API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Check blocks
GET /api/v1/blocks/status
GEThttps://securessmtp.com/api/v1/blocks/status
Tells you whether the site is disabled and which visitor IPs are blocked from submitting forms. It works with the key of a disabled site, so you can find out why it was disabled.
Headers
- x-securessmtp-api-keystringrequired
- The site’s API key (
qcs_live_…).x-securesmtp-api-keyandx-qcs-api-keyare accepted too. See Sites and API keys.
Parameters
None.
Request
curl https://securessmtp.com/api/v1/blocks/status \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"Response
200
{
"ok": true,
"status": {
"any_active_block": true,
"ip_blocks": [
{
"id": "c4d5e6f7-a8b9-4c0d-9e1f-2a3b4c5d6e7f",
"ip": "203.0.113.7",
"reason": "rate_limit",
"blockedAt": "2026-10-07T10:02:11.000Z",
"blockedUntil": "2026-10-07T11:02:11.000Z",
"selfLiftable": true,
"note": null,
"triggeredBySiteId": "a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d"
}
],
"site_blocks": [],
"headline": "1 IP address is blocked from submitting your forms."
}
}Response fields
- okbooleanrequired
true.- status.any_active_blockbooleanrequired
truewhen the site is disabled or at least one IP block is listed.- status.site_blocksobject[]required
- Empty unless the site is disabled. Then one item:
siteId,siteName,status(e.g.inactive)reason— the recorded reason, orSite is currently disabled.selfLiftable—truewhen the site was disabled automatically and you can turn it back on with POST /blocks/liftdisabledAt— ISO 8601, ornull
- status.ip_blocksobject[]required
- Active IP blocks started by this site, plus blocks not linked to any site. Newest first, at most 100. Each item:
id— pass it asblock_idto lift the blockip,reason(rate_limitfor the automatic form limit)blockedAt,blockedUntil— ISO 8601;blockedUntilisnullfor a block with no endselfLiftable—trueonly for reasonrate_limitnote— a note from us, ornulltriggeredBySiteId— the site that caused the block, ornull
- status.headlinestring | nullrequired
- One sentence you can show as is, e.g.
Your site is currently blocked from SecureSMTP: …or2 IP addresses are blocked from submitting your forms.nullwhen nothing is blocked.
Errors
Errors have "ok": false and an error. A disabled site does not get an error here.
| HTTP | Value | Meaning | What to do |
|---|---|---|---|
| 401 | missing_api_key | No key header was sent. | Send the key in the x-securessmtp-api-key header. |
| 401 | invalid_api_key | No site has this key. Keys stop working as soon as they are rotated. | Copy the current key from the dashboard, or rotate it to get a new one. |
See Blocks.