Vũ Văn HảiFull-stack · AI-native
GuidesBlog
Discuss a project

© 2026 Vu Van Hai · Written from real deployment experience.

HomeGuidesBlogRSS
  1. Guides
  2. /Integrations
  3. /Send email with the Brevo API when your VPS blocks SMTP

Send email with the Brevo API when your VPS blocks SMTP

Send verification emails from a VPS through the Brevo HTTP API v3 (HTTPS, port 443) instead of blocked SMTP ports: verify the sender and domain (DKIM, SPF), grab the right API key, configure .env, and fix common errors.

Updated: Sep 21, 20266 min read
EmailBrevoVPS
On this page
  • Quick reference
  • Step 1: Create a Brevo account
  • Step 2: Verify the sender
  • Step 3: Verify the domain
  • Step 4: Get the API key
  • Step 5: Configure the application (.env)
  • Troubleshooting

Some VPS providers (DigitalOcean, Vultr, Linode and others) block the SMTP ports (465, 587) by default to fight spam, so sending mail over plain SMTP (Gmail SMTP, for example) from a VPS fails with a timeout or connection refused. This guide uses the Brevo HTTP API v3 instead - it talks over HTTPS on port 443, which is never blocked - to send verification emails, and also fixes the wrong sender address showing up in the inbox.

Throughout, example.com is your domain, [email protected] and [email protected] are sender addresses, MyApp is your application name, and <account-id> and <brevo-code> are codes Brevo generates for you. Replace them with your real values.

Quick reference

  1. Sign up: create a free account on Brevo.
  2. Verify the sender email: go to Senders, Domains & Dedicated IPs > Senders, add the sender email and click the confirmation link in your inbox.
  3. Verify the domain (if you send from a custom domain): open the Domains tab, add the domain, then create 3 DNS records: TXT (DKIM), TXT (SPF) and CNAME (Return-Path).
  4. Get the API key: Profile menu > SMTP & API > API keys & MCP tab, click Generate a new API key (it looks like xkeysib-...). Do NOT take the SMTP key.
  5. Configure the app: put the new API key in .env, then restart Docker (docker compose down and docker compose up -d --build).

Step 1: Create a Brevo account

Brevo has a free-forever plan that allows 300 emails/day - plenty for OTP and account verification emails.

  1. Open the home page brevo.com.
  2. Click Sign up free in the top-right corner.
  3. Sign up with Google for speed, or with a regular email address.
  4. Fill in the personal/company details they ask for (no credit card required).

Step 2: Verify the sender

Brevo does NOT let you send email through the API until you prove you own the address you are sending from.

  1. In the Brevo dashboard, open Senders, Domains & Dedicated IPs (in the menu at the bottom right, or in the top-right corner).
  2. Select the Senders tab.
  3. Click Add a sender.
  4. Enter the details:
    • From Name: the display name of the sender, e.g. MyApp or MyApp Admin.
    • From Email: the address that will send the mail, e.g. [email protected] or [email protected].
  5. Open your inbox, find the email from Brevo and click the Verify button/link.
  6. Make sure the sender status in Brevo changes to Active/Verified.

Step 3: Verify the domain

If you send from a custom domain (e.g. [email protected]), recipients will often see a strange sender such as admin@<account-id>.brevosend.com instead of your actual address.

Why: the sender domain is not verified yet, so Brevo automatically routes the email through one of its own subdomains to keep it out of Spam.

How to fix it:

  1. Go to Settings > Senders & Domains (or the equivalent dashboard section) and select the Domains tab.
  2. Click Add a domain and enter your domain (e.g. example.com).
  3. Add the 3 DNS records Brevo asks for (table below) in the DNS management page of your domain (Cloudflare, MatBao, Tenten...).
  4. Once DNS is configured, go back to Brevo and click Verify. Allow a few minutes (up to a few hours) for DNS to propagate.
  5. After verification succeeds, add the sender [email protected] again as in Step 2. Mail will now show the correct [email protected] and stay out of Spam.

