DASHBOARD · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Blocks
Why a site or a visitor IP gets blocked, and how to lift it.
There are two kinds of block:
- IP block — form submissions from one visitor IP address are dropped.
- Site block — the whole site is disabled. Its key cannot send email or submit forms.
IP blocks
| Reason | Set by | How long | Who can lift it |
|---|---|---|---|
rate_limit | SecureSMTP, automatically | 1 hour, then it ends by itself | You |
| Any other reason | SecureSMTP staff | Until a date, or permanent | Support only |
A rate_limit block is set when an IP already has more than 3 submissions in the last 60 seconds and sends another. While an IP is blocked, POST /forms/submit answers { "ok": true, "blocked": true } and nothing is stored or emailed. If the visitor keeps sending as fast after you lift the block, the IP is blocked again.
You see the blocks set for IPs that submitted to your sites, and blocks that are not tied to any site.
Site blocks
- Disabled automatically. If a site gets at least 20 form submissions in 24 hours and half or more are spam, it is disabled. The reason reads like
auto_disabled: 14/22 spam in last 24h (ratio 64%). You can reactivate it yourself. - Disabled by SecureSMTP staff. Only support can turn it back on.
While a site is blocked, its key gets 403 site_disabled from the sending, forms, sites and sequence endpoints, and the WordPress plugin sends with WordPress’s own mailer. See Sites and API keys.
visitor.ip. See Spam protection.In the dashboard
Blocks (/app/forms/blocks) shows the number of site blocks, IP blocks, and blocks lifted in the last 30 days, then two tables:
- Site blocks — site, status, reason, when it was disabled, and a Reactivate site button.
- IP blocks — IP, reason, the site that triggered it, when it started, until when (or “Permanent”), and an Unblock button.
Blocks you cannot lift show Contact support instead. Write to [email protected]. In WordPress, the plugin’s Blocks page shows your blocks too.
From the API
Both endpoints accept the key of a disabled site, so your code can find out why it is blocked.
Check blocks
curl https://securessmtp.com/api/v1/blocks/status \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"{
"ok": true,
"status": {
"any_active_block": true,
"site_blocks": [],
"ip_blocks": [
{
"id": "4d3c2b1a-0f9e-4d8c-b7a6-5e4d3c2b1a0f",
"ip": "203.0.113.7",
"reason": "rate_limit",
"blockedAt": "2026-10-07T09:12:44.000Z",
"blockedUntil": "2026-10-07T10:12:44.000Z",
"selfLiftable": true,
"note": null,
"triggeredBySiteId": "8a7b6c5d-4e3f-4a1b-9c8d-7e6f5a4b3c2d"
}
],
"headline": "1 IP address is blocked from submitting your forms."
}
}Each site block has siteId, siteName, status, reason, selfLiftable and disabledAt. When the site is blocked, headline reads “Your site is currently blocked from SecureSMTP: reason”. With no blocks, any_active_block is false and headline is null.
Lift a block
Lift an IP block by its id, when selfLiftable is true:
curl -X POST https://securessmtp.com/api/v1/blocks/lift \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"kind": "ip",
"block_id": "4d3c2b1a-0f9e-4d8c-b7a6-5e4d3c2b1a0f"
}'Reactivate the site that owns the key, when it was disabled automatically:
curl -X POST https://securessmtp.com/api/v1/blocks/lift \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"kind": "site"
}'Success: { "ok": true, "lifted": "ip" } or { "ok": true, "lifted": "site" }.
| HTTP | error | Meaning |
|---|---|---|
400 | bad_body | The body is not {kind:"ip", block_id} or {kind:"site"}. |
404 | not_found | No block with that ID. |
400 | already_lifted | The IP block was already lifted. |
403 | not_self_liftable | The IP block’s reason is not rate_limit. Contact support. |
403 | not_owner | The IP block was set for another site. |
403 | requires_admin_review | The site was not disabled automatically. Contact support, or reactivate it on the Sites page if you deactivated it. |
400 | already_active | The site is not disabled. |
401 | missing_api_key, invalid_api_key | No key, or the key is wrong. |