Email Receiver processing flow: classification, trusted sender and document type with three output paths
Setting up a trusted email sender (Email Receiver)

Setting up the Email Receiver: allow a specific email address or domain to submit invoices.

With the Email Receiver, you control exactly which email addresses are allowed to submit invoices to your organization. This prevents unwanted or unknown invoices from entering your administration. You configure per supplier or domain that their invoices are automatically processed.

What is a trusted sender?

A trusted sender is an email address or domain that you have approved to send invoices to your organization. Only emails from these approved senders are processed; all others are blocked. This works as a whitelist for your invoice delivery.

When you create a trusted sender, the platform generates a unique email address. You share this address with your supplier, who uses it to submit invoices. In the overview (the sidebar option "All"), you can see all your created email receivers with their generated addresses and status.

You need at least a Basic subscription to use the Email Receiver.

From supplier email to processing

An incoming supplier email first reaches the Email Receiver. There the platform classifies the message, checks the trusted sender and assigns the document type. The flow then splits: invoice to processing, attach a specification, or ignore a logo or terms document. Each supplier gets a unique address on trust.econnect.eu.

Step 1: Create a trusted sender

Open the Email Receiver app in the platform and click New sender. For each sender, you configure the settings described below.

Whitelist type

Choose how you want to identify the sender:

  • Specific email address (Specific Address): only this exact address may submit invoices. The White List From Address field accepts exactly one address — not a comma- or semicolon-separated list of multiple addresses. This is the most secure option.
  • Entire domain (All within this domain): all email addresses from this domain may submit invoices (for example supplier.com). Useful when a supplier sends from multiple addresses.
  • Verified user: a user who has been verified on the platform.
  • Accept all: emails from any sender are accepted, without whitelist restrictions.

Per Email Receiver address, you can whitelist one domain. Does your organization need to receive invoices from multiple domains? Create a separate Email Receiver address for each domain, or use a specific email address per supplier for maximum security.

Need a second specific sender address? With whitelist type Specific email address, you can't simply add a second address in White List From Address: the field is single-value. For a second trusted sender at the same organization, create an additional Email Receiver with that second address. If both addresses may be on the same domain, there's an easier way: change the whitelist type of the existing Email Receiver to Entire domain / All within this domain instead of creating a second receiver.

Organization filter sender

Optionally, in the Organization field (on the sender side) you can specify which organization may submit invoices as a supplier. If you fill this in, only emails from that specific supplier organization are accepted. This makes the generated email address extra secure, as emails from other organizations are rejected.

Document type

Specify what should happen with the received invoices:

TypeWhat happensPurchase invoiceInvoice is delivered to the recipient in the InboxSales invoiceInvoice is archived for administrative processingDraft invoiceInvoice is queued for review and manual sending
Allowed document types

With the Allowed document types field, you determine which invoice formats are accepted:

  • E-invoices only: only XML invoices are processed.
  • Digital invoices only: only PDF invoices are processed.
  • Both e-invoices and digital invoices: both formats are accepted (default).

In eConnect terminology, "digital invoices" refers to PDF invoices and "e-invoices" refers to XML invoices.

Supplier recognition

With the Populate supplier email address based on field, you determine which email field is used to identify the supplier. The default is "Sender email address", but if a supplier uses an alias or forwarding address, you can choose a different field from the email header (such as Reply-To).

Supplier recognition serves two purposes. First, the supplier receives feedback messages when something goes wrong during processing, for example when the email has no attachment or the document cannot be processed. Second, the identified email address is included in the XML delivered to the accounting system, so the supplier is also traceable there.

Automatic sending

For draft invoices, you can optionally enable Send XML automatically. When the sender submits a valid XML invoice, it is automatically sent via Peppol without manual intervention. If the XML is not valid, the invoice is queued as a draft for manual review. This option requires SSL/TLS security to be enabled and the XML to be valid.

Note: the Draft invoice document type does not exclude automatic sending. If a sender submits a valid XML invoice with document type Draft invoice, it will also be automatically sent via Peppol once Send XML automatically is enabled.

