Docs / Obsidian Suite / Start here
Getting started
Obsidian Suite is a hosted service: there is no server to build and nothing to patch. We set up your organization, you change a few settings on your mail platform and your DNS, and your mail is filtered from the next message on. This chapter is the order to do things in.
1. Talk to us
Tell Larström Technologies your domains and your mail platform (Microsoft 365, Google Workspace, Exchange Server, or another mail server) through larstrom.com. We create your organization and your first administrator account, and tell you how that account signs in.
2. Sign in
Open https://portal.obsidiansuite.net and sign in. Administrators land on the Dashboard.
Turn on two-factor sign-in for your administrator account straight away: My mail > Account & security > Set up two-factor. See User portal.
3. Check your organization and add your domains
Open Manage > Organizations and click your organization.
- Under Settings, check that Platform matches your mail platform. It decides which setup steps your domain pages show and where new domains deliver by default.
- Under Domains, use Add domain for every domain you receive mail for. Deliver to (optional) is the server Obsidian Suite hands clean mail to. Leave it empty for Microsoft 365 and Google Workspace: it is filled in for you. For Exchange or another server, enter its public host name.
Click a domain to open its page. It shows your domain's current MX records and whether they already point at Obsidian Suite, the routing settings, and numbered Set up mail flow steps for your platform. See Domains and routing.
4. Prepare your mail platform
Before you change any DNS, your platform must accept mail from Obsidian Suite and know how to treat what it tags as spam. Follow the chapter for your platform:
- Microsoft 365
- Google Workspace
- Exchange Server
- Another mail server: see Domains and routing.
Use Test delivery host on each domain page to confirm Obsidian Suite can reach your mail server and that it offers an encrypted (STARTTLS) connection.
5. Connect the API (recommended)
Add an API connector on your organization page (API connectors > Add connector). It brings in your users and their aliases, lets people sign in with their Microsoft or Google account, and lets administrators claw back a delivered threat. The platform chapters explain the credentials it needs.
Once users are synced, open Manage > Users and mark your executives, finance and HR approvers as VIP, so outside mail using their names is caught. See Users and roles.
6. Switch your MX records
- A day ahead, lower the TTL of your MX records to 300 seconds, so a change back would be quick.
- Change the MX record of each domain to
10 mx1.obsidiansuite.netand remove the old MX records. - Watch Monitor > Message trace: new mail appears there within minutes as DNS caches expire. The old MX keeps working until then, so no mail is lost during the switch.
- Reload the domain page: the MX line should now say it points at Obsidian Suite.
7. Lock down and tune
- After the switch, make your platform accept inbound mail only from Obsidian Suite, so attackers cannot go around it by sending straight to your mail server. Each platform chapter shows how.
- Optionally route outbound mail through Obsidian Suite too: see Sending outbound mail.
- Review Policies, Allow and block lists and Quarantine digests, or keep the defaults.
- Tell your users about the User portal.