Docs / Obsidian Mail Server / Compliance
Mailbox audit log
The mailbox audit log records what happens to the mail inside mailboxes: who deleted, moved or changed messages, who sent mail as someone else, and who changed inbox rules. It answers questions like "who deleted the contract from the shared inbox?" or "did anyone else read and forward the CEO's mail?". It is Exchange's mailbox auditing. Search it under Mailbox audit log.
Change history is different: it records changes administrators make to the organization (people, domains, rules). The mailbox audit log records actions on mailbox content.
What is recorded
Each entry says when, in which mailbox, what happened, who did it and how (webmail, IMAP, phone, admin center), from which address, in which folder, and the subjects of the messages involved (up to 20).
Who did it is one of three logon types:
| Logon type | Meaning |
|---|---|
| Owner | The mailbox's own person |
| Delegate | Someone using another person's mailbox or a shared mailbox (Full Access, Send As, Send on Behalf) |
| Administrator | An action taken in the admin center, for example recovering deleted mail |
By default (as in Exchange) the log records:
| Action | Owner | Delegate | Administrator |
|---|---|---|---|
| Created an item | yes | yes | |
| Changed items (flags, categories, calendar and contact edits) | yes | yes | yes |
| Copied items | yes | ||
| Moved items | yes | ||
| Moved to Deleted Items | yes | yes | yes |
| Deleted (recoverable) | yes | yes | yes |
| Permanently deleted | yes | yes | yes |
| Sent as / on behalf of the mailbox | yes | yes | |
| Changed inbox rules | yes | yes | yes |
Change what is recorded under What is recorded on the same page. Reading mail is never recorded, and neither is what the server does by itself: delivering mail, running inbox rules, auto-archiving, or clearing old deleted items.
For a delegate who opens a shared mailbox in a mail app with [email protected]\[email protected], entries name the person who signed in, not the shared mailbox.
Search
Filter by mailbox, by who did it, by what happened, by logon type and by date, then Search. Newest entries come first; Show older entries loads more. Export CSV downloads what the filters match (up to 5,000 entries) for a spreadsheet or a report; exports are noted in Change history.
From a person's page in Users & groups, Who deleted or changed what opens the log for their mailbox.
Only organization administrators can read the log, because entries show the subjects of other people's mail.
How long entries are kept
Entries are kept for 90 days by default and then removed automatically. Set Keep entries for to what your regulations require (for example 365 days, or 6 years for HIPAA-covered records). Entries stay after a mailbox is deleted, until their time is up.
From the command line
oms mailboxaudit search <org> [--mailbox <address>] [--actor <address>] [--operation SoftDelete] [--days 7]