Enable DKIM to reduce sent emails from being flagged as Spam or put in Quarantine
We are seeing more emails that are sent from within Xero being flagged as Spam or put in Quarantine, especially if the recipient is using Outlook 365.
Xero need to implement DKIM to reduce the number of false positives like this. It's very easy to implement and the benefits to Xero users would be enormous.
-
Cord Blomquist commented
Please add this
-
Konstantin Ryabenko commented
Hi everyone,
Try leaving your Xero feedback on TrustPilot and ProductReviews:
https://au.trustpilot.com/review/www.xero.com
https://www.productreview.com.au/listings/xeroXero wants to look good for their new customers, and with an influx of reviews, we have a chance to make our voices heard!
-
Melissa Newsome commented
Our clients have to regularly check their junk/spam just to get our invoices, and many times they are missed. This is not ideal and needs to change.
-
Lesley Kent commented
It would appear that Yahoo are just dropping emails that are not DKIM and DMARC compliant, not even sending an undelivered bounce back. I believe Google are implementing the same strategy thus there is no way of knowing that the electronic invoice was not delivered, severely affecting cashflow. PLease set up DKIM for the post.xero.com mail servers and publish the process for obtaining the CNAME records for the same so we can be DKIM compliant.
-
André Allavena commented
Has anything changed on Xero side (I suspect not, but checking)?
On our side, the costs to invoices being blocked / flagged as spam, etc. is high enough that it'll pay for another solution so we''re now looking into alternatives. Has anyone got feedback / recommendations they'd like to share?
- 3rd party tool that manages invoicing (takes payment / reconciliation uploads results to Xero)
- custom built solution
- Webhook from Xero to download / email from elsewhere (if we do that, likely 1 will be better)
- other?Thanks
-
Manya Christensen commented
Important documents have not gotten through to our customer because of this issue.
-
Warwick de Zwaan commented
I've stopped sending them direct from Xero, and print the PDF to file and send from our system. People don't trust links in email anymore, rightly so, and so as a financial services business, I've stopped sending links that ask for bank details and TFNs and such.
We need to be able to send emails and questions from Xero Blue, Tax, Workpapers, XPM, without links.
-
Tim Sneller commented
The problem is, that we can't easily see whether or not an invoice we have sent to a client has been caught by their spam filter. We will only know about the ones we receive and find in our SPAM bin.
We SEND about 50 invoices a month, but only receive 2 from suppliers using Xero.
I wonder how Xero send their invoices - If they use Xero, then they are going to be in a rather embarrassing situation when their own invoices fail to get delivered.....
-
Chris Templeton commented
As the original raiser of this idea, I think the only way to now force the issue is for everybody to start raising tickets for *every* email that is caught by this issue. Perhaps they'll start taking it seriously then
-
Konstantin Ryabenko commented
FEBRUARY 2024 IS COMING
As previously mentioned, Google and Yahoo are intensifying security efforts, requiring all email senders to comply with domain authentication by February 2024. I have just received confirmation that other service providers have begun taking action on the upcoming changes.
We have a MailerLite account that we no longer use, but, importantly, we received an email regarding this matter, which I have attached below. Essentially, they state that we need to configure domain authentication; otherwise, our emails will not be delivered.
Xero, do you still believe it's a good idea to ignore this problem?
-
Mark Anthony Cristodero commented
this needs to be sorted ASAP, otherwise, we will have no choice but to move over to Myob, cant run a business if our clients don't receive our invoices and pay them. Looks like xero's days are numbered.
-
Michael Romp commented
Agreed, although it's not just DKIM we need (since they are DKIM signed by post.xero.com), but rather the ability to send as our own domain.
I am seeing more and more Xero invoices being filtered into my client's junk mail folder or outright blocked and it's becoming increasingly difficult to continuously follow up on every invoice.
This issue alone may force me to jump to a different accounting system soon.
-
Hein Kuenen commented
This is essential now
-
Perry Paolantonio commented
Approximately 20% of our invoice emails are not delivered to our clients. The bulk of our work comes from institutional clients who use either Outlook or Google enterprise email systems. With google moving over to stricter third party email standards soon, I fear we may see a significant increase in the number of emails not received. Frankly it's embarrassing to have to email every client after we send an invoice to ask if they got it. It comes across as either pushy or unprofessional, since we've chosen an accounting system that can't do basic stuff like reliably deliver emails. Please allow for us to send emails from our own domain. This is absolutely mission critical.
-
Marcus Dowling (Rising Connection) commented
Hello XERO Community,
It appears XERO has decided not to be compliant with modern email messaging standards when sending emails on behalf of its customers; a customer with clients using Google systems (such as Google Workspace or Google Enterprise) it appears will be unable to receive emails from XERO commencing February 2024.Another discussion thread with XERO shows the company's decision not to develop support for DKIM and DMARC authentication for all domains, noting the "Not Planned" status and that both the inability to "Vote" interest and "How important is this to you?" are now disabled.
* https://productideas.xero.com/forums/939198-for-small-businesses/suggestions/44960536-invoice-email-send-as-company-name-com-not-messHere is a good write-up on the evolving email-sending requirement that we found concerning Google's & Yarhoo's shift towards DKIM and DMARC authentication for all domains:
* https://www.valimail.com/blog/the-new-requirements-for-email-delivery-at-gmail/And here are both Google's & Yahoo's pages on the announcements.
* https://blog.google/products/gmail/gmail-security-authentication-spam-protection/
* https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spamMicrosoft announced similar measures in July 2023 that have already taken effect, so clients with Office 365 will already be having issues receiving invoices from Xero.
* https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-new-dmarc-policy-handling-defaults-for-enhanced-email/ba-p/3878883We hope the XERO team will reconsider; we want to keep our services with XERO. If we can not safely send Purchase Orders, Quotes, Invoices and other accounting-related services through XERO using our company email, we must consider alternative platforms to do our accounting.
In good faith :-)
-
Gillian Furlong commented
I wholeheartedly agree. The amount of extra work not having DKIM implemented creates makes Xero become quite a problem both for clients and us. Why hasn't this been done yet, I thought Xero was supposed to be 'modern' and forward looking compared to the rest of the market...?
-
Chris Templeton commented
Perhaps if they'd spent less money sponsoring things and using that money to pay developers to make these types of changes we'd all be happier.
-
Ian Edwards commented
This is a 30 minute task, it doesn't need change management, just get on and do it. Clients are getting very frustrated.
-
John Crawford commented
happening with us a lot
-
Jared Robinson commented
Agreed.. often having invoices overdue until I follow up only to find out that their being filtered to spam/junk or having attachments such as the attached invoice pdf removed from the email on the client end.