• $100 – $1,500 per vulnerability
  • Managed by Bugcrowd

Program stats

56 vulnerabilities rewarded

Validation within 4 days
75% of submissions are accepted or rejected within 4 days

$242.85 average payout (last 3 months)

Latest hall of famers

Recently joined this program


Please note: This program does not allow disclosure. You may not release information about vulnerabilities found in this program to the public.

Mailgun empowers developers by allowing them to easily integrate email into their applications. With our powerful API, users can build apps that send, receive, and track emails in real time using a combination of standard protocols. We work hard to keep Mailgun high performing and secure for our user community. Help us make our products even better and earn rewards by reporting potential vulnerabilities.


This program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the prioritization/rating of findings.

Reward Range

Last updated
Technical severity Reward range
p1 Critical $1,000 - $1,500
p2 Severe $600 - $1,000
p3 Moderate $200 - $600
p4 Low $100 - $200
P5 submissions do not receive any rewards for this program.


In scope

Out of scope

Any domain/property of Mailgun not listed in the targets section is out of scope. This includes any/all subdomains not listed above.


For testing purposes, you're free to create your own accounts to do so, please sign up at with your ('username' email address (for more information regarding your @bugcrowdninja email, please see this doc:

Focus Areas


  • Privilege escalations based our user roles

Program rules

This program follows Bugcrowd’s standard disclosure terms.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.