Skip to content

Audit log

The audit log records who did what and when for sensitive actions. Owners and admins find it in Audit log (in the Organization group of the dashboard menu). Entries are listed newest first with the date, who did it, the action, its target and the IP address. Use Filter by action to show one area, e.g. billing.* or key.*.

Area (action prefix) Actions
Organization (org.*) organization created, settings changed (name, time zone, language), deletion scheduled
Keys (key.*) private key created / revoked, public key rotated
Security (security.*) security settings changed – allowed websites, bot protection, block list, rate limit, strict parameters, private key API, hold/reject mode
Team (member.*, invite.*) invitation sent / revoked, member joined / removed / left, role changed, ownership transferred (ownership.transferred)
Services (service.*) service created / updated / deleted, account connected via OAuth, service recovered after a test
Templates (template.*) template deleted
Messages (held.*, message.*) held messages released / discarded manually, message resent
Contacts & suppressions (contact.*, suppression.*) contact deleted, suppression added / removed
Exports (export.*) history, contacts or template exported, personal data export requested
Billing (billing.*) checkout started, plan changed, subscription cancelled / resumed, pack purchased, auto top-up settings changed, public-key spending policy changed, billing details changed, payment dispute opened / closed (credits removed / restored), credits revoked after a refund, subscription refund, monthly → yearly carry-over
Support (admin.*) actions performed by Frontmail support on your organization, e.g. a bonus grant, a refund, suspension

Each entry stores the actor, the action, the affected object, relevant details (never secrets or full credentials) and the IP address. Audit entries are kept for the lifetime of the organization.