Send via

With the Send via option, you can forward secured emails with valid XML invoices directly to the recipient via Peppol in one step. This requires the SSL/TLS security option to be enabled and the XML to be valid.

Step 2: Configure security options

The Email Receiver offers additional security layers:

  • SSL/TLS requirement: on first use of a trusted sender, the system automatically detects whether SSL/TLS is used. If so, it is then required for all subsequent emails from this sender.
  • Contact email address: set a separate email address where rejection notifications are sent. This does not need to be the same as the trusted sender's address.
  • Organization filter: by specifying a specific supplier organization, emails from other organizations are rejected.
Step 3: Conversion for multiple organizations

If you work with multiple administrations, you can enable the Conversion for multiple organizations option. The platform then automatically detects which administration a submitted invoice is intended for. This way, you can use a single email address for multiple administrations instead of creating a separate address per administration. This works for both XML invoices and PDF invoices.

This feature requires a Professional subscription or higher.

Note: enabling conversion for multiple organizations requires not only the setting in the Email Receiver but also configuration on the backend of the platform (IDR settings). This step cannot be completed fully independently. Involve a sales colleague so that the required platform configuration is set up correctly. Contact our sales team.

Step 4: Configure notifications

Per trusted sender, you can configure whether you want to receive a confirmation email when an invoice arrives through this sender. This helps you keep track of which suppliers are submitting invoices and when.

Step 5: Activate and invite

After creation, the trusted sender has the status "Draft". Before emails are processed, the sender must be activated. This can be done in two ways:

Manually activate: change the status to "Active". The trusted sender is then immediately operational.

Send invitation: instead of manually activating, you can send an invitation to the supplier. The supplier receives an email explaining the generated email address and how to use it for submitting invoices. On first use by the supplier, the email receiver is automatically activated. The status changes from "Invited" to "Active".

In the Email Receiver app sidebar, you can filter by status: Drafts, Invited, Active and Inactive. This helps you keep track of which senders are in which stage.

Office 365 integration

Does your organization use Office 365 and is email forwarding not permitted? You can create a direct connection with your Office 365 mailbox. Use the "Alternative delivery address" field in the Email Receiver configuration to set up the O365 integration.

Frequently asked questions
Can I set up multiple trusted senders for different suppliers?

Yes, you can create a separate trusted sender per supplier. Each trusted sender gets a unique email address and its own settings for whitelist type, document type and security options. This gives you full control over who may submit invoices and how they are processed.

What happens if someone sends an invoice that is not on the whitelist?

The email is rejected and not processed. Only emails from approved senders (based on the configured whitelist type) are accepted. The sender does not receive an error notification — the email is simply not picked up.

Do I need a specific subscription to use the Email Receiver?

Yes, you need at least a Basic subscription to use the Email Receiver. For the "Conversion for multiple organizations" option (administration detection), a Professional subscription or higher is required.

Why does my Email Receiver stay empty while the whitelist looks correct? (multi-entity/holding)

Do you work with multiple entities or a holding structure, and does an Email Receiver at *@trust.econnect.eu stay empty while the sender's domain appears to be whitelisted? First check whether anything actually arrives in the logs or the Inbox of this receiver, not just for another entity. Then open the sent email and look literally at the From field: that is what counts, not the display name. A holding company and a subsidiary often have separate Email Receivers with their own whitelists. The fact that the same outgoing address works for another entity does not prove that the From address and whitelist are correct for this receiver. Check the whitelist entry exactly against the From address: typos, aliases and forwarding rules change the visible sender address. Want to quickly test whether the channel is reachable? Temporarily set the Email Receiver to Accept all (not possible with Draft invoice) and restore the whitelist after the test.

I sent an email to my trust address, but I don't see anything in the portal or my accounting/ERP system. What now?

