DASHBOARD · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Sites and API keys

What a site is, where its key comes from, and how to rotate it.

A site is one website or app that sends email or receives form submissions through SecureSMTP. Each site has its own API key, notify email, sender name, sending domain, captcha setting, webhooks and blocks. Emails and submissions are logged per site. The monthly email count is per account: all your sites together.

Add a site

Open Sites (/app/forms/sites) and add a site. The wizard (/app/forms/sites/new) asks for:

FieldUsed for
Display nameHow the site shows in the dashboard. Also the default sender name.
Website domainThe site’s domain, for example example.com.
Notify emailWhere form submissions go when a request names no recipient.
From name (optional)Sender name for notification emails. If empty, the display name is used.

Then pick how the site sends email:

  • Use SecureSMTP delivery — mail goes out from [email protected] with your sender name. No DNS changes.
  • Send from my own domain — add a sending domain and publish its DNS records. Until it is verified, the site sends with SecureSMTP delivery. See Domains and DNS.

The last step shows the API key.

The API key

  • Format: qcs_live_ followed by 32 characters.
  • It is shown in full once, when the site is created, and emailed to the account owner. We store only a hash of it, so we cannot show it again later.
  • API keys (/app/forms/api-keys) shows a short form of each key (the start and the last four characters), and the SMTP settings.
  • The same key works everywhere: in the x-securessmtp-api-key header for the API, in the WordPress plugin, as the SMTP password, and as a bearer token for the MCP server.
Shell
export SECURESSMTP_API_KEY="qcs_live_..."
Keep the key on your server. Do not put it in browser JavaScript, a mobile app or a public repository.

Rotate a key

  1. Open API keys (/app/forms/api-keys) and click Rotate key on the site. Confirm.
  2. The new key is shown once. Copy it. It is not emailed.
  3. The old key stops working at once. Put the new key everywhere the old one was: the WordPress plugin, your environment variables, SMTP settings and MCP clients that use it.

Rotate when a key may have leaked, or when someone who knew it should no longer have access.

Edit a site

On Sites, click Edit to change the display name, domain, notify email or from name. Changing the domain marks the site as not verified again; it becomes verified the next time it sends an email, receives a form submission, or the WordPress plugin checks in from the new domain.

How many sites your plan allows

PlanSites
Free1
Starter3
Pro10
BusinessUnlimited

The limit is checked when you add a site. Sites you already have keep working if you move to a smaller plan. See Plans and limits.

Disabled sites

Click Deactivate on Sites to switch a site off, and Reactivate to switch it back on. SecureSMTP can also disable a site, for example when most of its recent form submissions are spam — see Blocks.

While a site is disabled:

  • Sending, forms, sites and sequence endpoints answer 403 site_disabled.
  • SMTP logins with the key fail (535). A message sent in a session that was already logged in gets 550 5.7.1.
  • The WordPress plugin sends email with WordPress’s own mailer instead.
  • GET /blocks/status and POST /blocks/lift still work, so the plugin can show why.
A site you deactivated yourself is turned back on with Reactivate on the Sites page. POST /blocks/lift only reactivates sites that SecureSMTP disabled automatically.