DASHBOARD · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Sites and API keys
What a site is, where its key comes from, and how to rotate it.
A site is one website or app that sends email or receives form submissions through SecureSMTP. Each site has its own API key, notify email, sender name, sending domain, captcha setting, webhooks and blocks. Emails and submissions are logged per site. The monthly email count is per account: all your sites together.
Add a site
Open Sites (/app/forms/sites) and add a site. The wizard (/app/forms/sites/new) asks for:
| Field | Used for |
|---|---|
| Display name | How the site shows in the dashboard. Also the default sender name. |
| Website domain | The site’s domain, for example example.com. |
| Notify email | Where form submissions go when a request names no recipient. |
| From name (optional) | Sender name for notification emails. If empty, the display name is used. |
Then pick how the site sends email:
- Use SecureSMTP delivery — mail goes out from
[email protected]with your sender name. No DNS changes. - Send from my own domain — add a sending domain and publish its DNS records. Until it is verified, the site sends with SecureSMTP delivery. See Domains and DNS.
The last step shows the API key.
The API key
- Format:
qcs_live_followed by 32 characters. - It is shown in full once, when the site is created, and emailed to the account owner. We store only a hash of it, so we cannot show it again later.
- API keys (
/app/forms/api-keys) shows a short form of each key (the start and the last four characters), and the SMTP settings. - The same key works everywhere: in the
x-securessmtp-api-keyheader for the API, in the WordPress plugin, as the SMTP password, and as a bearer token for the MCP server.
export SECURESSMTP_API_KEY="qcs_live_..."Rotate a key
- Open API keys (
/app/forms/api-keys) and click Rotate key on the site. Confirm. - The new key is shown once. Copy it. It is not emailed.
- The old key stops working at once. Put the new key everywhere the old one was: the WordPress plugin, your environment variables, SMTP settings and MCP clients that use it.
Rotate when a key may have leaked, or when someone who knew it should no longer have access.
Edit a site
On Sites, click Edit to change the display name, domain, notify email or from name. Changing the domain marks the site as not verified again; it becomes verified the next time it sends an email, receives a form submission, or the WordPress plugin checks in from the new domain.
How many sites your plan allows
| Plan | Sites |
|---|---|
| Free | 1 |
| Starter | 3 |
| Pro | 10 |
| Business | Unlimited |
The limit is checked when you add a site. Sites you already have keep working if you move to a smaller plan. See Plans and limits.
Disabled sites
Click Deactivate on Sites to switch a site off, and Reactivate to switch it back on. SecureSMTP can also disable a site, for example when most of its recent form submissions are spam — see Blocks.
While a site is disabled:
- Sending, forms, sites and sequence endpoints answer
403 site_disabled. - SMTP logins with the key fail (
535). A message sent in a session that was already logged in gets550 5.7.1. - The WordPress plugin sends email with WordPress’s own mailer instead.
GET /blocks/statusandPOST /blocks/liftstill work, so the plugin can show why.
POST /blocks/lift only reactivates sites that SecureSMTP disabled automatically.