Check this in a fixed order — skipping a step often leads to the wrong conclusion:

  1. Correct trust address. Check for typos and the right organization/entity, and whether you used your production or pilot address (trust.econnect.eu versus a pilot variant).
  2. Has anything arrived at all? Check whether this Email Receiver received mail in the relevant period. The status Active alone is not enough: an Email Receiver can be active while no email has arrived yet.
  3. Whitelist and the From address. If an email was received but is not processed, compare the From address literally with the whitelist setting (see the question above about an empty Email Receiver with multiple entities).
  4. Correct organization in the portal. Check whether you are looking at the right organization or administration.
  5. Only then check your accounting or ERP connection (for example Metacom): a working connection there does not rule out an empty Inbox or an Email Receiver with no received mail. So start the diagnosis at the Email Receiver's reception, not at the connection.
I get the message 'You are not a trusted sender' — where do I start looking?

First check the To/receiving address literally, digit by digit (local part + domain), before diving into the whitelist or the From address. The error message is about the sender/whitelist, but the cause can also be an incorrectly noted receiving address — for example one missing or transposed digit in the local part, copied from a manual, signature or forwarded message. Compare the address used with the Email Receivers actually configured in the platform. That other colleagues within the same organization can successfully submit invoices does not rule out an incorrect To address: check whether the successful and failed attempts were sent to the same receiving address. If the To address is correct and the message persists, only then move on to the whitelist settings (Verified user, domain, specific address) as described above.

Our shared test or accounts-payable mailbox gets the message 'Sender's email address is not present as a member or additional email address', while a colleague can submit from a personal address. What now?

This happens with whitelist type Verified user (the default setting). That type only accepts emails whose From address belongs to a user (member) of the organization, or to a verified additional email address on such a user profile. A shared test or accounts-payable mailbox is not a member and therefore does not count, even though it concerns the same Email Receiver address a colleague can successfully submit to.

You have three equivalent solutions, choose what fits best:

  1. Create a user for the test address, so it counts as an organization member.
  2. Add the address as an additional email address on an existing user profile and verify it via the activation link.
  3. Change the whitelist type on the Email Receiver to Specific email address with the test mailbox as the value, or to Entire domain if the whole organization domain may submit.

First confirm the To/receiving address is correct (see the question above) before adjusting the whitelist. A previously rejected email is not automatically reprocessed after the fix: have the sender resubmit the invoice.

I received a confirmation of the email connection, but my PDF invoice is not visible in the draft invoices. What now?

A confirmation email when setting up the email connection means at least one email has been successfully received on this Email Receiver — so the connection works. That a PDF invoice you submit afterward is not yet in the draft invoices is usually not an incident but normal processing time: a PDF invoice first goes through IDR conversion (Scan & Recognize) before it appears as a draft invoice. For this conversion: 99% of documents are processed within 8 working hours (see SLA IDR); in practice the average turnaround is lower. Look in the overview under Sales invoice — Draft invoices, not just the generic Inbox. If the invoice remains untraceable even after the waiting period, first check whether the correct receiving address was used and whether the Email Receiver has status Active, before further investigating the whitelist settings.

Our monthly invoices do arrive at the trust address, but another invoice type (for example a quarterly statement) does not. What now?

This occurs when the same supplier normally invoices monthly via *@trust.econnect.eu, but a different invoice type — for example a quarterly or annual statement — does not arrive at that same receiving address. First gather three pieces of information before investigating further: the invoice PDF or invoice number with invoice date, the literal From address of the sender, and the date and (if known) time of sending.

Then follow this order:

  1. Receiver hit. Does this Email Receiver show mail or activity around that invoice number or time in the reported period? The status Active alone is not proof of receipt.
  2. No hit found. Then the email likely did not reach the Email Receiver. Have someone check whether the To address is exactly correct (typo or missing digit in the local part) and whether the supplier actually sent the invoice. In this case, do not assume a platform outage or whitelist problem without a receiver hit.
  3. Hit found, but nothing processed. Compare the From address with the whitelist setting of this receiver and entity, and check whether the invoice ends up in the correct organization or administration.
  4. Multiple entities. Do multiple subsidiaries use the same receiver, and does the monthly flow work fine there? That only proves the channel works in general — not that this specific From address, To address or invoice type was correct for this attempt.

Want to learn more about how invoices are processed via email? Read how submitting purchase invoices by email works.

Learn how to submit invoices