redact-secret · Report
Public validation key (pubkey-)
pubkey- followed by 32 bytes; Mailgun's public email-validation key, not a secret.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict rejected, tier none) cited 9 sources; the dossier does not attribute sources to individual properties.
- devcenter.heroku.com/articles/mailgun-validationsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.gitlab.com/user/application_security/dast/browser/checks/798.73/other · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- gitleaks/gitleaks @ b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b: config/gitleaks.tomlother · last read 2026-10-05 · latest outcome read · supports Cited by the legacy dossier research for this family
- mailgun/mailgun-python @ ce47f6bb7c9035d2c8070a9cf2c2e1a57eb5b40a: mailgun/filters.pyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- github.com/mailgun/mailgun-ruby/issues/145issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- mailgun/validator-demo @ 2c0f9731d26c35ea9fd257979342fc77c5fd38e9: index.htmlprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/confirm-only.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- help.mailgun.com/hc/en-us/articles/203380100-Where-can-I-find-my-API-keys-and-SMTP-credentialsprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- help.mailgun.com/hc/en-us/articles/360010523074-Email-Validationsprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- never stated by Mailgun. The prefix
pubkey-comes from mailgun-python's log filter ((key-|pubkey-)[\w\-]+, described as scrubbing "Mailgun private and public key patterns"), mailgun-ruby's recorded regenerate-key response (apubkey-placeholder) and a 2018 customer report.pubkey-+ 32 lowercase hex comes from gitleaks (mailgun-pub-key, behind amailgunkeyword) and about thirty tools that copy it or its ancestors (betterleaks, Checkmarx 2ms, semgrep-rules, PEASS-ng, gitGraber, ScoutSuite). trufflehog, Nosey Parker, CredSweeper and detect-secrets have nopubkey-rule. The #582 measurement found 17pubkey-+ 32 candidates in public code, 16 of them hex-only.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | mailgun-pub-key | mailgun keyword + pubkey- + 32 hex |
No rule maps to this family in flare-redact, openredaction, trufflehog.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- github.com/gitleaks/gitleaks/blob/v8.30.1/config/gitleaks.toml
- help.mailgun.com/hc/en-us/articles/360010523074-Email-Validations
- help.mailgun.com/hc/en-us/articles/203380100-Where-can-I-find-my-API-keys-and-SMTP-credentials
- github.com/mailgun/validator-demo/blob/2c0f9731d26c35ea9fd257979342fc77c5fd38e9/index.html
- devcenter.heroku.com/articles/mailgun-validations
- github.com/mailgun/mailgun-ruby/issues/145
- github.com/mailgun/mailgun-python/blob/ce47f6bb7c9035d2c8070a9cf2c2e1a57eb5b40a/mailgun/filters.py
- github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/config/gitleaks.toml
- docs.gitlab.com/user/application_security/dast/browser/checks/798.73/
Research log
- redact-secret/redact-secret#314Research issue
- redact-secret/redact-secret#582Research issue
- redact-secret/redact-secret-benchmarks#473Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/confirm-only.md