Docs / Obsidian Mail Server / Compliance
Journaling
Journaling keeps a record of email for regulators, auditors and legal teams. For every message a journal rule covers, the server sends a journal report to a journal address: a short summary of who really sent and received the message, with the message itself attached. Unlike a copy or a blind copy, the report shows everyone - including blind-copied people and the members behind group addresses. Journal rules are under Journaling.
Set up journaling
- Create a mailbox for the reports: Users & groups > New > User, for example
[email protected]. Hide it from the address book and give only the reviewers access to it (see Shared access and delegation). An outside archiving service's address works too. - Open Journaling and choose New journal rule.
- Choose Which mail: all mail, only mail to or from outside the organization, or only mail between people inside.
- Choose Whose mail: everyone, or one person or group (their sent and received mail; for a group, every member's).
- Enter the address the reports go to and choose Create journal rule.
Mail queued from then on is journaled. Journaling is not retroactive: earlier mail is not reported.
What a journal report contains
The report's subject is the message's subject. Its text lists the envelope, for example:
Sender: [email protected]
Subject: Merger
Message-Id: <[email protected]>
To: [email protected]
Cc: [email protected], Expanded: [email protected]
Bcc: [email protected]
- To / Cc say where the recipient was addressed; Bcc means they received it without being on To or Cc.
- Expanded names the group through which a member received it.
- On-Behalf-Of appears when the message was sent as someone else (send as / send on behalf).
The message is attached exactly as recipients received it, after mail flow rules (a disclaimer a rule added is in the attached copy). When a rule gave some recipients a changed copy, each copy gets its own report.
Good to know
- Journal reports are never journaled again, and mail flow rules do not act on them.
- Several rules with the same journal address produce one report per message; the report's
X-OMS-Journal-Ruleheader names the rules. - Reports are sent without a return address, so a journal address that stops accepting mail silently loses reports. Check the journal mailbox now and then, and watch Track a message for Journaled entries.
- Journaling copies mail; it does not keep people from deleting their own copies. To keep mail from being deleted, use a hold (coming with retention and holds).
From the command line
oms journalrule list <org>
oms journalrule new <org> "<name>" <journal-address> [--scope Global|Internal|External] [--recipient <address>]
oms journalrule enable|disable|remove <org> "<name>"