Tipalti Help Center home page
  • Get started
    • Onboarding tools
    • Video tutorials
  • User guides
    • Tipalti Hub Home
      • Log in to the Tipalti Hub
      • Home for employees
      • Home for finance team
    • Tipalti AI Assistant
      • Ask the assistant
      • Common prompts
    • Administration
      • General
      • Communications
      • Bills setup
    • Multiple entities
      • Multiple entities
      • Switch entities with multi-instance setup
    • Funding
      • Funds overview
      • Manage virtual accounts
      • Fund Tipalti accounts
      • Transfer funds between accounts
      • Fund Multi-FX accounts
    • Payees
      • Add, import, and invite payees
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Manage actions as a payee
      • Add and review payee documents
      • Verification of payee
    • Taxation
      • US tax forms
      • Tax form expiration
      • Tax withholding
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement
      • New Procurement
      • Original Procurement
    • PO matching
      • What's new with PO matching
      • PO matching
      • Review PO matching
      • Updates to POs
      • Bill approval for PO-backed bills
      • Match dropship invoices
      • Handle prepayments
      • Matching process
      • Bill routing
      • Matching policies
    • Bills
      • Start using Bills
      • Manage bills
      • Approve and pay
      • How Bills works
    • Tipalti Expenses
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Build expense approval workflows
      • Reimburse expenses
      • Connect and manage your corporate cards
    • Tipalti Cards
      • Tipalti Cards
      • Fund your card
      • Manage cards
      • Process transactions
      • Monitor card transactions
      • Card matching
      • ERP sync
      • Credit card statement report
    • Payments
      • Submit payments
      • Manage payments
      • Schedule payments
      • Understanding payment statuses
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
      • Managing unsuccessful payments
    • Reports
      • AI-powered reports
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices
      • Email security
      • Business continuity practices
      • Two-factor authentication
      • Detect
  • Integrations
    • 3rd Party Apps
      • Partner Platforms
      • SSO
    • ERPs
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration
      • Configure auto-sync settings
      • Import files
      • Export files
  • Resources
    • Webinars
    • General FAQs
    • User guide FAQs
      • Payee FAQs
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
    • Support FAQs
  • Release notes
  • Dev docs
Sign in
  • Get started  
    • Onboarding tools  
    • Video tutorials  
    • Live training  
  • User guide  
    • Log in to the Tipalti Hub
    • Administration  
      • Administrative operations
      • User roles
    • Multiple entities
    • Funding  
      • View funds required
      • Fund Tipalti accounts
      • Fund Multi-FX accounts  
        • Currency cutoffs and validations
    • Payees  
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Documents review
    • Taxation  
      • US tax forms
      • Tax form expiration
      • Tax withholding  
        • Withholding rates
        • Income types
        • Tax form and entity types
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement  
      • System overview
      • Create and track purchase requests
      • Approve purchase requests
      • Mark goods and services as received
      • Vendor registration
      • Send PO PDF
      • Back office  
        • Set reminders
        • Run parallel PR/ vendor approval
        • Emails
        • PO PDF customization
        • Upload budget
        • Customize Procurement forms
        • Contract repository
      • Workflow integrations
    • PO Matching  
      • Matching process
      • Handle matching exceptions
      • Bill routing
      • Matching policies
      • Bill coding
      • Bill approval for PO-backed bills  
        • Approvable bills
        • Non-approvable bills
        • PO updates
      • Prepayments (NetSuite 2.0)
      • Track and match a dropship invoice  
        • Set payees up as dropship vendors
        • Upload and match a dropship invoice
    • Bills  
      • Bill flows
      • Usability
      • Add invoices
      • Manage bills
      • Add comments and files to bills
      • Bill approvers
      • Invoice processing approvals
      • Email Security
      • Tax collection in Bills
      • Bill statuses
    • Tipalti Expenses  
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Reimburse expenses
      • Connect your corporate cards
    • Tipalti Cards  
      • Funds flow
      • Manage cards
      • Card transactions overview
      • Process transactions
      • ERP sync
      • Credit card statement report
    • Submitting payments
    • Payment information  
      • Payment statuses defined
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
    • Reports  
      • Smart report builder
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices  
      • Email security
      • Business continuity practices
      • Two-factor authentication
    • Detect
  • Integrations  
    • 3rd Party Apps  
      • Partner Platforms
      • SSO
    • ERPs  
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration  
      • Configure auto-sync settings
      • Import files
      • Export files
  • FAQs  
    • General FAQs
    • User guide FAQs  
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
  • Release notes
  • Dev docs
  1. Tipalti
  2. Resources
  3. User guide FAQs
Follow

Articles in this section

  • User Guide - General FAQs
  • Payees FAQs
  • Bill FAQs
  • Card FAQs
  • PO matching FAQs
  • Payment FAQs
  • Taxation FAQs
  • Administration FAQs
  • Expenses FAQs
  • Email domain setup FAQs

Email domain setup FAQs

This article covers detailed information to help technical admins configure an email domain in Tipalti. For a more general overview, go to Email domain setup.

