Obsidian SuiteDocumentation
Obsidian Mail Client: all chapters

Docs / Obsidian Mail Client / Privacy & security

Secure links

A secure link sends encrypted mail to anyone, without certificates or a special app on their side. The message is encrypted on your PC and put on your organization's Obsidian Suite portal; the recipients get an ordinary email with a link, and read the message in their browser.

What you need

Secure links work through an Obsidian Suite portal, so you need an API token for it. Ask your Obsidian Suite administrator, or contact Larström Technologies.

Set it up

  1. Open File > Options > Secure Links.
  2. Obsidian portal address: leave https://portal.obsidiansuite.net unless you were given another address.
  3. API token: paste the token you were given.
  4. Click Test. It shows ✓ Connected when the portal accepts the token, or Could not connect with the reason.
  5. Click OK.

The token is kept in Windows Credential Manager, not in the app's files.

Send a secure message

  1. Write the message as usual, with its recipients, attachments and formatting.
  2. Turn on Secure link in the message window.
  3. Click Send.

The app encrypts the message, attachments included, and uploads it to the portal; the status line shows Encrypting and uploading…. What goes out by email is only a notice to every recipient (To, Cc and Bcc): Secure message from your name, with an Open the secure message button and the date until which it can be opened. Your real subject stays inside the encrypted message.

If the upload fails, nothing is sent and the message window says why (for example when no API token is set). Undo Send works as usual and also takes the upload back off the portal.

Encrypt and Sign (S/MIME) are not applied to a secure link: the link replaces them.

What the recipients see

They open the link in a browser, confirm their email address with a one-time code sent to it, and read the message there. They can reply securely from the same page. The key that unlocks the message is only in the link, never stored on the portal, so the portal can't read your message.

A link can be opened for 30 days.

For the portal's side, see the Obsidian Suite guide: Secure messages.

Replies and who opened it

Send / Receive > Secure Messages lists your most recent secure messages. For each one it shows when it was sent, until when it can be opened (or that it was withdrawn or has expired), and which recipients have opened it and when. Replies appear under the message; they are decrypted on your PC, the only place that has the key.

  • Copy link copies the full link, key included. Anyone who has it and can read the recipient's mailbox could open the message, so share it carefully.
  • Withdraw makes the message impossible to open from then on; the portal deletes it.

The app checks for new replies after a mail check, at most every ten minutes. When one arrives, the status line says so and, if the app is in the background, Windows shows a Reply to a secure message notification.

The app has to be running for these checks (see Troubleshooting).