Xero Mail - Send as @company-name.com not message-service@post.xero.com
Ability to make an email sent from Xero appear as @company-name.com instead of message-service@post.xero.com, when users send an email to their client/customer.
Purpose: To provide more validity when sending communications from Xero out to clients/customers and avoid items ending up in Spam/Junk mail.
Hi team, we appreciate the on-going support and feedback we're receiving on this idea and pleased to be able to share this update. Our product team are actively exploring how we can best solve for the needs raised here, although at this time are unable to provide any set timeframes.
They are very much aware of the appetite from our community on this, and as part of their exploration have reached out some users here as they gather insights.
For the time being we'll shift to In discovery and I'll return as soon as there is more on this to share.
-
Andrew Syme
commented
Adam, I disagree. Read the first line i wrote. We know that threat actors are using DEMO. Therefore, if you give permission to XERO to send via SMTP, you are giving permission to DEMO to send emails under your name.
How many of "SendGrid, Amazon, HubSpot and many others" have a FREE demo account for anyone to use ?
-
Adam Romain
commented
Andrew,
I think there may be a bit of a misunderstanding here.
The suggestion isn't that anyone should be able to send arbitrary email addresses through Xero. The whole point of domain verification is the opposite .... it proves that the sender actually controls the domain they're sending from.
Platforms like SendGrid, Amazon, HubSpot and many others already do this. You add a DNS record to prove ownership of the domain, then configure SPF/DKIM so receiving mail servers can verify the message is legitimate.
Without that verification step, it wouldn’t work in the first place.
The current situation actually has the opposite problem .... invoices arrive from @post.xero.com, which can look less authentic to recipients who expect communication from the company’s own domain….
-
Andrew Syme
commented
There is also the reverse. We know that "Threat actors" are using Xero Demo Company to send fake invoices to targets.
Now, you wish to add your email addresses to their reportoire ?Email should be the second last resort (Postal being last) for communicating invoices.
-
Tim Sneller
commented
Gavin highlights one of the main problems. Because so much SPAM email appears to come from post.xero... that people just block them, withoiut any consideration of the impact to suppliers sending invoices.
It also makes it almost impossible for those of us who use Xero to block these spam emails without affecting copies of emails that we send to ourselves from Xero.
Please just enable us to specify an alternate SMTP service, so that we have an alternative. It will also look more professional if our invoices look as if WE sent them, and not an outside agency.
-
Gavin Wilkinson
commented
I receive job offers saying they are from Ferrari or Chanel, etc. and when I look at the address, it is a post.xero.com address.
There is no way these places would be offering me a job and they are clearly phishing. The trouble is that I can't flag them as such because it would mess with our billing and payroll. Nightmare.
Letting us send from our domain would be ideal. I can't think of any other platforms we use that don't allow this.
-
Dave Turney
commented
easiest thing in the world to solve.
just allow smtp LIKE EVERY OTHER SERVICE OUT THERE.get serious or start losing people.
i'm ready to make the jump. -
Adam Romain
commented
Kelly and the team @ Xero. I'm VERY pleased to see this major problem has now progressed internally at Xero.
From Xero's point of view, the objective is simple. Give customers who want the ability to use their own domain, following proof of ownership of the domain, the ability to send as alias@company-name.com
.A straightforward domain ownership verification step would prevent abuse. Once verified, users could configure the necessary DNS records (SPF/DKIM/DMARC) to support it.
If there are concerns around support load due to misconfigured mail authentication, the feature could simply be opt-in with a clear disclaimer that configuration of SPF/DKIM/DMARC is the responsibility of the customer.
Businesses that already operate with custom domains typically have access to the resources needed to configure DNS correctly. And for smaller customers or those who prefer simplicity, the existing @post.xero.com option remains perfectly suitable.
In other words, this doesn't need to replace the current system ... just provide a proper option for those who need it.
Ultimately, enabling this would strengthen the authenticity and professionalism of communications sent through Xero.... giving SMEs a small but meaningful professional boost, and making it a clear win for both customers and Xero.
