Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / Start here

How filtering works

Every screen in the console is built on a few ideas: findings add points to a score, the score crosses thresholds, a verdict names what kind of threat the message is, and the policy says what to do about it.

The scan, step by step

Each message goes through these stages in order: allow and block lists, sender authentication, Spamhaus reputation, antivirus, attachments, links, impersonation, content, the Bayesian filter, and the AI model when it is needed. Then the decision is made.

Before any of this, connections from addresses on Spamhaus ZEN are turned away. Those never appear in Message trace: they were refused before a message existed.

Each stage records findings (rules), each worth points: positive for suspicious, negative for reassuring (a DMARC pass, for example). Every rule is listed in the detection rule reference. If one stage fails, mail is never lost: the stage is marked with an error and the others still decide.

Score and thresholds

Total scoreDefaultWhat happens
below tagunder 5Delivered normally (clean), unless it is bulk mail.
at or above tag5Delivered with X-Obsidian-Spam: Yes and, optionally, [SPAM] in the subject. Your Junk rule moves it.
at or above quarantine8The verdict's action applies: quarantine by default.
at or above reject15Refused during the SMTP conversation. The sender gets a bounce from their own mail server.

Thresholds are set per policy.

Verdicts

VerdictMeaning
cleanNothing significant found.
bulkLegitimate-looking marketing or newsletter mail.
spamUnwanted mail.
phishTries to steal credentials or payment details, or spoofs a sender.
becBusiness email compromise: impersonation aimed at payments, gift cards, payroll or data.
virusThe antivirus or a Spamhaus file-hash lookup identified malware.
malwareAttachment rules found malware-like content and the score is high.
blockedThe sender is on a block list.
policyAn attachment rule was broken (blocked file type, macro, password-protected archive) while the score is otherwise low.

When a message crosses a threshold, the verdict comes from the kind of finding that contributed most: phishing, BEC or malware findings win when they make up at least 40% of the suspicious points (and at least 3 points); bulk wins when half the points are bulk; otherwise it is spam.

Some outcomes skip scoring:

  • A virus is always a virus.
  • A block-listed sender is always blocked.
  • An attachment rule violation always applies its action.
  • An allow-listed sender is clean, unless the message is a virus, breaks an attachment rule, or fails DMARC for a domain that publishes p=reject. So a forged copy of a trusted sender is still caught.

Actions

ActionWhat it does
DeliverDelivered unchanged (with Obsidian Suite's headers added).
Deliver + tag (Junk)Delivered with X-Obsidian-Spam: Yes and the subject prefix, so it lands in Junk.
QuarantineAccepted from the sender and kept in Obsidian Suite, not delivered. Can be released.
Reject at SMTPRefused with a 550 error; the sender's mail server returns it to them.
Discard silentlyAccepted and dropped. Nobody is told, so use it sparingly.
Hold (AI)Kept like quarantine while the AI model reviews it, then delivered automatically if it is judged clean.

Message and recipient statuses

A message has one overall action and a status for each recipient, so a message to five people can be released to one of them. The statuses are delivered, tagged, quarantined, held, rejected, released, deleted, clawed back, expired and tempfail.

tempfail means the message was refused temporarily; the sending server tries again automatically. expired means it stayed in quarantine past the retention period.

Admin-only mail

Viruses, malware and phishing quarantined above the threshold are marked admin only. Users see them in their quarantine, so they know something was stopped, but cannot release them; quarantine digests show "Admin review" instead of a release link. Which other verdicts users may release is set per policy.

AI review

The AI model is only asked when its answer can change the outcome:

  • mail in the grey zone, from the policy's Ask the model from score up to the quarantine threshold;
  • messages that look like business email compromise;
  • outside mail using the display name of one of your VIP users;
  • first-time senders whose message contains links.

It never reviews outbound mail, viruses or allow- and block-listed senders. There are three modes, chosen per policy:

  • Hold (default): the message is held while the model reviews it. Clean mail is delivered automatically with X-Obsidian-AI-Review: released; anything else is quarantined. If the model cannot be reached for longer than the policy's maximum hold, the rules decide.
  • Async: the message is delivered at once. If the model then finds phishing, BEC or malware, it is clawed back from the mailboxes through your API connector.
  • Inline: the SMTP conversation waits for the model, within a time limit. For the strictest policies.

The model can add caution but never remove it. In every mode, a clean verdict cannot deliver mail the rules would quarantine or reject: its credit still shows in the score, the reason says it did not release the message, and only a person can release it. Hold only parks mail the rules would have delivered anyway.

The model judges what a message is trying to get the recipient to do. Authentication and reputation are already scored by the rules, so it does not count them again: a failed SPF, DKIM or DMARC check alone never makes it call a message phishing or malware. The email text is kept separate from the model's instructions, and a message that tries to give the model orders is treated as evidence of phishing, never followed.

The model's verdict, risk, confidence and reasoning appear at the top of the message page.

Directions

DirectionMeaning
inboundFrom the internet to one of your domains.
outboundFrom your mail platform through Obsidian Suite to anywhere. Authentication, impersonation and AI checks are skipped; viruses and spam are still stopped, so a compromised account cannot get your domain blocklisted.
apiRead from a mailbox by an API connector (API mode).

First-time senders and VIPs

A sender is "first-time" until your organization has received clean mail from that address or sent mail to it, looking back 180 days. VIP users are marked on the Users page; their display names are protected against outside use. See Users and roles.