Xero invoices often go to junk because they don't come from your email address at all: Xero sends every invoice from its own shared address, messaging-service@post.xero.com, with your business name on it and your address only as the reply-to. Because the email also carries financial details, a link and often a PDF, some spam filters wrongly flag it, and Xero's own help says this can happen.
How Xero sends your invoices
When you click Email on an invoice, Xero's mail server sends it. Your customer sees your business name as the sender, but the actual From address is Xero's. In Xero's email settings you choose two things only:
- The reply-to address. Replies from your customer go here.
- The email name. The sender name your customer sees.
Xero's help says the address it sends from is always messaging-service@post.xero.com and can't be changed. If you've seen advice to "verify your domain in Xero", that option isn't in Xero's current help. Sending from your own domain is a popular request on Xero Product Ideas. In March 2026 Xero marked it "In Discovery", with no timeframe.
What this means for SPF, DKIM and DMARC
Receivers run SPF, DKIM and DMARC checks against the domain in the From address. For a Xero invoice, that is Xero's domain, not yourbusiness.com.au. So:
- Xero is responsible for its own SPF and DKIM. There's nothing to add to your SPF record for Xero.
- Your DMARC policy doesn't apply to Xero invoices, because your domain isn't in the From address.
- Alignment (the From domain matching the domain that passed SPF or DKIM) is between Xero's domains, not yours.
If your invoices land in junk, the cause is usually not your DNS. It's how the receiving mail system treats a shared sending address and an invoice-shaped email.
Why Xero invoices land in junk anyway
- Every Xero organisation sends from the same address. Filters judge that address on everything sent from it, not just your invoices.
- The name and the address don't match. Your customer sees your business name next to a Xero address. Invoice scams use exactly this look, so some filters and some people are wary of it.
- Strict filters at your customer's end. Xero's help notes that some email hosts use high-level filters that can delay, junk or reject genuine invoices. Businesses with their own spam filter in front of Microsoft 365 are the usual examples.
How to fix it
1. See what your customers' mail systems see
Make a contact in Xero with your private test address as its email. Then email it a small test invoice, and void the invoice afterwards. The report shows which domain the invoice really comes from, whether it passes SPF, DKIM and DMARC for that domain, and a verdict for Outlook.com, Microsoft 365, Gmail, Google Workspace and Yahoo. If Xero's own checks fail, contact Xero support. Tell them the check failed and which server sent the email.
2. Ask customers to add Xero to their safe senders
Xero recommends that your contacts add @xero.com, @identity.post.xero.com and @post.xero.com to their safe senders list. A customer on Outlook or Hotmail can do this in Outlook's junk email settings, and marking a junked invoice as not junk helps too. On a business Microsoft 365 account, their IT administrator may need to allow these addresses for the whole organisation.
3. Set a reply-to address on your own domain
Use an address like accounts@yourbusiness.com.au that someone reads, not a personal Gmail. To set it:
- Click the organisation name, then select Settings.
- Click Email settings.
- Next to Email address, click Edit, then Add email address.
- Enter the reply-to address and the email name you want customers to see, then click Add email.
If you add an address Xero hasn't used before, the owner of that mailbox has to approve it. The approval link expires after 14 days. You need the standard or administrator user role to change these settings.
4. Make sure your own email is set up properly
You still chase overdue invoices, send statements and answer questions from your own mailbox. That email uses your domain, so your SPF, DKIM and DMARC decide whether it reaches the inbox. If you use Microsoft 365, check you have:
| Type | Name | Value |
|---|---|---|
| TXT | yourbusiness.com.au | v=spf1 include:spf.protection.outlook.com ~all |
| TXT | _dmarc.yourbusiness.com.au | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au |
Keep only one SPF record, and change the rua address to a mailbox you read. Then switch on DKIM for your domain in the Microsoft Defender portal.
5. For important customers, send from your own mailbox
If one customer's system keeps junking Xero's emails, download the invoice PDF or copy its online invoice link, then send it from your Microsoft 365 mailbox. Some add-on apps send Xero invoices from your own domain. If you use one, it will give you its own SPF and DKIM records to add. Test it the same way.
Checked against: Xero Central, Email settings · Xero Central, Contact not receiving an email sent through Xero · Xero Product Ideas, Xero Mail - Send as @company-name.com not message-service@post.xero.com · Microsoft Learn, Set up DMARC to validate email in Microsoft 365.