What do SPF, DKIM, and DMARC mean?
  • SPF (Sender Policy Framework) - SPF checks that the mail server sending an email is allowed to send messages for your domain.
  • DKIM (DomainKeys Identified Mail) - DKIM adds a digital signature to each message, proving that it’s authentic and hasn’t been changed during delivery.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance) - DMARC uses SPF and DKIM to confirm that emails come from your domain and haven’t been forged.

If any of your DMARC policies are set to strict, please contact Tipalti support before making any changes.

What is the ‘MAIL FROM’ or Return Path?

The Return Path (also known as the “envelope sender”) tells receiving mail servers where to send bounce or delivery failure messages. It’s hidden from most users but is key for authentication and managing delivery issues.

How does domain registration work?
  1. Tipalti creates DKIM keys (public and private).
  2. The public key is hosted under tipalti.com; the private key stays secure in AWS SES.
    Tipalti hosts the DKIM public key as a TXT record under a subdomain of tipalti.com (for example: <customer-domain>.dkim.tipalti.com).
  3. You add a CNAME record in your DNS pointing to Tipalti’s DKIM record.
  4. SES verifies ownership.
  5. Once verified, Tipalti can send DKIM-signed emails for your domain.

Why this is secure:

  • The CNAME lets mail servers find Tipalti’s DKIM key automatically.
  • Tipalti handles key rotation and security.
  • You only add one simple DNS record—no key management needed.
What are dedicated IPs, and why might I need them?

Some organizations only accept emails from approved IP addresses (IP whitelisting).

By default, AWS SES uses shared IPs that can change over time. Tipalti offers dedicated IPs, which are fixed and exclusive to Tipalti for your domain. Enabling the dedicated IPs option ensures that users in your domain receive emails from a list of static IPs. This does not apply to emails sent to your payees.

How to enable:

  • Go to the Domain Registration page and enable static IPs.
  • You can view the full list of Tipalti’s current IPs here: https://ips.tipalti.com/prod-email-ips
What is a Custom ‘MAIL FROM’ and why would I use it?

By default, emails display a Return Path, e.g., something@amazonses.com.

A Custom MAIL FROM lets you use your own subdomain, like bounce.yourdomain.com.

Benefits:

  • Branding: Removes “mailed-by: amazonses.com” from message details.
  • Filtering: Makes it easier to route or archive emails internally.
  • Consistency: Aligns all technical email fields with your domain.

How to set it up:

  1. Contact Tipalti Support.
  2. Choose a subdomain (e.g., bounce.yourdomain.com).
  3. Tipalti will provide MX and TXT DNS records to add to your DNS.
  4. Once verified, the feature will be activated for your domain.

Result:

Your emails’ Return-Path and “mailed-by” fields will reference your domain.

What is the suppression list, and how does it affect delivery?

Amazon SES keeps a suppression list of email addresses that shouldn’t receive mail.

Addresses are added if:

  • They bounced permanently.
  • The recipient server rejected them.
  • They caused spam complaints.

If an address is on the list, Tipalti emails to that address won’t be delivered.

To remove an address:

  1. Contact Tipalti Support.
  2. Provide the affected email address(es).
  3. Tipalti will request removal through Amazon SES.
  4. Once cleared, messages will resume normal delivery.
What does TLS enforcement mean?

Tipalti uses TLS (Transport Layer Security) to encrypt emails while they’re being sent.

Default behavior:

  • Uses the strongest available encryption (TLS 1.3).
  • Falls back to older versions if needed.

When TLS 1.3 is required:

Some sensitive messages (like Tipalti Card notifications) require TLS 1.3 only. If the recipient’s mail server doesn’t support it, those emails won’t be delivered for security reasons.

Common troubleshooting tips
Cloudflare proxy issue

If you manage your DNS with Cloudflare, ensure that CNAME records are set to DNS Only (represented by a grey cloud). Cloudflare’s orange cloud proxy can break AWS SES verification.

How to fix:

  • Go to your Cloudflare DNS settings.
  • Switch SES-related CNAMEs from orange to grey.
  • Save and allow time for DNS updates.
Duplicate domain name issue

Some DNS providers automatically append your domain name. If you type the full domain manually, it can duplicate (e.g., tipalti._domainkey.tipalti.com.tipalti.com).

Fix:

In your DNS provider, check the final FQDN value shown for the record.

If your domain name appears twice, this configuration is incorrect.

Enter only the host portion (e.g., tipalti._domainkey). Your DNS provider will append the domain automatically.

Was this article helpful?

We’d love the opportunity to improve. Submit your feedback.

We’re glad you enjoyed the article!

Have more questions? Submit a request
Return to top
Privacy Policy | Terms of Use | Payer/Sender Rights | Customer Assistance Policy
LinkedIn Instagram Facebook Twitter YouTube
Contact support