Premium Add-on: Console

    Operational visibility for your Rspamd deployment

    Know what reached users, what blocked it, and which detection layers earn their cost — without grepping logs.

    100+ enterprise users
    Built by the Rspamd core team
    Rspamd Console

    Who it's for

    ESPs & hosting providers

    Map your identity provider's organizations onto tenants: every customer signs into the same console and sees only their own traffic, tuning only within limits you set — while you keep the global view of the whole cluster.

    Enterprise mail teams

    Every verdict is explainable — see why a message was rejected or delivered, and validate tuning changes against replayed traffic before they ship.

    Security leads

    Ground-truth accuracy metrics and per-layer impact analysis: evidence of what your filter catches, what it misses, and what each layer costs.

    Why teams deploy Rspamd Console

    Your logs show what fired. Console shows what mattered — and what to do about it.

    See what actually matters

    Detection Impact separates layers that fire from layers that decide verdicts. One deployment found an RBL with 98% coverage but only 2% decisive contribution — and switched it off with minimal effect on catch rate.

    Cut incident response from hours to minutes

    Campaign clustering turns 500 near-miss messages into one decision. LLM-assisted authoring goes from observation to deployed rule in about 60 seconds. Rules, maps and scoring policy change live from the console — preview any change against real captured mail, apply it, revert it. No restarts, no service interruption.

    Automate without losing the wheel

    Auto-triage proposes corrective actions, a second adversarial model judges each one, and nothing runs until an operator approves it. Every applied action is verified by rescan and revertible — and your own AI agents can drive the same action layer, with the same permissions and the same audit trail as an operator.

    Prove your accuracy

    Feedback & Replay measures real false positives and false negatives, not symbol hit counts, and re-runs your labelled corpus against the live config. On the benchmark corpus, Premium Neural cuts false positives ~20× vs Bayes at the same recall.

    Catch the spam that hides in images

    Image-only pitches, QR codes, banners sliced into tiles: a multimodal model reads them while a borderline message waits out its greylist delay, so nothing slows the mail flow. When the sender retries, the verdict sees what the images actually say — and one analysis covers an entire campaign, not every copy of it.

    Your own name is a brand too

    The brand a BEC crew spoofs most is yours. Brand Protection derives every recipient's company identity on the fly — no list to maintain — and flags senders who claim it across alphabets, spellings and lookalike tricks, while built-in exceptions keep real colleagues writing from personal mailboxes safe.

    0.998
    ROC AUC, Premium Neural (benchmark corpus)
    ~4 ms
    per message, CPU-only
    ~20×
    fewer false positives vs Bayes (benchmark)
    30+
    modules
    Drop-in
    container deployment

    Answers for your security review

    The four questions every infrastructure and security team asks first.

    Mail stays in your network

    Scan data lives in your ClickHouse; streams and caches in your Redis. Content reaches an LLM provider only through features you explicitly enable — with a self-hosted model, everything stays in-house.

    No config writes

    Scan data access is read-only. Learn operations go through Rspamd's controller API, and rule deployment writes to HTTP-served map files that Rspamd polls — configuration files are never touched.

    Runs air-gapped

    The containers run entirely within your infrastructure. Only the optional LLM features make external calls, and you choose when and what to send.

    Drops into your cluster

    No migration, no patches, no custom builds: a container alongside your existing Rspamd 4.1+ cluster — single-node or HA — using the ClickHouse and Redis you already run.

    Rspamd API
    ClickHouse
    Redis
    Drop-in Deployment
    Full integration details

    The decisions your logs can't show

    Overview

    Overview

    Traffic health at a glance: volume, action mix, and top-firing symbols.

    Detection Impact

    Detection Impact

    Which layers decide verdicts — not just which ones fire.

    Campaigns

    Campaigns

    500 near-misses clustered into one row, one decision.

    Vision

    Vision

    Image-only phishing read and scored — one analysis covers the whole campaign.

    Dynamic Settings

    Dynamic Settings

    Preview a policy change against real captured mail before it goes live.

    Rspamd Console ships with the Enterprise and Hosted plans. See pricing

    FAQ

    Frequently asked questions

    Ready to see what your logs can't show you?

    Talk to the Rspamd team about operational visibility for your Rspamd deployment.