Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / For administrators

Message trace

Monitor > Message trace lists every message Obsidian Suite processed for your organization - delivered, tagged, quarantined, rejected, released - and opens the full story of any one of them. It answers "why was this blocked?" and "did this ever arrive?".

Searching

The search box matches, as you type, any of:

  • the sender (header From or envelope sender) or any recipient; partial text works (contoso, @gmail.com);
  • subject text;
  • the Message-ID header, or Obsidian Suite's own ID (from the X-Obsidian-ID header or a bounce message);
  • the connecting server's IP address, or the mail queue ID.

Filters

FilterWhat it narrows to
VerdictOne verdict, or All threats (phishing, BEC, virus, malware). See verdicts.
ActionWhat happened to the message: delivered, tagged, quarantined, held, rejected, released, deleted, clawed back, tempfail.
Directioninbound, outbound, or api (API-mode scans).
Period1 hour to 90 days, or All. The default is 7 days. Messages older than the log retention period are gone.

Changing a filter applies it immediately, and the address bar keeps it, so you can bookmark or share a view.

The list

ColumnShows
ReceivedLocal time (hover for seconds), with direction and source (for API scans: m365, google or exchange).
FromDisplay name and address.
SubjectWith the AI's verdict and risk when the model reviewed it, or "AI review pending".
ToAll recipients.
Verdict, Score, ActionSee How filtering works. Scores are colored: red 8 and up, amber 5 and up, green 0 or less.

Click anywhere on a row to open the message. Newer / Older page through 50 at a time.

The message page

Header line

The subject, verdict, action, score, exact time, direction and organization.

AI analysis

When the model reviewed the message: its verdict, risk (0-100), confidence, how long it took, a one-sentence summary and up to five indicators. "AI analysis pending" means a review is queued; held mail is released automatically if it comes back clean.

Why

Every rule that fired, strongest first, with its points, the stage that raised it and its category. The line at the top right states the decision (for example "score 20.9 >= reject threshold 15"). Look up any rule in the detection rule reference.

Scan stages

One row per stage with a status dot (green ran, red error, grey skipped), its time and number of findings. Expand a stage to see its data: the SPF, DKIM and DMARC results, the Spamhaus answers per IP address and domain, the antivirus result, the attachment inventory with file types and nesting, the Bayesian probability and top tokens, and why the AI was or was not asked.

Every link host with the full URL and the text shown to the reader: the quickest way to see where a phishing mail really points.

Text preview

The message as plain text. HTML, images and links are never rendered in the console, so opening a malicious message here is safe.

Full headers

The original headers, while a raw copy of the message is kept. Quarantined mail keeps its raw copy until it leaves the quarantine; delivered mail keeps it only for a short time.

Actions on a message

ActionWhat it does
Release(Quarantined or held mail.) Delivers to every recipient still quarantined, skipping filtering. Released mail carries X-Obsidian-Released. For API-mode messages it moves the message back to the inbox instead.
Release (per recipient)In the Recipients box: release to one person only.
DeleteMarks the quarantined copies deleted. Users can no longer release them.
Claw back(Delivered mail.) Finds the message in every recipient mailbox by its Message-ID through your API connector and moves it out. Needs a connector with Allow clawback of delivered threats.
Report spam / Not spamTrains the Bayesian filter (your organization's and the shared corpus) and records the report. Needs the raw copy. See Learning.
Ask AIQueues an AI review now, whatever the score. The result appears on the page when finished (refresh).
Allow sender / Block senderAdds the exact sender address to your organization's allow or block list.
Allow domain / Block domainThe same for the whole sender domain (@domain).
Download .emlDownloads the original message, saved as .eml.txt so it cannot open by accident. Recorded in the audit log.

Envelope

FieldMeaning
From / EnvelopeHeader From versus SMTP MAIL FROM. A difference is normal for newsletters, suspicious for "personal" mail.
Client / HELOThe connecting server's IP address, reverse DNS name and greeting.
Message-ID, Queue IDFor matching the message in your mail platform's own trace.
Size, Scan timeThe message size and how long scanning took.
PoliciesWhich policy overrides applied.
ReportedWhether a user or administrator reported it as spam or not spam.

Recipients and attachments

Recipients shows each recipient's own status, whether it is admin-only, and who released it when. Attachments shows each file's name, type, size and SHA-256 hash, useful for threat-intelligence lookups.

Mail Obsidian Suite sends itself - quarantine digests, sign-in links and secure-message codes - is not filtered and does not appear in Message trace.