Audit log¶
A record of who changed what, and when, that the people it records can't quietly edit. It answers "who turned this off?" months later, and it can be handed to someone outside the organization together with a way to check it.
It records administration, not mail. It isn't the server's log file, and it keeps no copy of messages.
It is under Management › Compliance › Audit log in the console.

What is recorded¶
- Every change an administrator makes: settings, accounts, groups, domains, roles, tenants, and every other object the console or the API can create, change or delete. Each setting that changed is listed with its value before and after. A password, key or other secret shows only as Changed; its value is never recorded.
- Actions such as reloading the configuration or reindexing.
- Admin sign-ins, successful or not, on any protocol, once an hour per account, method and address, since mail apps reconnect every few minutes. A failed sign-in is recorded only for an account that exists and has admin rights, so password guessing against ordinary accounts doesn't flood the log. Sign-ins as a master user and by the recovery administrator are recorded the same way.
- Opening someone else's data: an administrator reading another account's mail or files, once per session, account and hour.
- Restores of archived items and deleted accounts done for someone else.
- Account locks, and what delegates do in a locked account: see Locked accounts.
- Mail sent as someone else's address, such as a member answering as the group: who sent it and the address it went out as. The message itself shows only the group's address, so this is where the person is named.
- Every export, of the audit log itself included.
- What the server changes on its own: certificate renewals, DKIM key
rotation, automatic bans and the like. These are recorded under the
server's name, with the part of the server that made the change (for
example
system:AcmeRenewal), so nothing changes without a record just because no person did it. A spam filter rules update writes one record for the whole update, saying what it added, replaced and kept.
Each record says who (the name they had at the time, and their tenant), how they signed in (password, app password, API key, which app, or as which master user), from which address, what they did to what, whether it worked, and the reason they gave, if any.
Not recorded: looking at things. Opening a page or reading a setting leaves no trace; exporting does. A person's own self-service isn't recorded either: their masked addresses, their archived items, spam training.
No change without its record¶
The record is written before the change. If it can't be written, the change is refused, and the console says why. A change is never made unrecorded because the store was busy.
If the server stops between writing the record and making the change, the record stays Unfinished, and the tamper check counts it.
Reasons¶
Every record can carry a reason: a ticket number, a case, "left the company". Locking, unlocking and changing a locked account's delegates require one. Elsewhere it's optional, and the export form asks for one.
Reading it¶
Newest first, 50 to a page. From and To narrow it to dates, What happened to one kind of action, and Outcome to Done, Refused or Unfinished. Search finds a name, an address, an object or words in a reason. Open a record to see each setting it changed, before and after.

Who can read it:
| Reads | Exports | Changes how long records are kept | |
|---|---|---|---|
| Administrator | Everything | Yes | Yes |
| Compliance Officer, server-level | Everything | Yes | No |
| Tenant Administrator | Its own tenant's records | Yes | No |
| A tenant's Compliance Officer | Its own tenant's records | Yes | No |
See Compliance officers for giving someone that role.
A custom role, under Management › Directory › Roles, can be given any of the three separately: Read the audit log, Export the audit log and Change how long audit records are kept.
A tenant's records are those made by someone in the tenant, or made to something in it. That includes a server administrator's changes to the tenant's accounts, with the administrator named: a tenant has a right to know who touched its accounts.
Exporting¶
Export… writes the records the filters show to a file on the server, which the console then downloads:
- CSV (spreadsheets), or
- JSON Lines (tools, SIEM), one record per line.
At most 100,000 records per export. Each line keeps the record's hash, and the file ends with a manifest: the filter used, how many records, the first and last, and the file's SHA-256. The console shows that hash when the export finishes. Anyone given the file can check it hasn't been changed, without access to the server.
The export itself is recorded, with the reason given.
Checking for tampering¶
Records can't be edited or deleted through the server, by anyone, administrators included. The only removal is by age (below).
Each server in a cluster links its records into a chain: every record carries the hash of the one before it. Change or remove one in the database, and the chain breaks there. Check for tampering rechecks every chain and names the first break, or reports No tampering found and how many records it checked.
Tampering is detected, not prevented
Someone with root on the database host can rewrite the whole log and recompute every hash. The check shows that the log is intact as stored; it can't show the store was never rewritten. For a record the mail administrators can't touch, send a copy somewhere they don't control (below).
Sending a copy elsewhere¶
Every record is also raised as an event, security.audit-recorded, so any
tracer or webhook can pass it on: to a SIEM, to journald on another host, or
to an OpenTelemetry collector. See
Live tracing and logs for tracers, and
Alerts for webhooks. If a record can't be written,
security.audit-write-failed is raised instead.
That copy is best effort, as all telemetry is. The record in the store is the one that counts.
How long records are kept¶
Two years by default. Change it on the audit log page under How long records are kept, in days, down to a minimum of 90. Changing it is recorded too.
Old records are removed by the daily clean-up, oldest first, and the chain notes where it now starts, so the tamper check still passes.