We have switched to sending the Akismet API key as part of the request body by default. At the time of this report, Akismet API keys used formed part of the subdomain request to Akismet’s backend in the form This means that the API key is transmitted over DNS - a protocol that is well known for its lack of encryption. As a result, Akismet API keys cannot be considered secure or private. Anyone capturing network packets, or the DNS server operator for example, could easily log the DNS requests - and therefore API key - from a client accessing the Akismet API. The unwanted disclosure of the API key could cause Denial of Service or Information Leakage should a malicious actor get hold of......

