Connect SpamTitan
SpamTitan is TitanHQ's email security gateway. It sits in front of your mail, filters spam, malware and impersonation, holds what it blocks in quarantine, and gives you per-customer control of who may…
Written By Christopher Scaminaci
Last updated About 3 hours ago
SpamTitan is TitanHQ's email security gateway. It sits in front of your mail, filters spam, malware and impersonation, holds what it blocks in quarantine, and gives you per-customer control of who may send, who may receive and how outbound mail leaves. StackJack talks to SpamTitan through its REST API, the same interface the web console is built on.
Connecting SpamTitan to StackJack gives your AI assistant a family of spamtitan_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Work the quarantine: list what is held, read one message, and release or delete it; search message history across a time window; read the mail queue; and ask SpamTitan to send a quarantine report, to everyone or to one user
- Report: scan summaries and the other reports SpamTitan keeps, for the whole system or for one customer
- Manage sender and IP lists: the sender allow and block lists and the allowed and blocked IP lists, for the whole system or scoped to one customer, domain or user
- Manage customers, domains and users: customers (SpamTitan calls them domain groups), the domains under them, each domain's filtering policy, recipient verification and authentication settings, and users with their aliases. Suspend, lock out and reinstate a customer
- Run mail authentication: SPF, DKIM checking and bypass, DMARC (including the failure action and reporting), the DKIM keys a domain signs with, and ARC signing keys
- Tune filtering: pattern filters, geoblocking with its country rules and exemptions, Link Lock, DNS blocklists and their bypass lists, sandboxing, and rate controls
- Run the outbound side: outbound relay, trusted networks, SASL, smarthosts and outbound TLS policy
- Administer the appliance: read and set appliance configuration, apply a license file, request a Let's Encrypt certificate, open and close the support tunnel, and change the account password. The configuration, license, certificate and support tunnel tools need a Global Admin
How StackJack authenticates to SpamTitan
SpamTitan uses an API token. An admin makes it once, and StackJack sends it as a Bearer token on every request. There is no client ID, no sign-in and no refresh. The token alone authenticates, and it expires on the date chosen when it was made: one year by default. Nothing renews it, so put the expiry in your calendar.
Two things decide what StackJack can do:
- The Location. A token is valid only on the cluster that made it. You choose the Location in StackJack, and StackJack uses that cluster's API address, never the sign-in address.
- The admin who made the token. A SpamTitan token has no scopes. It carries the role of the admin who made it, and SpamTitan decides what each role may call.
Pick your location
Your cluster is part of the address you sign in at. Signing in at https://us1-smtp-ui.titanhq.com means your cluster is us1. The clusters are us1, us2, us3, us4, eu1, uk1, ap1 and ca1. StackJack stores your choice and fills in the API address for you.
The API address is not the sign-in address. The sign-in site answers every request with a web page, so a connection pointed at it could never tell a good token from a bad one. StackJack refuses that address. If you paste a sign-in address into the host box, StackJack switches the Location to the matching cluster and tells you so.
If you run SpamTitan Gateway, a Private Cloud, or an older cloud host, choose Other SpamTitan host and enter that host's own address, starting with https://. StackJack reaches it from the internet, so it must be public, over HTTPS, with a certificate a browser would trust. A Private Cloud instance uses a self-signed certificate by default, which StackJack rejects until a trusted certificate is installed.
Steps
Find your location. Look at the address you sign in at and note the cluster, for example us1.
Make an API token. On current SpamTitan Cloud (version 9.00 and later) the web console has no API key screen, so the token is made with one request. Open a terminal and run the command below, with your own admin email and password and your own cluster in the address. The password stays in your terminal and StackJack never sees it. Copy the
access_tokenvalue from the answer. The token is shown once.curl -X POST https://us1-smtp-api.titanhq.com/restapi/auth/tokens \ -H "Accept: application/json" -H "Content-Type: application/json" \ -d '{"email":"admin@example.com","password":"your-password"}'The token lasts one year unless the request carries an
expiration_date. Do not ask for a token that never expires: SpamTitan says such a token can only be removed through a support request. On SpamTitan 8.00 or earlier, open Settings, then User Management, then RestAPI Keys, and create a key there instead. SpamTitan does not document how the request behaves for an account with two-factor authentication. If it is refused, make the token from an admin account that can.Choose which admin the token belongs to. A Global Admin reaches everything, including appliance-wide settings. An MSP admin can act on each of their customers. A Domain Group Admin or a Domain Admin reaches only their own customers or domains, and a User reaches only their own mailbox. Make the token from the admin whose reach matches what you want StackJack to manage.
Enter it in StackJack. Open Connectors, choose SpamTitan, pick your Location (or Other and the host address), paste the token and save.
Test the connection. StackJack reads the system geoblocking setting, which every admin role can read, so the test proves the token and the address without changing anything.
The token is stored encrypted and is not shown again. Enter it again whenever you edit this connector. Changing only the Location asks for the token again, which is deliberate: a save can never quietly replace a working token with a blank one.
What to know before your AI uses this connector
Working across your customers
SpamTitan calls a customer a domain group. If you are an MSP, most tools take an optional customer, domain or user, so the same tool can act on the whole system or on one of them. Leave all three out and the tool acts at the level of the token. Give one and StackJack uses SpamTitan's address for that scope. Give more than one and the tool refuses, because SpamTitan has no address that means two scopes at once. The customer list tool shows the ids.
A few tools need a scope and refuse without one: removing a geoblocking exemption and creating or removing a Link Lock policy act on one customer, domain or user, never on the whole system.
Some tools change what mail is filtered or who sees it
Every change is a Pro tool, and the ones that matter most are labeled as changes that need approval. An AI assistant that honors that label shows you the action and waits for you to confirm. The confirmation is the assistant's, not StackJack's. A StackJack automation cannot run one of these at all until somebody signs off that it may take consequential actions on its own.
