pending and whether Twilio has already suspended the account must be confirmed with support.
- IP Access Management is unsuitable without stable approved egress addresses because it can lock out legitimate operators.
- The frozen Secure your Twilio account page recommends quarterly API-key rotation and deleting unused keys, but it does not substantiate that Twilio requires 2FA for every SendGrid user.
Sources (6)
- Secure your Twilio account — Introduction, lines 53-59Twilio SendGrid
- Compromised Account Recovery — Recovery procedure, lines 99-106Twilio SendGrid
- Compromised Account Recovery — Recovery procedure, lines 104-106Twilio SendGrid
- API Keys — Deleting an API key and replacing an old API keyTwilio SendGrid
- IP Access Management — What is IP access management, lines 116-127Twilio SendGrid
- Secure your Twilio account — Review Teammate access, lines 129-141Twilio SendGrid


