Send email with the Brevo API when your VPS blocks SMTP
Send verification emails from a VPS through the Brevo HTTP API v3 (HTTPS, port 443) instead of blocked SMTP ports: verify the sender and domain (DKIM, SPF), grab the right API key, configure .env, and fix common errors.
On this page
Some VPS providers (DigitalOcean, Vultr, Linode and others) block the SMTP ports (465, 587) by default to fight spam, so sending mail over plain SMTP (Gmail SMTP, for example) from a VPS fails with a timeout or connection refused. This guide uses the Brevo HTTP API v3 instead - it talks over HTTPS on port 443, which is never blocked - to send verification emails, and also fixes the wrong sender address showing up in the inbox.
Throughout, example.com is your domain, [email protected] and [email protected] are
sender addresses, MyApp is your application name, and <account-id> and <brevo-code>
are codes Brevo generates for you. Replace them with your real values.
Quick reference
- Sign up: create a free account on Brevo.
- Verify the sender email: go to
Senders, Domains & Dedicated IPs>Senders, add the sender email and click the confirmation link in your inbox. - Verify the domain (if you send from a custom domain): open the
Domainstab, add the domain, then create 3 DNS records:TXT (DKIM),TXT (SPF)andCNAME (Return-Path). - Get the API key: Profile menu >
SMTP & API>API keys & MCPtab, clickGenerate a new API key(it looks likexkeysib-...). Do NOT take the SMTP key. - Configure the app: put the new API key in
.env, then restart Docker (docker compose downanddocker compose up -d --build).
Step 1: Create a Brevo account
Brevo has a free-forever plan that allows 300 emails/day - plenty for OTP and account verification emails.
- Open the home page brevo.com.
- Click Sign up free in the top-right corner.
- Sign up with Google for speed, or with a regular email address.
- Fill in the personal/company details they ask for (no credit card required).
Step 2: Verify the sender
Brevo does NOT let you send email through the API until you prove you own the address you are sending from.
- In the Brevo dashboard, open Senders, Domains & Dedicated IPs (in the menu at the bottom right, or in the top-right corner).
- Select the Senders tab.
- Click Add a sender.
- Enter the details:
- From Name: the display name of the sender, e.g.
MyApporMyApp Admin. - From Email: the address that will send the mail, e.g.
[email protected]or[email protected].
- From Name: the display name of the sender, e.g.
- Open your inbox, find the email from Brevo and click the Verify button/link.
- Make sure the sender status in Brevo changes to Active/Verified.
Step 3: Verify the domain
If you send from a custom domain (e.g. [email protected]), recipients will often see a
strange sender such as
admin@<account-id>.brevosend.com instead of your actual address.
Why: the sender domain is not verified yet, so Brevo automatically routes the email through one of its own subdomains to keep it out of Spam.
How to fix it:
- Go to
Settings > Senders & Domains(or the equivalent dashboard section) and select the Domains tab. - Click Add a domain and enter your domain (e.g.
example.com). - Add the 3 DNS records Brevo asks for (table below) in the DNS management page of your domain (Cloudflare, MatBao, Tenten...).
- Once DNS is configured, go back to Brevo and click Verify. Allow a few minutes (up to a few hours) for DNS to propagate.
- After verification succeeds, add the sender
[email protected]again as in Step 2. Mail will now show the correct[email protected]and stay out of Spam.
The three DNS records to create:
| Type | Name (Host/Name) | Purpose |
|---|---|---|
| TXT (DKIM) | mail._domainkey.example.com | Proves the email really comes from you |
| TXT (SPF) | example.com | Authorizes Brevo to send email on your behalf |
| CNAME (Return-Path) | <brevo-code>.example.com | Tracks returned mail (tracking bounces) |
The exact value of each record is shown on the Brevo domain page - copy it verbatim into your DNS management page.
Step 4: Get the API key
Brevo has 2 kinds of key: the SMTP key and the API key. You MUST take the API key - the SMTP key does not work with the HTTP API.
| Key type | How to recognize it | Usable here |
|---|---|---|
| SMTP key (SMTP password) | Starts with *** and ends with a few short letters | No |
| API key | Extremely long and always starts with xkeysib- | Yes |
- Click your Profile in the top-right corner of Brevo and choose SMTP & API.
- This screen has 2 tabs: "SMTP" and "API keys & MCP".
- Select the API keys & MCP tab.
- Click Generate a new API key.
- Give it a memorable name (e.g.
website-prod-api). - Click Generate.
- Copy the key (
xkeysib-...) immediately. It is shown only once.
Step 5: Configure the application (.env)
With everything in hand, open the .env file on the VPS (or your local machine) and
update the settings. The variable names below come from a sample app - rename them to
match yours:
# 1. Send through the HTTP API (brevo) instead of traditional SMTP
Email__Provider=brevo
# 2. Paste the API key (starts with xkeysib-) from Step 4 here
Email__BrevoApiKey=xkeysib-<your-api-key>
# 3. Use EXACTLY the email you verified in Step 2
Email__SenderEmail=[email protected]
# 4. Sender display name (should match the From Name in Step 2)
Email__SenderName=MyAppRestart the Docker application:
docker compose down
docker compose up -d --buildTroubleshooting
| Symptom | Fix |
|---|---|
| The frontend shows an error (spinner never stops) and the backend log says "Unauthorized" | You pasted the SMTP password instead of the Brevo API key. Revisit Step 4 and make sure the key starts with xkeysib- |
| The log reports API success (201 Created) but NO email arrives | Step 2 (sender email verification) was skipped, so Brevo blocks the send. The message may also have been held by Brevo's moderation filter (suspected spam/phishing) - check the Email Log in the Brevo dashboard for details |
| Mail lands in Spam/Junk | On the first sends the mailbox (Gmail, for example) does not "know" you yet - ask recipients to open the spam folder and mark the message Not spam a few times to build reputation (deliverability). Also make sure the DKIM/SPF DNS records from Step 3 are in place |
Mail shows the wrong sender, like admin@<account-id>.brevosend.com | The domain is not verified (Step 3). You must verify the domain in Brevo before you can send from your own domain address |