Those tools fall into groups:
- Entries that exempt mail from filtering. An allow list entry, an allowed IP and a bypass entry tell SpamTitan to stop checking something. Your AI is told what each one exempts before it writes it. SpamTitan's own documentation also says that deleting an allow list entry, a block list entry or a pattern filter, or updating an allow list entry, deletes every other entry that belongs to the same customer, and that updating a block list entry updates all of that customer's entries. Those tools say so in their descriptions, and they are labeled as changes that need approval.
- Protection switches. SPF, DKIM, DMARC, geoblocking, sandboxing, rate controls and the others can turn a protection off for everything in their scope. Updating a customer, a domain's policy or a user's policy can do the same, because each can switch spam, virus, attachment or geoblocking protection off for that customer, domain or user. Those updates are labeled as changes that need approval too.
- Deletes. Deleting a domain, a user, a customer's lists or a key cannot be undone. Deletes that accept either one id or a list of ids refuse to run with neither.
- Tools that store a password or a key. Creating or updating a user or a domain, changing how a domain's users sign in, adding or changing a smarthost, setting SASL or the outbound TLS client certificate, and creating a DKIM or ARC signing key can store a password, a bind password or a key, and a user can be given administrator roles. Replacing an RBL, which removes one and adds another, is labeled the same way. These are labeled as changes that need approval too.
- Reaching people. Releasing quarantined mail delivers it. Requesting a quarantine report mails the users it covers. Suspending a customer or locking one out stops their mail.
- Appliance-wide changes. Appliance configuration, the license, certificates, the support tunnel, the server-wide smarthost and the system outbound TLS policy apply to the whole system.
Some answers contain secrets
The DKIM and ARC key tools return private signing keys. The appliance configuration holds stored secrets, and the license record identifies your license. These answers are never recorded or saved as a file, and the tools that take a password, a key or a license file keep those arguments out of StackJack's records too. A tool that is asked to read a key will return it to the assistant that asked, so grant the key tools only to assistants you would trust with the key.
Releasing or deleting quarantined mail needs a second id
SpamTitan identifies a quarantined message by two values: its id and a secret_id. Both come back from the quarantine list and from the message read. Release and delete each need both, so the assistant lists or reads the message first.
Quarantine and message trace search the whole cluster by default
SpamTitan's own default is to search only the node that answered. StackJack asks for all nodes for the quarantine list and the message trace, because a single node would hide part of your mail. You can narrow it with the cluster argument. Message trace requires a start and an end date and a recipient.
Lists come in pages
Most list tools accept a page size up to 100 and a page number starting at 1. Ask for a page at a time and use SpamTitan's filter and sort arguments to narrow a large list. Five small lists are not paged, because SpamTitan documents no paging for them: geoblocking rules, geoblocking exemptions, RBLs, rate control policies and outbound hostnames.
What StackJack does not offer
StackJack holds one token that you made. It does not make, list, revoke or restore tokens, and it does not turn two-factor authentication on or off for the admin account. Those are your own credential management, and revoking tokens in particular could cut StackJack off from your SpamTitan.
Plans
Reading is free. Every change needs the Pro plan on this connector.
Tool reference
See the generated SpamTitan tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.
SpamTitan publishes no rate limit for its API, so StackJack paces requests on its own. Pacing smooths a burst. It does not guarantee that every call arrives, so check whether a change landed before repeating it. See Retrying a failed or timed-out write.
Troubleshooting
"SpamTitan rejected the API token" (401). A 401 on a connection that used to work almost always means the token expired. Tokens last one year by default and cannot be renewed: make a new one and paste it in. If the token is new, check the Location. A token is valid only on the cluster that made it, so a token from one cluster fails on another.
"Accepted the token but not for this action" (403). The admin who made the token cannot call that route. Appliance-wide settings (configuration, license, certificates, the support tunnel and system-wide filtering) need a Global Admin, and per-customer or per-domain routes need at least the matching Domain Group Admin or Domain Admin. Make a new token from an admin whose role can reach it.
"Something answered at that address, but it was not the SpamTitan API." The address is probably the web console (a -smtp-ui address) or another service. Choose your Location again so StackJack uses the cluster's API address, or enter your own host's address under Other.
"That route or record does not exist" (404). Check the id, domain or user first. The list tools show what exists. If the record exists, your edition may not serve the route: SpamTitan Cloud serves some documented routes only through its generic tier routes, and a Gateway or Private Cloud on an older version lacks routes added later.
"A value in the request was rejected" (422). SpamTitan names the field that failed, such as an address, a mask or a required combination of fields. Correct it and try again.
Nothing connects to my Gateway or Private Cloud. StackJack reaches your host from the internet over HTTPS. Check that the host is public, the port is open, and the certificate is one a browser would trust. A self-signed certificate is rejected.
The connector worked and then stopped, with no change on your side. Check the token's expiry date first. Then confirm the admin who made it still exists and still has the same role.
SpamTitan tools
spamtitan_ · 199 tools · Free 84 · Pro 115
Customers
Domain DKIM keys
Domain authentication
Domains
Users and aliases
Allowed IPs
Blocked IPs
Sender allow list
Sender block list
Mail queue
Message trace
Quarantine
Reports
ARC signing keys
DKIM checking and bypass
DMARC
SPF
Geoblocking
Geoblocking exemptions
Geoblocking rules
Link Lock
Pattern filters
RBL bypass
RBL lists
Rate controls
Sandboxing
Outbound TLS
Outbound relay
SASL
Smarthosts
Trusted networks
Admin account
Appliance configuration
License and certificate
Support tunnel
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team