Be bold Xero. Lead on this. It's important.... trust me..... I'm a consulting CISO.
-
George Aretakis
commented
Very good point, Richard Fincher
-
Stephanie Leito
commented
Glad more people are expressing that their customers are not receiving the invoices.
When i open a ticket Xero acts as if i'm the only one and wants to have a call with me. I told them i am not their beta tester. These problems started happening when they changed the new invoicing. I did not have it before.
This is very annoying to customers when they don't get the recurring invoices, but do get the reminder emails.
Xero send me this:
Please ask your IT department to try this:
Emails sent from Xero usually contain financial information, so can sometimes be incorrectly identified as spam and redirected to junk folders or rejected completely.
It’s also possible that your customer might have marked Xero email addresses as spam or has blocked them.
To resolve this, please ask them to add '@xero.com' and '@post.xero.com' to their email approve list to ensure they receive messages from Xero. Alternatively if their email service provider allows, they can add the following IP Addresses to their allow list:
192.237.159.130
192.237.159.151
192.237.159.187
192.237.159.186
104.130.122.55If they're still having trouble receiving emails from Xero, we'd recommend that they investigate further with their email service provider.
I've included a link to our support article for more information.
Xero Central article: Contact not receiving an email sent through Xero"
However, the issue still remains, thus we are receiving payments very late because of this issue.
-
Richard Fincher
commented
Yes, it only takes one or two people to mark @post.xero.com as spam, (perhaps because a former-supplier whose invoices they're disputing, keeps sending them invoices they don't want to receive), and that impacts on all the rest of us. Plus we ourselves might block this sender, without realising that we are also blocking every other supplier of ours who also happens to use Xero. Imagine if, in the old days, it'd been easy to inadvertently block incoming invoices by post from companies that used Sage Line 50?!
-
Stuart Murray
commented
I can't believe this.... my accountant wants me to switch from Zoho Books to Xero and now I find I can't even email my customers properly from the platform?? It's crazy that you haven't fixed this yet.
-
Natalie Moore
commented
I had a major client blacklist the @post.xero.com emails as they weren't sure they were legitimate. That was a fun few weeks! Several hundred emails bouncing back, and no one entirely sure why until we had the chance to speak to head office.
-
Chris Blackwell
commented
QuickBooks already has this, support for Gmail integration for sending invoices through your own Gmail account, not from generic Xero email address.
Would be more personal, professional and functional, as well as supporting record of sent emails (invoices etc) in Gmail sent items. Some services also do not accept emails of invoices unless from a recognised email address, so xero address is rejected.
-
Sam Foster
commented
Totally agree. I didn't mean it was an acceptable solution, it's a cumbersome workaround. Seems like a pretty basic feature to me.
-
Jon Murphy
commented
I currently use a service called Paidnice - this allows for Custom Domain settings via CNAME amendments and DKIM settings. I send all my invoices, statements, reminders through their page which links directly to Xero. It's the best i can find to enable all emails to come from my company email address rather than a generic Xero email address. You do have to pay for the service, so frustrating that Xero don't do this but Paidnice are providing a solution that works.
-
Tim Sneller
commented
That's OK if you are sending a single invoice, but when doing a large batch, that's not reasonable, and subject to error - Very easy to miss one.
Xero need to FIX the problem.
-
Sam Foster
commented
I currently send invoices and quotes to myself, then send to the customer from my business email directly.
-
Perry Paolantonio
commented
New customer - a law firm. Just had an invoice bounce. Xero helpfully says: "We could not determine the reason for this failure which may indicate a temporary issue. Please check the email address and try again."
I checked with the customer, and their IT department explicitly blocks post.xero.com entirely, because "the high volume of phishing emails associated with that server."
-
Stephanie Leito
commented
@Edward, Highly doubt they care, they have been losing customers because otherwise there is no reason to offer new customers 90% discount on a successful product for 6 months........
-
Edward Kay
commented
I've replied to Xero CEO's latest missive - see attached.
My expectations are low, but it's worth a shot.
Please consider doing the same.