Map your identity provider's organizations onto tenants: every customer signs into the same console and sees only their own traffic, tuning only within limits you set — while you keep the global view of the whole cluster.
Every verdict is explainable — see why a message was rejected or delivered, and validate tuning changes against replayed traffic before they ship.
Ground-truth accuracy metrics and per-layer impact analysis: evidence of what your filter catches, what it misses, and what each layer costs.
Your logs show what fired. Console shows what mattered — and what to do about it.
Detection Impact separates layers that fire from layers that decide verdicts. One deployment found an RBL with 98% coverage but only 2% decisive contribution — and switched it off with minimal effect on catch rate.
Campaign clustering turns 500 near-miss messages into one decision. LLM-assisted authoring goes from observation to deployed rule in about 60 seconds. Rules, maps and scoring policy change live from the console — preview any change against real captured mail, apply it, revert it. No restarts, no service interruption.
Auto-triage proposes corrective actions, a second adversarial model judges each one, and nothing runs until an operator approves it. Every applied action is verified by rescan and revertible — and your own AI agents can drive the same action layer, with the same permissions and the same audit trail as an operator.
Feedback & Replay measures real false positives and false negatives, not symbol hit counts, and re-runs your labelled corpus against the live config. On the benchmark corpus, Premium Neural cuts false positives ~20× vs Bayes at the same recall.
Image-only pitches, QR codes, banners sliced into tiles: a multimodal model reads them while a borderline message waits out its greylist delay, so nothing slows the mail flow. When the sender retries, the verdict sees what the images actually say — and one analysis covers an entire campaign, not every copy of it.
The brand a BEC crew spoofs most is yours. Brand Protection derives every recipient's company identity on the fly — no list to maintain — and flags senders who claim it across alphabets, spellings and lookalike tricks, while built-in exceptions keep real colleagues writing from personal mailboxes safe.
The four questions every infrastructure and security team asks first.
Scan data lives in your ClickHouse; streams and caches in your Redis. Content reaches an LLM provider only through features you explicitly enable — with a self-hosted model, everything stays in-house.
Scan data access is read-only. Learn operations go through Rspamd's controller API, and rule deployment writes to HTTP-served map files that Rspamd polls — configuration files are never touched.
The containers run entirely within your infrastructure. Only the optional LLM features make external calls, and you choose when and what to send.
No migration, no patches, no custom builds: a container alongside your existing Rspamd 4.1+ cluster — single-node or HA — using the ClickHouse and Redis you already run.

Traffic health at a glance: volume, action mix, and top-firing symbols.

Which layers decide verdicts — not just which ones fire.

500 near-misses clustered into one row, one decision.

Image-only phishing read and scored — one analysis covers the whole campaign.

Preview a policy change against real captured mail before it goes live.
Rspamd Console ships with the Enterprise and Hosted plans. See pricing
Talk to the Rspamd team about operational visibility for your Rspamd deployment.