Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Mail flow

Mail flow rules

Mail flow rules act on messages while they pass through the server, before anyone receives them. Use them to tag mail from outside, add a disclaimer, block risky attachments, copy mail to a supervisor, or redirect mail for someone who has left. They are Exchange's transport rules. Each organization has its own rules, under Mail flow rules.

How rules work

  • Every message is checked once, as soon as it is queued: mail arriving from the internet, mail people send from webmail, phones and mail apps, and mail forwarded by inbox rules. Reports the server writes itself (non-delivery reports, incident reports) are not checked.
  • Rules run top to bottom. Use the arrows in the Order column to move a rule up or down. A later rule sees what earlier rules changed; for example, it can test a header an earlier rule set.
  • A rule applies when all of its conditions are true. A list (of words, people or domains) matches when any entry matches. A rule without conditions applies to every message.
  • Exceptions skip the rule: any single exception that is true is enough.
  • Conditions about recipients (A recipient is outside the organization, A recipient is one of these people) are checked for each recipient. When a rule changes a message for only some recipients, those recipients get their own changed copy and everyone else gets the original. A disclaimer for outside recipients never appears in the copy colleagues receive.
  • Stop checking more rules after this one matches ends the run for the recipients the rule matched.

The sender counts as inside the organization when they signed in to send (webmail, phones, mail apps with a password). Mail arriving from the internet always counts as from outside, even when it claims an address of your own domain; that is exactly the mail a Tag mail from outside rule should mark.

A recipient is inside the organization when the address belongs to a mailbox, group or public folder of the organization, or to one of its domains. Contacts (people outside shown in the address book) are outside.

Building a rule

  1. Open Mail flow rules and choose New rule.
  2. Pick a starting point: Tag mail from outside, Disclaimer on outgoing mail, Block dangerous attachments, Copy someone's mail, Redirect someone's mail, or Start from scratch.
  3. Under Apply this rule if, add conditions with Add a condition.... Type words, addresses or domains and press Enter after each one; addresses suggest people as you type.
  4. Under Do the following, add one or more actions.
  5. Optionally add exceptions, start and end dates, and a note about why the rule exists.
  6. Choose Create rule. It applies to messages queued from then on.

To check a rule before it affects anyone, set Mode to Test: matches are recorded in Track a message as Rule applied, with "matched in test mode" in the details, and nothing changes. Switch it to On when you are happy.

Try a message

Try a message shows which rules would act on a message you describe (sender, recipients, subject, text and attachment names), in order, and for which recipients. Nothing is sent.

Conditions

ConditionMatches when
The sender is inside / outside the organizationSee How rules work above
The sender is one of these people / a member of this groupAny address of that person counts; groups include nested groups
The sender's or a recipient's domain isThe domain or one of its subdomains (example.com also matches mail.example.com)
The sender's / a recipient's address includesPart of the address, for example noreply
A recipient is inside / outside, one of these people, a member of this groupChecked per recipient
The subject (or body) includes any of these wordsWhole words or phrases, upper or lower case alike
The subject (or body) matches a text patternA regular expression, for example invoice\s*#?\d{4,}
A message header includes / matchesThe named header, for example X-Mailer
The message has attachmentsFiles attached, including pictures inside the message
An attachment's file type isThe extension without the dot: exe, js, zip
An attachment's name matches a text patternA regular expression on the file name
An attachment's content includesText inside text, CSV, HTML, Word, Excel and PowerPoint files
An attachment / the message is larger thanA size in KB or MB
The message is marked asHigh, normal or low importance
The spam level is at leastThe spam confidence level (0-9) the gateway gave the message
The message contains sensitive informationSee Data loss prevention

Actions

ActionWhat happens
Add text to the start of the subjectAdds it once, for example [EXTERNAL] (keep the space at the end)
Add a disclaimerAdds text at the end (or top) of the message, in both its plain and formatted versions
Set / remove a message headerFor other systems that read headers
Add recipients to the To or Cc lineAdds them to the message and delivers to them too
Send a blind copy (Bcc) toDelivers a copy nobody else sees
Redirect the message toDelivers to these people instead of the matched recipients
Return it to the sender with a reasonThe sender gets a non-delivery report with your reason
Delete it without telling anyoneThe message is dropped for the matched recipients
Tell the senderA notice to a sender inside the organization; can also stop the message
Send an incident report toA report of what matched, with the message attached
Set the spam level-1 skips junk filtering; 5 or more sends it to Junk Email

Disclaimers on signed or encrypted mail

A signed or encrypted message cannot be changed without breaking it. For those, choose what the rule does instead: Wrap it (the default) sends a new message with your disclaimer and the original attached unchanged; Send it without the disclaimer; or Return it to the sender.

Seeing what rules did

  • Track a message shows Rule applied with what the rule did, Copy made by a rule when recipients got separate copies, Redirected, and Deleted by a rule.
  • The Matches column on Mail flow rules counts how often each rule matched, and when it last did.
  • Creating, changing, reordering and deleting rules is recorded in Change history.

A rule that fails (for example a text pattern that takes too long) is skipped for that message and noted in Track a message; the message is still delivered.

From the command line

oms transportrule list <org>
oms transportrule show <org> "<name>"          (prints the rule as JSON)
oms transportrule new <org> "<name>" --json rule.json [--priority 0]
oms transportrule set <org> "<name>" --json rule.json
oms transportrule enable|disable|remove <org> "<name>"

The JSON has the same shape show prints, for example:

{ "conditions": { "fromScope": "NotInOrganization" }, "actions": { "prependSubject": "[EXTERNAL] " } }