Protection
What it does
The console is an expert cockpit — and the wrong first hour for someone who just wants a mail filter. Protection is one page that answers the three questions most operators actually have — how strict is it, what happens to flagged mail, and what protection is running — in outcome language, with nothing rspamd-shaped on it.
Strictness is a choice between four named levels — Relaxed, Standard, Strict, Aggressive — each with a one-line promise that includes its honest cost. And before anything is applied, the page shows what each level would have done to this deployment's own mail over the selected period: how many messages rejected, tagged, greylisted — computed from the live corpus, not from a brochure.
Your mail flow, drawn live
The page opens with a flow graph of the selected period: received mail fanning out into rejected, tagged, accepted and parked-for-inspection, then what ran while messages were parked and what they became when released — every box a real count from the deployment's own logs.
The picture follows the configuration. Turn the background judge off and its chip greys out; switch holding off and the branch collapses to a dashed outline. The diagram is the current policy, not a stock illustration of one.
Levels move volume and posture — never your work
A level adjusts how much mail flows into deep inspection and how the background judge leans on borderline calls; the protection machinery itself stays on at every level. A hand-tuned config shows as Custom — closest to Strict with the exact differences named, applying a level touches only the thresholds the level owns, and one button returns to the scanner's own configured values. Every apply is audited.
Each protection layer carries its own three-state switch — off, shadow, enforce. Shadow is evaluate-before-trust: the layer runs and reports, but contributes nothing to verdicts until you promote it. And for deployments whose thresholds must never move from a UI, a read-only mode keeps the whole page visible while Apply and the switches refuse, with the reason stated.
Simple mode
Turnkey deployments can start the console with a collapsed navigation — Overview, Protection, Quarantine, Mail Streams, Audit, Settings — and an Advanced view switch for the day the operator outgrows it. Nothing is removed: every expert page stays reachable, and support can still deep-link to any module.



Example: choosing a policy from evidence
An operator considers tightening the filter. The Strictness table shows Strict would have rejected 344 messages last week against the current 316, with slightly fewer tagged. They apply Strict — the change is audited and reaches the scanner within a minute — and every override, rule and score edit made by hand survives untouched. A week later, one click on 'Reset to scanner config' would take it all back.




