Docs / Obsidian Suite / For administrators
Message trace
Monitor > Message trace lists every message Obsidian Suite processed for your organization - delivered, tagged, quarantined, rejected, released - and opens the full story of any one of them. It answers "why was this blocked?" and "did this ever arrive?".
Searching
The search box matches, as you type, any of:
- the sender (header From or envelope sender) or any recipient; partial text works (
contoso,@gmail.com); - subject text;
- the
Message-IDheader, or Obsidian Suite's own ID (from theX-Obsidian-IDheader or a bounce message); - the connecting server's IP address, or the mail queue ID.
Filters
| Filter | What it narrows to |
|---|---|
| Verdict | One verdict, or All threats (phishing, BEC, virus, malware). See verdicts. |
| Action | What happened to the message: delivered, tagged, quarantined, held, rejected, released, deleted, clawed back, tempfail. |
| Direction | inbound, outbound, or api (API-mode scans). |
| Period | 1 hour to 90 days, or All. The default is 7 days. Messages older than the log retention period are gone. |
Changing a filter applies it immediately, and the address bar keeps it, so you can bookmark or share a view.
The list
| Column | Shows |
|---|---|
| Received | Local time (hover for seconds), with direction and source (for API scans: m365, google or exchange). |
| From | Display name and address. |
| Subject | With the AI's verdict and risk when the model reviewed it, or "AI review pending". |
| To | All recipients. |
| Verdict, Score, Action | See How filtering works. Scores are colored: red 8 and up, amber 5 and up, green 0 or less. |
Click anywhere on a row to open the message. Newer / Older page through 50 at a time.
The message page
Header line
The subject, verdict, action, score, exact time, direction and organization.
AI analysis
When the model reviewed the message: its verdict, risk (0-100), confidence, how long it took, a one-sentence summary and up to five indicators. "AI analysis pending" means a review is queued; held mail is released automatically if it comes back clean.
Why
Every rule that fired, strongest first, with its points, the stage that raised it and its category. The line at the top right states the decision (for example "score 20.9 >= reject threshold 15"). Look up any rule in the detection rule reference.
Scan stages
One row per stage with a status dot (green ran, red error, grey skipped), its time and number of findings. Expand a stage to see its data: the SPF, DKIM and DMARC results, the Spamhaus answers per IP address and domain, the antivirus result, the attachment inventory with file types and nesting, the Bayesian probability and top tokens, and why the AI was or was not asked.
Links
Every link host with the full URL and the text shown to the reader: the quickest way to see where a phishing mail really points.
Text preview
The message as plain text. HTML, images and links are never rendered in the console, so opening a malicious message here is safe.
Full headers
The original headers, while a raw copy of the message is kept. Quarantined mail keeps its raw copy until it leaves the quarantine; delivered mail keeps it only for a short time.
Actions on a message
| Action | What it does |
|---|---|
| Release | (Quarantined or held mail.) Delivers to every recipient still quarantined, skipping filtering. Released mail carries X-Obsidian-Released. For API-mode messages it moves the message back to the inbox instead. |
| Release (per recipient) | In the Recipients box: release to one person only. |
| Delete | Marks the quarantined copies deleted. Users can no longer release them. |
| Claw back | (Delivered mail.) Finds the message in every recipient mailbox by its Message-ID through your API connector and moves it out. Needs a connector with Allow clawback of delivered threats. |
| Report spam / Not spam | Trains the Bayesian filter (your organization's and the shared corpus) and records the report. Needs the raw copy. See Learning. |
| Ask AI | Queues an AI review now, whatever the score. The result appears on the page when finished (refresh). |
| Allow sender / Block sender | Adds the exact sender address to your organization's allow or block list. |
| Allow domain / Block domain | The same for the whole sender domain (@domain). |
| Download .eml | Downloads the original message, saved as .eml.txt so it cannot open by accident. Recorded in the audit log. |
Envelope
| Field | Meaning |
|---|---|
| From / Envelope | Header From versus SMTP MAIL FROM. A difference is normal for newsletters, suspicious for "personal" mail. |
| Client / HELO | The connecting server's IP address, reverse DNS name and greeting. |
| Message-ID, Queue ID | For matching the message in your mail platform's own trace. |
| Size, Scan time | The message size and how long scanning took. |
| Policies | Which policy overrides applied. |
| Reported | Whether a user or administrator reported it as spam or not spam. |
Recipients and attachments
Recipients shows each recipient's own status, whether it is admin-only, and who released it when. Attachments shows each file's name, type, size and SHA-256 hash, useful for threat-intelligence lookups.
Mail Obsidian Suite sends itself - quarantine digests, sign-in links and secure-message codes - is not filtered and does not appear in Message trace.