Audit log
The audit log records who did what and when for sensitive actions. Owners and admins find it in
Audit log (in the Organization group of the dashboard menu). Entries are listed newest
first with the date, who did it, the action, its target and the IP address. Use Filter by
action to show one area, e.g. billing.* or key.*.
What is recorded
Section titled “What is recorded”| Area (action prefix) | Actions |
|---|---|
Organization (org.*) |
organization created, settings changed (name, time zone, language), deletion scheduled |
Keys (key.*) |
private key created / revoked, public key rotated |
Security (security.*) |
security settings changed – allowed websites, bot protection, block list, rate limit, strict parameters, private key API, hold/reject mode |
Team (member.*, invite.*) |
invitation sent / revoked, member joined / removed / left, role changed, ownership transferred (ownership.transferred) |
Services (service.*) |
service created / updated / deleted, account connected via OAuth, service recovered after a test |
Templates (template.*) |
template deleted |
Messages (held.*, message.*) |
held messages released / discarded manually, message resent |
Contacts & suppressions (contact.*, suppression.*) |
contact deleted, suppression added / removed |
Exports (export.*) |
history, contacts or template exported, personal data export requested |
Billing (billing.*) |
checkout started, plan changed, subscription cancelled / resumed, pack purchased, auto top-up settings changed, public-key spending policy changed, billing details changed, payment dispute opened / closed (credits removed / restored), credits revoked after a refund, subscription refund, monthly → yearly carry-over |
Support (admin.*) |
actions performed by Frontmail support on your organization, e.g. a bonus grant, a refund, suspension |
Each entry stores the actor, the action, the affected object, relevant details (never secrets or full credentials) and the IP address. Audit entries are kept for the lifetime of the organization.