high
resend-api-key· ResendResend API key
Send email from your verified domains — the raw material for a phishing campaign with your DKIM signature on it.
How it is detected
Matches the two-segment `re_` key format.
If you find one
- 1Revoke the credential with its provider. Rotation is the only fix — the key is in the browser cache, in CDN edge nodes, and in whatever scraped the page.
- 2Review the account for activity you did not initiate.
- 3Move the call that needed it to a server route, so the browser never receives the replacement.
Where it turns up
Most often in client bundles built by AI coding tools.