Audit log
Manage › Audit log records who did what: every sign-in, release, deletion, download and configuration change, with the source IP.
Using it
Search matches the actor, action or target. Entries for message actions link to the message. Organization administrators see their organization's entries; MSP administrators see everything. Entries are kept for at least a year.
Action names
| Action | Recorded when |
|---|---|
setup.superadmin | The first administrator was created. |
login.password, login.password+totp, login.sso, login.magic, login.failed, logout | Sign-ins by method, failures, sign-outs. |
quarantine.release, quarantine.delete | Mail released or deleted (by an admin, the user, a digest link digest:<address> or the API api:<token name>). Automatic releases after an AI hold are shown on the message instead (released by ai). |
report.spam, report.ham | Training reports. |
message.clawback, message.download | Clawback from mailboxes (actor ai when an async AI review triggered it); raw message downloaded. |
list.allow, list.block, list.delete | Allow / block list changes. |
org.create, org.update, org.delete | Organization changes. |
domain.add, domain.update, domain.delete, domain.dkim_generate, domain.relay_key | Domain changes. |
connector.add, connector.update, connector.delete | Connector changes (secrets are never logged). |
user.create, user.update, user.password_change, user.mfa_enable, user.mfa_disable | Account changes. |
policy.save, policy.delete, policy.default.update | Policy changes. |
settings.update | A Settings section was saved (lists the keys). |
token.create, token.revoke | API tokens. |
tls.request | A Let's Encrypt certificate request was started (names and method). |