Keep a provider-wide view while customers manage their own domains and policy. Tenant-scoped access and provider-defined limits support delegated operations.
Investigate filtering decisions, review retained messages and test tuning against labelled mail. Give support and operations a shared view of the evidence.
Trace detection signals, follow changes in traffic and export a dated threat-posture report. Use your installation’s records to support reviews and explain decisions.
Follow the workflow from traffic and evidence to a reviewed policy change.
Start with traffic and final actions, then inspect Detection Impact to see which layers contributed enough score to change the decision. Open captured messages to examine the underlying symbols and evidence.
Traffic Alerts track persistent deviations across the installation. Bounded expected patterns account for recurring mail, while incidents keep the finding and its evidence available for review.
Move from message evidence to rules, maps and dynamic policy. Preview supported changes against retained messages, choose the traffic they apply to and check the result after applying them.
Quarantine preserves selected mail for review. Operators can inspect held messages and, when release signing and transport are configured, re-inject a false positive through the MTA. Retention and capture rules determine what is recoverable.
Give customers access to their own supported views and policy controls within limits you define. Customers use My Settings for bounded self-service; providers retain central tenant administration.
Use role- and tenant-scoped REST keys for integrations, and MCP for trusted installation-level agents. LLM-assisted investigation supports hosted or local models. Review and apply controls depend on the action and integration you enable.
Deployment and access boundaries, explained before you integrate.
Scan data lives in ClickHouse; captures and operational state use Redis. Select hosted or local LLM endpoints and decide which analysis features may send message content to them.
Console sessions and REST keys use roles; tenant access is restricted to supported routes and data. MCP is intended for trusted installation-wide agents and requires separate access controls.
Run Console in your infrastructure and choose optional providers. Licensing, updates, reputation feeds, federation and hosted models each have connectivity requirements to review for your deployment.
Console runs alongside Rspamd with ClickHouse and Redis. The team can help assess compatibility, available capabilities and deployment requirements.
Actual Console interface with illustrative demo data. Figures demonstrate the workflow and are not performance benchmarks.
Rspamd Console ships with the Enterprise and Hosted plans. See pricing
Walk through an investigation, tenant delegation or an integration with the Rspamd team.