API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Lift a block

POST /api/v1/blocks/lift

POSThttps://securessmtp.com/api/v1/blocks/lift

Lifts one IP block, or turns the site back on after it was disabled automatically. Blocks that need a review by us cannot be lifted here. Works with the key of a disabled site.

Headers

x-securessmtp-api-keystringrequired
The site’s API key (qcs_live_…). x-securesmtp-api-key and x-qcs-api-key are accepted too. See Sites and API keys.
Content-Typestringrequired
application/json

Body

kind'ip' | 'site'required
ip lifts one IP block. site turns the site back on.
block_idstringoptional
1–80 characters. Required when kind is ip: the block’s id from GET /blocks/status.

Request

curl -X POST https://securessmtp.com/api/v1/blocks/lift \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "kind": "ip",
  "block_id": "c4d5e6f7-a8b9-4c0d-9e1f-2a3b4c5d6e7f"
}'

Turn the site back on

curl -X POST https://securessmtp.com/api/v1/blocks/lift \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "kind": "site"
}'

Response

200
{
  "ok": true,
  "lifted": "ip"
}
Response fields
okbooleanrequired
true.
lifted'ip' | 'site'required
What was lifted.

Errors

Errors have "ok": false and an error.

HTTPValueMeaningWhat to do
401missing_api_keyNo key header was sent.Send the key in the x-securessmtp-api-key header.
401invalid_api_keyNo site has this key. Keys stop working as soon as they are rotated.Copy the current key from the dashboard, or rotate it to get a new one.
400bad_bodyThe body is not valid JSON, kind is missing or wrong, or block_id is missing for kind ip.Send {"kind":"ip","block_id":"…"} or {"kind":"site"}.
404not_foundkind ip: no block with this ID.Get the current IDs from GET /blocks/status.
400already_liftedkind ip: the block was already lifted.Nothing to do.
403not_self_liftablekind ip: the block’s reason is not rate_limit, so we have to review it.Contact support.
403not_ownerkind ip: the block was started by another site.Lift it with the key of the site that started it.
400already_activekind site: the site is not disabled.Nothing to do.
403requires_admin_reviewkind site: the site was not disabled automatically, so we have to review it.Contact support.

Notes

  • An IP block applies to form submissions on every site, so lifting it lets that IP submit to all of them again.
  • Automatic rate_limit blocks end by themselves after 1 hour.
  • You can do the same in the dashboard under Blocks (/app/forms/blocks). See Blocks.