Docs / Obsidian Suite / For administrators
Policies
A policy decides the score thresholds and what happens to each kind of threat. There is one default policy for all mail, maintained by Larström Technologies, plus overrides you create for your organization, a group of recipients or a direction.
Open Protect > Policies. The Default policy card summarizes the default: its tag, quarantine and reject thresholds and its AI mode. Overrides lists the overrides with their scope, who they apply to, priority and status.
How policies combine
- Start from the default policy.
- Collect the enabled overrides that match the message: overrides for all organizations first, then your organization's.
- Within each group the override with the lowest priority number wins: it is applied last, on top of the others.
- An override only changes the values saved on it; everything else comes from the policies beneath.
The message page lists the overrides that applied (Envelope > Policies). When a message has several recipients, the first recipient's policy is used.
Example: "Finance - strict" for
@finance.contoso.com, priority 10: quarantine at 6, BEC always quarantined, AI always consulted. Everyone else in Contoso keeps the defaults.
Creating an override
Protect > Policies > New policy. The form starts with the default values; change what you need and click Save policy.
Scope
| Field | Meaning |
|---|---|
| Name | Shown in lists and on messages. |
| Recipients (optional) | Addresses or @domain entries, separated by commas or lines. Blank means everyone in your organization. |
| Direction | Any, Inbound, Outbound, or API-scanned mailboxes. |
| Priority | Lower wins. Default 100. |
| Enabled | Untick to keep the policy without applying it. |
Your overrides always belong to your organization. Delete on an existing override removes it immediately.
Every option
Score thresholds
| Option | Default | Meaning |
|---|---|---|
| Tag | 5 | Score at which mail is delivered but marked as spam (X-Obsidian-Spam: Yes, optional subject prefix), so your Junk rule moves it. |
| Quarantine | 8 | Score at which the verdict's action applies (quarantine by default). |
| Reject | 15 | Score at which mail is refused during the SMTP conversation (550). The sender's server bounces it; nothing is stored unless it is a virus. |
| Prefix the subject of tagged spam | on | Put the subject prefix in front of the subject of tagged spam and phishing. |
| Subject prefix | [SPAM] | The text put in front of tagged subjects. |
| Add X-Obsidian headers (needed for Junk routing rules) | on | Add the X-Obsidian-* and Authentication-Results headers to delivered mail. Required for the Junk rules on Microsoft 365, Google and Exchange. |
| Honor sender DMARC p=reject | on | When a sender's domain publishes p=reject, failing mail that also scores at least the tag threshold is treated as phishing and handled as admin-only. |
Actions per verdict
Every action field offers Deliver, Deliver + tag (Junk), Quarantine, Reject at SMTP and Discard silently - see Actions. Rejection only happens for mail arriving through the gateway; API-scanned mail that would be rejected is quarantined instead.
| Option | Default | Meaning |
|---|---|---|
| Spam | Quarantine | Spam at or above the quarantine threshold. |
| Bulk / marketing | Deliver + tag | Newsletters and marketing mail. Tagging lets Junk rules or users decide. |
| Phishing | Quarantine | Credential theft, fake invoices, QR-code and call-back lures. |
| Business email compromise | Quarantine | Impersonation, payment, gift-card or payroll requests. |
| Virus | Quarantine | Malware identified by the antivirus or a Spamhaus file hash. Quarantined viruses are always admin-only. |
| Malware | Quarantine | Malware-like mail found by the attachment rules (disguised executables, macros, HTML smuggling) at or above the quarantine threshold. |
| Block-listed sender | Reject at SMTP | Mail from a sender on a block list. |
| Attachment policy | Quarantine | A blocked file type, macro or password-protected archive while the score stays below the quarantine threshold. |
| Users may release their own | spam, bulk, policy | Which verdicts users may release from their own quarantine and from digest links (choose from spam, bulk, policy, phish, bec). Viruses and malware always need an administrator. |
AI analysis
| Option | Default | Meaning |
|---|---|---|
| Use the AI model | on | Use the AI model for this policy's mail. |
| Mode | Hold | Hold grey mail until the AI decides (recommended): parked until the model decides, delivered automatically if clean. Deliver now, claw back if the AI finds a threat: needs an API connector with clawback. Wait for the AI during SMTP: the strictest; the connection waits for the model. |
| Ask the model from score | 1.5 | Mail scoring from this value up to (not including) the quarantine threshold is reviewed. |
| Always review first-time senders with links | on | Ask the model whenever a first-time sender includes links, whatever the score. |
| Always review VIP display-name matches | on | Ask the model whenever an outside sender uses a VIP's display name. |
| Maximum hold (minutes) | 30 | If the model cannot be reached for this long, held mail is decided by the rules alone. |
Attachments
| Option | Default | Meaning |
|---|---|---|
| Blocked file types | see below | File types refused as attachments. Checked on the last extension, inside archives, and against the real file type. |
| Office documents with macros | Quarantine | Quarantine, Score only (the rule ATTACH_OFFICE_MACRO adds points) or Allow. |
| Password-protected archives | Quarantine | ZIP, 7z or RAR archives with a password cannot be virus-scanned: Quarantine, Score only or Allow. |
| Archive depth to unpack | 3 | How many nested archive levels are unpacked and inspected. |
Up to 500 files are inspected inside one archive.
The blocked file types by default are: exe scr pif com bat cmd vbs vbe js jse wsf wsh hta cpl msi msp jar ps1 psm1 reg lnk iso img vhd vhdx one chm application gadget msc appx appxbundle msix library-ms settingcontent-ms xll wiz url svg.
Tuning tips
- Too much spam getting through: lower Quarantine by 1 at a time and watch Message trace for false positives.
- Newsletters annoying users: set Bulk / marketing to Quarantine. Users can still release them.
- A partner constantly failing SPF or DMARC: ask them to fix their DNS. Meanwhile allow-list their domain; a spoof that fails DMARC
p=rejectis still caught. - Fewer messages waiting for the AI: raise Ask the model from score, or use the async mode where you have an API connector.