API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Lift a block
POST /api/v1/blocks/lift
POSThttps://securessmtp.com/api/v1/blocks/lift
Lifts one IP block, or turns the site back on after it was disabled automatically. Blocks that need a review by us cannot be lifted here. Works with the key of a disabled site.
Headers
- x-securessmtp-api-keystringrequired
- The site’s API key (
qcs_live_…).x-securesmtp-api-keyandx-qcs-api-keyare accepted too. See Sites and API keys. - Content-Typestringrequired
application/json
Body
- kind'ip' | 'site'required
iplifts one IP block.siteturns the site back on.- block_idstringoptional
- 1–80 characters. Required when
kindisip: the block’sidfrom GET /blocks/status.
Request
curl -X POST https://securessmtp.com/api/v1/blocks/lift \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"kind": "ip",
"block_id": "c4d5e6f7-a8b9-4c0d-9e1f-2a3b4c5d6e7f"
}'Turn the site back on
curl -X POST https://securessmtp.com/api/v1/blocks/lift \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"kind": "site"
}'Response
200
{
"ok": true,
"lifted": "ip"
}Response fields
- okbooleanrequired
true.- lifted'ip' | 'site'required
- What was lifted.
Errors
Errors have "ok": false and an error.
| HTTP | Value | Meaning | What to do |
|---|---|---|---|
| 401 | missing_api_key | No key header was sent. | Send the key in the x-securessmtp-api-key header. |
| 401 | invalid_api_key | No site has this key. Keys stop working as soon as they are rotated. | Copy the current key from the dashboard, or rotate it to get a new one. |
| 400 | bad_body | The body is not valid JSON, kind is missing or wrong, or block_id is missing for kind ip. | Send {"kind":"ip","block_id":"…"} or {"kind":"site"}. |
| 404 | not_found | kind ip: no block with this ID. | Get the current IDs from GET /blocks/status. |
| 400 | already_lifted | kind ip: the block was already lifted. | Nothing to do. |
| 403 | not_self_liftable | kind ip: the block’s reason is not rate_limit, so we have to review it. | Contact support. |
| 403 | not_owner | kind ip: the block was started by another site. | Lift it with the key of the site that started it. |
| 400 | already_active | kind site: the site is not disabled. | Nothing to do. |
| 403 | requires_admin_review | kind site: the site was not disabled automatically, so we have to review it. | Contact support. |
Notes
- An IP block applies to form submissions on every site, so lifting it lets that IP submit to all of them again.
- Automatic
rate_limitblocks end by themselves after 1 hour. - You can do the same in the dashboard under Blocks (
/app/forms/blocks). See Blocks.