API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Check blocks

GET /api/v1/blocks/status

GEThttps://securessmtp.com/api/v1/blocks/status

Tells you whether the site is disabled and which visitor IPs are blocked from submitting forms. It works with the key of a disabled site, so you can find out why it was disabled.

Headers

x-securessmtp-api-keystringrequired
The site’s API key (qcs_live_…). x-securesmtp-api-key and x-qcs-api-key are accepted too. See Sites and API keys.

Parameters

None.

Request

curl https://securessmtp.com/api/v1/blocks/status \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"

Response

200
{
  "ok": true,
  "status": {
    "any_active_block": true,
    "ip_blocks": [
      {
        "id": "c4d5e6f7-a8b9-4c0d-9e1f-2a3b4c5d6e7f",
        "ip": "203.0.113.7",
        "reason": "rate_limit",
        "blockedAt": "2026-10-07T10:02:11.000Z",
        "blockedUntil": "2026-10-07T11:02:11.000Z",
        "selfLiftable": true,
        "note": null,
        "triggeredBySiteId": "a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d"
      }
    ],
    "site_blocks": [],
    "headline": "1 IP address is blocked from submitting your forms."
  }
}
Response fields
okbooleanrequired
true.
status.any_active_blockbooleanrequired
true when the site is disabled or at least one IP block is listed.
status.site_blocksobject[]required
Empty unless the site is disabled. Then one item:
  • siteId, siteName, status (e.g. inactive)
  • reason — the recorded reason, or Site is currently disabled.
  • selfLiftable — true when the site was disabled automatically and you can turn it back on with POST /blocks/lift
  • disabledAt — ISO 8601, or null
status.ip_blocksobject[]required
Active IP blocks started by this site, plus blocks not linked to any site. Newest first, at most 100. Each item:
  • id — pass it as block_id to lift the block
  • ip, reason (rate_limit for the automatic form limit)
  • blockedAt, blockedUntil — ISO 8601; blockedUntil is null for a block with no end
  • selfLiftable — true only for reason rate_limit
  • note — a note from us, or null
  • triggeredBySiteId — the site that caused the block, or null
status.headlinestring | nullrequired
One sentence you can show as is, e.g. Your site is currently blocked from SecureSMTP: … or 2 IP addresses are blocked from submitting your forms. null when nothing is blocked.

Errors

Errors have "ok": false and an error. A disabled site does not get an error here.

HTTPValueMeaningWhat to do
401missing_api_keyNo key header was sent.Send the key in the x-securessmtp-api-key header.
401invalid_api_keyNo site has this key. Keys stop working as soon as they are rotated.Copy the current key from the dashboard, or rotate it to get a new one.

See Blocks.