ObsidianDocumentation Sign in

User portal & digests

Obsidian checks your email for spam, scams and viruses before it reaches your inbox. Anything it holds back waits in your quarantine, where you can release what you were expecting.

Signing in

Open the address your IT team gave you. Depending on how your organization is set up, use one of:

  • Continue with Microsoft or Continue with Google - your normal work account.
  • Email and password - for Exchange organizations this is your normal Windows / network password.
  • Email me a sign-in link - enter your address; a link valid for 15 minutes arrives by email. Open it and click Sign in. (Not available for administrator accounts, and only when your IT team has enabled it.)

If two-factor authentication is on for your account, you then enter the 6-digit code from your authenticator app. After several wrong passwords the account locks for a few minutes.

My quarantine

Everything held back for you and your aliases, newest first. Search by sender or subject.

Why
What Obsidian thinks it is: spam, bulk (newsletters), phishing, BEC (impersonation / payment fraud), policy (a blocked attachment type) and so on.
Release
Delivers the message to your inbox now.
Delete
Removes it from your quarantine.
admin review
Judged dangerous (virus, malware, phishing). Only your IT team can release it - contact them if you were expecting it.
"being checked by AI"
A borderline message the AI is reviewing. It is usually delivered or quarantined within a few minutes without you doing anything.

Click a message to see why it was flagged and the AI's assessment, and to choose:

Release to my inbox
Deliver it once.
Release and always allow this sender
Deliver it and add the sender to your personal allow list, so their future mail skips spam filtering (never virus checks).
Delete
Remove it.
Before releasing, ask: was I expecting this? Does the sender's address really match who they claim to be? Unexpected invoices, shared documents, voicemails, password warnings and payment-detail changes are the most common scams.

My recent mail

The last 14 days of mail sent to you, including what was delivered. If something bad got through, open it and choose:

Report as spam and block sender
Teaches the filter and blocks that sender for you.
Report as not spam
Teaches the filter that this kind of mail is fine.

My allow & block lists

Your personal lists. Enter a sender address (news@shop.com) or a whole domain (@shop.com) and choose Always allow or Always block. Remove deletes an entry. Your list overrides your organization's lists for your mail. Blocked senders go to your quarantine.

Account & security

Two-factor authentication

  1. Set up two-factor.
  2. Scan the QR code with Microsoft Authenticator, Google Authenticator, 1Password or similar (or type the manual key).
  3. Enter the 6-digit code and Confirm. From now on sign-in asks for a code.

To turn it off, enter a current code and click Turn off. Lost your phone? Ask an administrator to reset two-factor on your account.

Quarantine digest

Tick Email me a summary when mail is quarantined to receive digests (below).

Password

Accounts with an Obsidian password can change it here (12 characters minimum). Other sessions are signed out. Microsoft / Google / Windows passwords are changed with your organization as usual.

Quarantine digest emails

At set times each day (for example 8:00 and 16:00) you receive a list of new quarantined mail - each message appears in one digest only. For each item:

Release
Opens a confirmation page; click the button to deliver the message.
Always allow
Releases it and adds the sender to your allow list.
Admin review
Dangerous items have no release link.

The links work without signing in, expire after 7 days and always ask you to confirm (so link scanners that "click" every link cannot release mail by themselves). Open your quarantine at the bottom takes you to the portal.