Docs / Obsidian Suite / For administrators
Test a message
Monitor > Test a message runs the complete scan on a message you upload and shows exactly what Obsidian Suite would do with it - without delivering, storing or learning anything. Use it to check a suspicious message a user forwarded, or to see how a policy change would treat a known message.
Getting an .eml file
- Outlook (classic desktop) saves
.msgfiles, which are not.emland cannot be scanned. Open the same message in Outlook on the web instead. - Outlook on the web / new Outlook: open the message, then ... > Save as (downloads an
.eml). - Gmail: open the message, then More > Show original > Download original.
- Thunderbird: File > Save As > File.
- The Obsidian Suite console: any message page > Download .eml.
Fields
| Field | What to enter |
|---|---|
| Message file (.eml) | The message, up to 60 MB. |
| Recipient | One of your protected addresses. It picks the organization, and with it your domains, VIP users, policy overrides, lists and learned data. Leave it empty to test with the default policy only. |
| Envelope sender (optional) | The SMTP MAIL FROM, used for SPF. Take it from the message's Return-Path header. |
| Connecting IP (optional) | The IP address that delivered the message, from the first external Received header. It enables the SPF and Spamhaus ZEN checks; without it those checks are skipped. |
Click Scan.
Reading the result
- The header shows the verdict, the action that would be taken, the score and the reason.
- The AI model runs inline here, if it would be asked, so you see its opinion. Allow it some time.
- Stages shows each check's data, exactly as on a real message page.
- Headers that would be added shows the
X-Obsidian-*headers andAuthentication-Resultsthe recipient would receive.
Authentication depends on context. A message scanned from a file may fail SPF or DKIM checks that passed originally: DKIM breaks if the file was modified, and SPF depends on the IP address you enter. Compare with the original
Authentication-Resultsheader.
EICAR self-test
EICAR self-test on the Dashboard scans a built-in message carrying the harmless EICAR antivirus test file and shows the result here. The antivirus should report Eicar-Signature.