Docs / Obsidian Suite / For everyone
User portal
Obsidian Suite checks your email for spam, scams and viruses before it reaches your inbox. Anything it holds back waits in your quarantine, where you can release what you were expecting. This chapter is for everyone with a mailbox protected by Obsidian Suite. The portal works on a phone as well as a computer.
Signing in
Open https://portal.obsidiansuite.net. Depending on how your organization is set up, use one of:
- Continue with Microsoft or Continue with Google: your normal work account.
- Email and password. In organizations that use Exchange Server, this is your normal Windows (network) password.
- Email me a sign-in link: enter your address, and a link valid for 15 minutes arrives by email. Open it and click Sign in. (Not available for administrator accounts.)
If two-factor sign-in is on for your account, you then enter the 6-digit code from your authenticator app. After several wrong passwords in a row, the account locks for a few minutes.
My quarantine
Everything held back for you and your aliases, newest first. Search by sender or subject.
| You see | Meaning |
|---|---|
| Why | What Obsidian Suite thinks it is: spam, bulk (newsletters), phishing, BEC (impersonation or payment fraud), policy (a blocked attachment type) and so on. |
| Release | Delivers the message to your inbox now. |
| Delete | Removes it from your quarantine. |
| admin review | Judged dangerous (virus, malware, phishing). Only your IT team can release it; contact them if you were expecting it. |
| being checked by AI | A borderline message the AI model is reviewing. It is usually delivered or quarantined within a few minutes without you doing anything. |
Click a message to see Why it was flagged and the AI's assessment, and choose under What would you like to do?:
- Release to my inbox: deliver it once.
- Release and always allow this sender: deliver it, and add the sender to your personal allow list so their future mail skips spam filtering (never the virus checks).
- Delete: remove it.
Before releasing, ask yourself: was I expecting this? Does the sender's address really match who they claim to be? Unexpected invoices, shared documents, voicemails, password warnings and changes to payment details are the most common scams.
My recent mail
The last 14 days of mail sent to you, including what was delivered. If something bad got through, open it and choose:
- Report as spam and block sender: teaches the filter and blocks that sender for you.
- Report as not spam: teaches the filter that this kind of mail is fine.
My allow and block lists
My allow & block holds your personal lists. Enter a sender address ([email protected]) or a whole domain (@shop.com), choose Always allow or Always block, and click Add. Remove deletes an entry. Your lists override your organization's lists for your own mail. Mail from senders you block goes to your quarantine.
Account and security
Two-factor authentication
- Open Account & security and click Set up two-factor.
- Scan the QR code with Microsoft Authenticator, Google Authenticator, 1Password or a similar app (or type the key shown).
- Enter the 6-digit Code and click Confirm. From now on, signing in asks for a code.
To turn it off, enter a Current code and click Turn off. Lost your phone? Ask an administrator to reset two-factor on your account.
Quarantine digest
Tick Email me a summary when mail is quarantined and click Save to receive digests (below).
Password
If your account has an Obsidian Suite password, change it here: Current password, New password (at least 12 characters), Confirm, then Change password. Your other sessions are signed out. Microsoft, Google and Windows passwords are changed with your organization as usual.
Quarantine digest emails
At set times each day (for example 8:00 and 16:00) you receive a list of new quarantined mail; each message appears in one digest only. For each item:
| Link | What it does |
|---|---|
| Release | Opens a confirmation page; click the button there to deliver the message. |
| Always allow | Releases it and adds the sender to your allow list. |
| Admin review | Dangerous items have no release link. |
The links work without signing in, expire after 7 days and always ask you to confirm, so link scanners that "click" every link cannot release mail by themselves. Open your quarantine at the bottom takes you to the portal.
Digests come from Obsidian Suite's own address and are DKIM-signed and covered by SPF and DMARC, so your mail system can verify they are genuine.