I have a payload p that comes from a limited domain. I want to hash p to produce a unique signature and store it. This will allow detection of duplicate ps that I might receive later.
Since p comes from a small domain, and is somewhat sensitive, I plan to use a pepper when hashing to prevent against rainbow table attacks (if there are better approaches to deal with limited domain data, I would welcome recommendations)
When hashing p, is it preferred to compute the hash via an HMAC algorithm. Per this post, HMAC-SHA256(pepper, p) seems like it's preferrable to SHA256(concat(p, pepper)).