Journaling to an archive
Send a copy of your organisation's mail, as journal reports, to an archive such as Smarsh, Global Relay, Mimecast or your own, for the rules your regulator sets.
Some organisations must keep a copy of every message they send and receive, in an archive they do not manage day to day. Journaling sends that copy. For each message a rule names, Nixt Server sends the archive a journal report: a short summary of the message and the message itself, attached unchanged.
A journal report names:
- the sender;
- the subject and the message’s ID;
- which way it went: in from outside, out to outside, or between people here;
- every recipient, marked To, Cc or Bcc. Bcc recipients are named too, which is why only the archive is sent the report.
Set up a rule
On the console, open Settings and find Journaling. Write one rule to a line: the archive’s address, a colon, whose mail, a semicolon, and which of it.
vault@archive.example: everybody; in, out, between
compliance@archive.example: traders@example.com, advisers@example.com; in, out
| Part | What to write |
|---|---|
| The archive | The address your archive gave you for journal reports. |
| Whose mail | everybody, or the addresses of one or more groups. The members of a group, and of any group inside it, are included. |
| Which mail | in for mail from outside to them, out for mail from them to outside, between for mail between people in the organisation. Any of the three. |
Choose Save. From then on, every message a rule names is journaled as it is sent or received. Undo puts the rules back as they were.
From the command line:
vsx admin journal add vault@archive.example
vsx admin journal add compliance@archive.example --groups traders@example.com,advisers@example.com --in --out
vsx admin journal show
vsx admin journal remove vault@archive.example
add without --in, --out or --between journals all three.
An archive on this server
The archive can be a mailbox on this server, at one of your own domains. It must be a shared mailbox nobody is a member of: a rule naming a person’s mailbox, or an address here that is nobody’s, is refused, so that nobody reads everybody’s mail as their own.
- Make a shared mailbox for it, for example
journal@example.com, and give it no members. - Name its address as the archive in a rule.
While a rule names it, the journal mailbox is kept apart: it cannot be given members, no retention policy deletes from it, and auditors read it through discovery.
How reports are sent
- Each report is signed with your organisation’s DKIM key, so the archive can check it came from you.
- Reports are only ever sent encrypted. An archive that cannot take mail over TLS does not receive them.
- A report the archive does not accept straight away is tried again, as any message is. The person who sent or received the message is never told of it.
- Mail sent to the archive’s own address is not journaled, and neither are the reports themselves.
- Mail held for review, in quarantine or held from sending, is journaled once, when it is let go, with who let it go and when; mail that stays held, or is thrown away, is not journaled.
If a report has not reached its archive after a day, the organisation’s administrators get the journal-delayed alert. Every organisation has it unless it has changed its alerts; see Monitoring. The Queue page, under Mail flow, shows each report waiting and what the archive answered.
Who can change it
The organisation’s administrators set the rules, and an auditor can read them. Every change is in the audit log, with the rules before and after.
Something unclear or out of date on this page? Tell us.