START HERE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Quickstart

Add a site, copy its key, send the first email — with curl, Node, Python or PHP.

Three steps: add a site, copy its key, send. A domain is optional — you can send before you verify one.

1. Add a site and copy the key

  1. Create an account (the Free plan needs no card).
  2. In the dashboard open Sites (/app/forms/sites) and add your website or app.
  3. Copy the API key from the box that appears. It starts with qcs_live_ and is shown in full only once. We also email it to the account owner. If you lose it, rotate it — see Sites and API keys.

Keep the key on your server, for example in an environment variable:

Shell
export SECURESSMTP_API_KEY="qcs_live_..."
Never put the key in browser JavaScript or a mobile app. Anyone who has it can send email as your site.

2. Send an email

curl -X POST https://securessmtp.com/api/v1/mail/send \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "to": "[email protected]",
  "subject": "Hello from SecureSMTP",
  "text": "It works."
}'

A successful send answers:

Response
{
  "ok": true,
  "sent": true,
  "mode": "relay",
  "message_id": "<[email protected]>"
}

3. Check the result

  • Always read ok in the response. Some failures — rate limit, monthly limit, send failure — come back with HTTP 200 and "ok": false. See API conventions.
  • Open Email log in the dashboard (/app/forms/email-log) to see whether the email was delivered, bounced or opened.

Next