API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Verify a site
POST /api/v1/sites/verify
POSThttps://securessmtp.com/api/v1/sites/verify
Checks the key and reports the URL your code runs on. If the URL’s host is the site’s domain or a subdomain of it, the site is marked verified. The answer also has the site’s captcha settings. The WordPress plugin calls it on install and from Test connection.
You do not need to call it. The first successful send or form submission also marks the site as verified.
Headers
- x-securessmtp-api-keystringrequired
- The site’s API key (
qcs_live_…).x-securesmtp-api-keyandx-qcs-api-keyare accepted too. See Sites and API keys. - Content-Typestringrequired
application/json
Body
- site_urlstringrequired
- A full URL, e.g.
https://www.acme.example. Saved on the site. - plugin_verstringoptional
- Up to 20 characters. Your plugin or app version. Saved on the site.
- wp_versionstringoptional
- Up to 20 characters. Saved on the site.
- php_versionstringoptional
- Up to 20 characters. Saved on the site.
Request
curl -X POST https://securessmtp.com/api/v1/sites/verify \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"site_url": "https://www.acme.example",
"plugin_ver": "1.23.0",
"wp_version": "6.6.2",
"php_version": "8.2"
}'Response
200
{
"ok": true,
"site": {
"id": "a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d",
"name": "Acme Store",
"domain": "acme.example",
"verified": true,
"domain_match": true
},
"turnstile_site_key": "0x4AAAAAAA...",
"captcha": {
"provider": "shared",
"site_key": "0x4AAAAAAA...",
"widget_js": "https://challenges.cloudflare.com/turnstile/v0/api.js",
"widget_class": "cf-turnstile",
"response_field": "cf-turnstile-response"
}
}Response fields
- okbooleanrequired
true.- site.idstringrequired
- The site’s ID (UUID).
- site.namestringrequired
- The site’s name.
- site.domainstringrequired
- The domain registered for the site.
- site.verifiedbooleanrequired
- Whether the site is verified now. A URL that does not match leaves an already verified site verified.
- site.domain_matchbooleanrequired
- Whether
site_urlmatched the site’s domain on this call. - turnstile_site_keystring | nullrequired
- Our shared Turnstile site key, whatever provider the site uses. Older plugins read it.
- captchaobjectrequired
- Same as the response of GET /sites/captcha without
ok.
Errors
Errors have an error field and no ok field.
| HTTP | Value | Meaning | What to do |
|---|---|---|---|
| 401 | missing_api_key | No key header was sent. | Send the key in the x-securessmtp-api-key header. |
| 401 | invalid_api_key | No site has this key. Keys stop working as soon as they are rotated. | Copy the current key from the dashboard, or rotate it to get a new one. |
| 403 | site_disabled | The site is disabled. | Check GET /blocks/status. See Blocks. |
| 400 | invalid_json | The body is not valid JSON. | Send a JSON body with Content-Type: application/json. |
| 400 | invalid_payload | site_url is missing or not a full URL, or a version is longer than 20 characters. details says which. | Send site_url with the scheme, e.g. https://. |