Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Compliance

Mailbox audit log

The mailbox audit log records what happens to the mail inside mailboxes: who deleted, moved or changed messages, who sent mail as someone else, and who changed inbox rules. It answers questions like "who deleted the contract from the shared inbox?" or "did anyone else read and forward the CEO's mail?". It is Exchange's mailbox auditing. Search it under Mailbox audit log.

Change history is different: it records changes administrators make to the organization (people, domains, rules). The mailbox audit log records actions on mailbox content.

What is recorded

Each entry says when, in which mailbox, what happened, who did it and how (webmail, IMAP, phone, admin center), from which address, in which folder, and the subjects of the messages involved (up to 20).

Who did it is one of three logon types:

Logon typeMeaning
OwnerThe mailbox's own person
DelegateSomeone using another person's mailbox or a shared mailbox (Full Access, Send As, Send on Behalf)
AdministratorAn action taken in the admin center, for example recovering deleted mail

By default (as in Exchange) the log records:

ActionOwnerDelegateAdministrator
Created an itemyesyes
Changed items (flags, categories, calendar and contact edits)yesyesyes
Copied itemsyes
Moved itemsyes
Moved to Deleted Itemsyesyesyes
Deleted (recoverable)yesyesyes
Permanently deletedyesyesyes
Sent as / on behalf of the mailboxyesyes
Changed inbox rulesyesyesyes

Change what is recorded under What is recorded on the same page. Reading mail is never recorded, and neither is what the server does by itself: delivering mail, running inbox rules, auto-archiving, or clearing old deleted items.

For a delegate who opens a shared mailbox in a mail app with [email protected]\[email protected], entries name the person who signed in, not the shared mailbox.

Filter by mailbox, by who did it, by what happened, by logon type and by date, then Search. Newest entries come first; Show older entries loads more. Export CSV downloads what the filters match (up to 5,000 entries) for a spreadsheet or a report; exports are noted in Change history.

From a person's page in Users & groups, Who deleted or changed what opens the log for their mailbox.

Only organization administrators can read the log, because entries show the subjects of other people's mail.

How long entries are kept

Entries are kept for 90 days by default and then removed automatically. Set Keep entries for to what your regulations require (for example 365 days, or 6 years for HIPAA-covered records). Entries stay after a mailbox is deleted, until their time is up.

From the command line

oms mailboxaudit search <org> [--mailbox <address>] [--actor <address>] [--operation SoftDelete] [--days 7]