Rspamd Console is a commercial operational dashboard for Rspamd, built by the Rspamd team. 30+ modules, drop-in deployment: decisive-contribution analysis, symbol introspection, stream capture, campaign triage, and rule authoring on top of your existing cluster.
Modules are grouped below by what they do. The product's own sidebar groups them differently and is configurable per deployment — several modules are opt-in and won't appear until you enable them.
This reference documents every module in detail, plus the architecture, integration requirements, and operational FAQ. For the short version, see the Rspamd Console overview.
Controller HTTP API (4.1+) — reads scan data and configuration
Scan data storage & analytics — powers detection impact and symbol introspect
Cache & session state — stores streams and cached responses
Container-based — drops in alongside your existing infrastructure
Rspamd Console deploys as containers alongside your existing Rspamd cluster — single-node or HA — and uses the Redis and ClickHouse you already run. No data leaves your network.
No patches, no custom builds: a small drop-in plugin package adds the capture-stream and learn-queue endpoints; everything else is read from your existing ClickHouse and Redis through the controller API. Requires Rspamd 4.1 or later with ClickHouse logging enabled and the controller worker reachable from the dashboard.
Traffic health at a glance, decisive-contribution analysis, per-symbol behaviour, score distributions, accuracy against ground truth, and the auditor-ready threat posture page.
Mail stream capture, campaign clustering, the suggestion approval queue, the quarantine desk, greylist-window verdicts, borderline review and learn-queue management.
Read the groupAI-assisted rule authoring, the Maps editor, What-If score simulation, live Dynamic Settings, the selector toolchain and the Selector Grid rules engine.
Brand Protection, Premium Neural, Vision image analysis, YARA scanning, clusters, sender reputation, Bayes, vendor feeds, and URL and content analytics.
The Protection policy page and simple mode, live rate limiting, DKIM signing health, the operator audit trail, and knowledge sharing between deployments.
Read the groupData locality, LLM handling, ClickHouse and Redis requirements, multi-tenancy, backups, upgrades and support — all 20 questions.