Report a Security Vulnerability

Responsible Reporting


At Proofpoint our top priority is protecting the way people work today. We value the security research community and encourage responsible reporting of potential security vulnerabilities. Our security team is dedicated to working with you to validate and respond to legitimate reports. If you believe you've identified a potential security vulnerability, please email your discovery to

See latest security advisories

Contacting Security

Reporting Security Issues

We encourage people who contact Proofpoint Security to use email encryption, using our PGP encryption key:

Encryption Key
Fingerprint 806E 0096 7B5E 6E50 4C6B 083D 88B3 C1DA 8125 69D4

We ask that you do not share or publicize an unresolved vulnerability. If you submit a vulnerability report or other security concern, the Proofpoint security team will use reasonable efforts to:

  • Validate the reported vulnerability
  • Keep you informed of our progress as we investigate your reported security concern
  • Notify you when the vulnerability has been fixed
  • Publicly acknowledge your responsible disclosure (unless you prefer anonymity)

If additional information is required in order to validate or reproduce the issue, Proofpoint will work with you to obtain it.



Proofpoint appreciates every security researcher who submits a vulnerability report which helps us improve our security and that of our customers. We maintain a Hall of Fame to recognize contributors for working with our Security team to resolve these vulnerabilities. If you have reported a vulnerability in the past but do not see your name listed in our Hall of Fame, please reach out to us at

See Hall of Fame