DASHBOARD · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Blocks

Why a site or a visitor IP gets blocked, and how to lift it.

There are two kinds of block:

  • IP block — form submissions from one visitor IP address are dropped.
  • Site block — the whole site is disabled. Its key cannot send email or submit forms.

IP blocks

ReasonSet byHow longWho can lift it
rate_limitSecureSMTP, automatically1 hour, then it ends by itselfYou
Any other reasonSecureSMTP staffUntil a date, or permanentSupport only

A rate_limit block is set when an IP already has more than 3 submissions in the last 60 seconds and sends another. While an IP is blocked, POST /forms/submit answers { "ok": true, "blocked": true } and nothing is stored or emailed. If the visitor keeps sending as fast after you lift the block, the IP is blocked again.

You see the blocks set for IPs that submitted to your sites, and blocks that are not tied to any site.

Site blocks

  • Disabled automatically. If a site gets at least 20 form submissions in 24 hours and half or more are spam, it is disabled. The reason reads like auto_disabled: 14/22 spam in last 24h (ratio 64%). You can reactivate it yourself.
  • Disabled by SecureSMTP staff. Only support can turn it back on.

While a site is blocked, its key gets 403 site_disabled from the sending, forms, sites and sequence endpoints, and the WordPress plugin sends with WordPress’s own mailer. See Sites and API keys.

Before you reactivate a site that was disabled for spam, find out where the spam comes from: turn on a captcha and make sure your server sends visitor.ip. See Spam protection.

In the dashboard

Blocks (/app/forms/blocks) shows the number of site blocks, IP blocks, and blocks lifted in the last 30 days, then two tables:

  • Site blocks — site, status, reason, when it was disabled, and a Reactivate site button.
  • IP blocks — IP, reason, the site that triggered it, when it started, until when (or “Permanent”), and an Unblock button.

Blocks you cannot lift show Contact support instead. Write to [email protected]. In WordPress, the plugin’s Blocks page shows your blocks too.

From the API

Both endpoints accept the key of a disabled site, so your code can find out why it is blocked.

Check blocks

curl https://securessmtp.com/api/v1/blocks/status \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"
Response
{
  "ok": true,
  "status": {
    "any_active_block": true,
    "site_blocks": [],
    "ip_blocks": [
      {
        "id": "4d3c2b1a-0f9e-4d8c-b7a6-5e4d3c2b1a0f",
        "ip": "203.0.113.7",
        "reason": "rate_limit",
        "blockedAt": "2026-10-07T09:12:44.000Z",
        "blockedUntil": "2026-10-07T10:12:44.000Z",
        "selfLiftable": true,
        "note": null,
        "triggeredBySiteId": "8a7b6c5d-4e3f-4a1b-9c8d-7e6f5a4b3c2d"
      }
    ],
    "headline": "1 IP address is blocked from submitting your forms."
  }
}

Each site block has siteId, siteName, status, reason, selfLiftable and disabledAt. When the site is blocked, headline reads “Your site is currently blocked from SecureSMTP: reason”. With no blocks, any_active_block is false and headline is null.

Lift a block

Lift an IP block by its id, when selfLiftable is true:

curl -X POST https://securessmtp.com/api/v1/blocks/lift \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "kind": "ip",
  "block_id": "4d3c2b1a-0f9e-4d8c-b7a6-5e4d3c2b1a0f"
}'

Reactivate the site that owns the key, when it was disabled automatically:

curl -X POST https://securessmtp.com/api/v1/blocks/lift \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "kind": "site"
}'

Success: { "ok": true, "lifted": "ip" } or { "ok": true, "lifted": "site" }.

HTTPerrorMeaning
400bad_bodyThe body is not {kind:"ip", block_id} or {kind:"site"}.
404not_foundNo block with that ID.
400already_liftedThe IP block was already lifted.
403not_self_liftableThe IP block’s reason is not rate_limit. Contact support.
403not_ownerThe IP block was set for another site.
403requires_admin_reviewThe site was not disabled automatically. Contact support, or reactivate it on the Sites page if you deactivated it.
400already_activeThe site is not disabled.
401missing_api_key, invalid_api_keyNo key, or the key is wrong.