ObsidianDocumentation Sign in

Quarantine

Monitor › Quarantine is Message trace narrowed to mail held back from mailboxes, with bulk actions.

Filters

Search
Same as Message trace: sender, recipient, subject, Message-ID, IP, queue ID.
Verdict
Narrow to one kind of threat.
Status
Quarantined + held (default), Quarantined, Held for AI (waiting for the model), Released or Deleted (history).
Period
Default "All" - quarantine items only disappear at the retention limit.
Organization
MSP administrators.

Bulk actions

Tick messages (or Select all for the page) and choose:

Release
Deliver each selected message to all its quarantined recipients. Asks for confirmation.
Not spam
Train Bayes that these were legitimate (does not release them).
Confirm spam
Train Bayes that these were spam.
Delete
Mark deleted. Asks for confirmation.

A summary shows how many succeeded. Messages from other organizations are skipped for organization administrators.

Held for AI

Held messages are waiting for the model. Normally they leave this list within a minute or two - released if clean, turned into quarantined otherwise. You can release one yourself at any time (the AI review is then recorded but no longer acts).

Retention

Quarantined mail is kept for Retention › Quarantine days (30 by default), then expires. Users are told about their items by the digest.

Who can release what

Administrators can release anything. Users can release their own items only when the verdict is in the policy's "Users may release their own" list and the item is not admin-only. See Policies.