The three DNS records to create:

TypeName (Host/Name)Purpose
TXT (DKIM)mail._domainkey.example.comProves the email really comes from you
TXT (SPF)example.comAuthorizes Brevo to send email on your behalf
CNAME (Return-Path)<brevo-code>.example.comTracks returned mail (tracking bounces)

The exact value of each record is shown on the Brevo domain page - copy it verbatim into your DNS management page.

Step 4: Get the API key

Brevo has 2 kinds of key: the SMTP key and the API key. You MUST take the API key - the SMTP key does not work with the HTTP API.

Key typeHow to recognize itUsable here
SMTP key (SMTP password)Starts with *** and ends with a few short lettersNo
API keyExtremely long and always starts with xkeysib-Yes
  1. Click your Profile in the top-right corner of Brevo and choose SMTP & API.
  2. This screen has 2 tabs: "SMTP" and "API keys & MCP".
  3. Select the API keys & MCP tab.
  4. Click Generate a new API key.
  5. Give it a memorable name (e.g. website-prod-api).
  6. Click Generate.
  7. Copy the key (xkeysib-...) immediately. It is shown only once.

Step 5: Configure the application (.env)

With everything in hand, open the .env file on the VPS (or your local machine) and update the settings. The variable names below come from a sample app - rename them to match yours:

# 1. Send through the HTTP API (brevo) instead of traditional SMTP
Email__Provider=brevo

# 2. Paste the API key (starts with xkeysib-) from Step 4 here
Email__BrevoApiKey=xkeysib-<your-api-key>

# 3. Use EXACTLY the email you verified in Step 2
Email__SenderEmail=[email protected]

# 4. Sender display name (should match the From Name in Step 2)
Email__SenderName=MyApp

Restart the Docker application:

docker compose down
docker compose up -d --build

Troubleshooting

SymptomFix
The frontend shows an error (spinner never stops) and the backend log says "Unauthorized"You pasted the SMTP password instead of the Brevo API key. Revisit Step 4 and make sure the key starts with xkeysib-
The log reports API success (201 Created) but NO email arrivesStep 2 (sender email verification) was skipped, so Brevo blocks the send. The message may also have been held by Brevo's moderation filter (suspected spam/phishing) - check the Email Log in the Brevo dashboard for details
Mail lands in Spam/JunkOn the first sends the mailbox (Gmail, for example) does not "know" you yet - ask recipients to open the spam folder and mark the message Not spam a few times to build reputation (deliverability). Also make sure the DKIM/SPF DNS records from Step 3 are in place
Mail shows the wrong sender, like admin@<account-id>.brevosend.comThe domain is not verified (Step 3). You must verify the domain in Brevo before you can send from your own domain address
NextConfigure the SePay webhook and API key to accept payments

Related articles

  • Where to put apps on a VPS: the /opt/apps directory layout

    A simple convention for app code on a VPS: keep each app in its own folder under /opt/apps, chown the parent folder once, and git clone, git pull and .env edits never need sudo again.

    VPS

    VPS
  • Migrate a PostgreSQL database between two VPS with pg_dump

    Move an entire PostgreSQL database (schema and data) from a source VPS to a target VPS through your local machine: dump with pg_dump, restore in a single transaction, verify row counts, then cut over and roll back safely.

    Database

    Database
  • Connect to PostgreSQL on a VPS through an SSH tunnel

    Use an SSH tunnel so your dev machine can reach PostgreSQL on a VPS without exposing port 5432 to the internet, plus the DATABASE_URL setup for local and production.

    Database

    Database

Written by Vu Van Hai

I'm Hai, a full-stack developer based in Ho Chi Minh City. These guides come from systems I built and run myself. Need to build or untangle something similar? Get in touch.

Discuss a projectMore guides

Spot a mistake or a command that no longer works? Let me know

On this page

  • Quick reference
  • Step 1: Create a Brevo account
  • Step 2: Verify the sender
  • Step 3: Verify the domain
  • Step 4: Get the API key
  • Step 5: Configure the application (.env)
  • Troubleshooting