Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Compliance

Journaling

Journaling keeps a record of email for regulators, auditors and legal teams. For every message a journal rule covers, the server sends a journal report to a journal address: a short summary of who really sent and received the message, with the message itself attached. Unlike a copy or a blind copy, the report shows everyone - including blind-copied people and the members behind group addresses. Journal rules are under Journaling.

Set up journaling

  1. Create a mailbox for the reports: Users & groups > New > User, for example [email protected]. Hide it from the address book and give only the reviewers access to it (see Shared access and delegation). An outside archiving service's address works too.
  2. Open Journaling and choose New journal rule.
  3. Choose Which mail: all mail, only mail to or from outside the organization, or only mail between people inside.
  4. Choose Whose mail: everyone, or one person or group (their sent and received mail; for a group, every member's).
  5. Enter the address the reports go to and choose Create journal rule.

Mail queued from then on is journaled. Journaling is not retroactive: earlier mail is not reported.

What a journal report contains

The report's subject is the message's subject. Its text lists the envelope, for example:

Sender: [email protected]
Subject: Merger
Message-Id: <[email protected]>
To: [email protected]
Cc: [email protected], Expanded: [email protected]
Bcc: [email protected]
  • To / Cc say where the recipient was addressed; Bcc means they received it without being on To or Cc.
  • Expanded names the group through which a member received it.
  • On-Behalf-Of appears when the message was sent as someone else (send as / send on behalf).

The message is attached exactly as recipients received it, after mail flow rules (a disclaimer a rule added is in the attached copy). When a rule gave some recipients a changed copy, each copy gets its own report.

Good to know

  • Journal reports are never journaled again, and mail flow rules do not act on them.
  • Several rules with the same journal address produce one report per message; the report's X-OMS-Journal-Rule header names the rules.
  • Reports are sent without a return address, so a journal address that stops accepting mail silently loses reports. Check the journal mailbox now and then, and watch Track a message for Journaled entries.
  • Journaling copies mail; it does not keep people from deleting their own copies. To keep mail from being deleted, use a hold (coming with retention and holds).

From the command line

oms journalrule list <org>
oms journalrule new <org> "<name>" <journal-address> [--scope Global|Internal|External] [--recipient <address>]
oms journalrule enable|disable|remove <org> "<name>"