API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Verify a site

POST /api/v1/sites/verify

POSThttps://securessmtp.com/api/v1/sites/verify

Checks the key and reports the URL your code runs on. If the URL’s host is the site’s domain or a subdomain of it, the site is marked verified. The answer also has the site’s captcha settings. The WordPress plugin calls it on install and from Test connection.

You do not need to call it. The first successful send or form submission also marks the site as verified.

Headers

x-securessmtp-api-keystringrequired
The site’s API key (qcs_live_…). x-securesmtp-api-key and x-qcs-api-key are accepted too. See Sites and API keys.
Content-Typestringrequired
application/json

Body

site_urlstringrequired
A full URL, e.g. https://www.acme.example. Saved on the site.
plugin_verstringoptional
Up to 20 characters. Your plugin or app version. Saved on the site.
wp_versionstringoptional
Up to 20 characters. Saved on the site.
php_versionstringoptional
Up to 20 characters. Saved on the site.

Request

curl -X POST https://securessmtp.com/api/v1/sites/verify \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "site_url": "https://www.acme.example",
  "plugin_ver": "1.23.0",
  "wp_version": "6.6.2",
  "php_version": "8.2"
}'

Response

200
{
  "ok": true,
  "site": {
    "id": "a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d",
    "name": "Acme Store",
    "domain": "acme.example",
    "verified": true,
    "domain_match": true
  },
  "turnstile_site_key": "0x4AAAAAAA...",
  "captcha": {
    "provider": "shared",
    "site_key": "0x4AAAAAAA...",
    "widget_js": "https://challenges.cloudflare.com/turnstile/v0/api.js",
    "widget_class": "cf-turnstile",
    "response_field": "cf-turnstile-response"
  }
}
Response fields
okbooleanrequired
true.
site.idstringrequired
The site’s ID (UUID).
site.namestringrequired
The site’s name.
site.domainstringrequired
The domain registered for the site.
site.verifiedbooleanrequired
Whether the site is verified now. A URL that does not match leaves an already verified site verified.
site.domain_matchbooleanrequired
Whether site_url matched the site’s domain on this call.
turnstile_site_keystring | nullrequired
Our shared Turnstile site key, whatever provider the site uses. Older plugins read it.
captchaobjectrequired
Same as the response of GET /sites/captcha without ok.

Errors

Errors have an error field and no ok field.

HTTPValueMeaningWhat to do
401missing_api_keyNo key header was sent.Send the key in the x-securessmtp-api-key header.
401invalid_api_keyNo site has this key. Keys stop working as soon as they are rotated.Copy the current key from the dashboard, or rotate it to get a new one.
403site_disabledThe site is disabled.Check GET /blocks/status. See Blocks.
400invalid_jsonThe body is not valid JSON.Send a JSON body with Content-Type: application/json.
400invalid_payloadsite_url is missing or not a full URL, or a version is longer than 20 characters. details says which.Send site_url with the scheme, e.g. https://.