Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / For administrators

Test a message

Monitor > Test a message runs the complete scan on a message you upload and shows exactly what Obsidian Suite would do with it - without delivering, storing or learning anything. Use it to check a suspicious message a user forwarded, or to see how a policy change would treat a known message.

Getting an .eml file

  • Outlook (classic desktop) saves .msg files, which are not .eml and cannot be scanned. Open the same message in Outlook on the web instead.
  • Outlook on the web / new Outlook: open the message, then ... > Save as (downloads an .eml).
  • Gmail: open the message, then More > Show original > Download original.
  • Thunderbird: File > Save As > File.
  • The Obsidian Suite console: any message page > Download .eml.

Fields

FieldWhat to enter
Message file (.eml)The message, up to 60 MB.
RecipientOne of your protected addresses. It picks the organization, and with it your domains, VIP users, policy overrides, lists and learned data. Leave it empty to test with the default policy only.
Envelope sender (optional)The SMTP MAIL FROM, used for SPF. Take it from the message's Return-Path header.
Connecting IP (optional)The IP address that delivered the message, from the first external Received header. It enables the SPF and Spamhaus ZEN checks; without it those checks are skipped.

Click Scan.

Reading the result

  • The header shows the verdict, the action that would be taken, the score and the reason.
  • The AI model runs inline here, if it would be asked, so you see its opinion. Allow it some time.
  • Stages shows each check's data, exactly as on a real message page.
  • Headers that would be added shows the X-Obsidian-* headers and Authentication-Results the recipient would receive.

Authentication depends on context. A message scanned from a file may fail SPF or DKIM checks that passed originally: DKIM breaks if the file was modified, and SPF depends on the IP address you enter. Compare with the original Authentication-Results header.

EICAR self-test

EICAR self-test on the Dashboard scans a built-in message carrying the harmless EICAR antivirus test file and shows the result here. The antivirus should report Eicar-Signature.