Skip to main content
Administrator Guide
Last Updated: 2026-04-17
Configure Email Ingestion for Supplier Accounts

Configure Email Ingestion for Supplier Accounts

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
  • UMSA
    , the feature is automatically available. You can skip the
    Enable Innovation Services Feature and AI Data Contributions for MSA Customers
    step. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
  • MSA
    , you must enable this feature through Innovation Services using the
    Enable Innovation Services Feature and AI Data Contributions for MSA Customers
    step.
Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
  • Security:
    Reports: Supplier Invoice OCR Initial Upload
    domain in the Supplier Accounts functional area.
  • Configure the
    Supplier Invoice Event
    business process and security policy in the Supplier Accounts functional area.
You can use email ingestion to enable a Workday tenant to receive inbound supplier accounts emails in specific domains. When you enable email ingestion, Workday automatically scans emails for invoices using OCR (Optical Character Recognition). Example: When an authorized vendor submits an email invoice, Workday automatically processes the email content into a supplier invoice request.
  1. On the
    Available Services
    tab, in the
    Cross Application Services
    category, select the
    Email Ingestion
    service to enable it.
    You might need to take additional steps to enable this feature depending on your organization's subscription service agreement. For more information, see this Community article.
  2. Access the
    Edit Tenant Setup - Machine Learning
    task.
    Select the region in which Workday hosts data used for improvement and personalization of machine learning and analytics functionality.
    Security:
    Set Up: Tenant Setup - Machine Learning
    in the System functional area.
  3. Access the
    Create Security Group
    task.
    Create a segment-based security group and select the suppliers, supplier groups, or supplier categories that you want to include in the segment. Included values can cross multiple segments or be mutually exclusive. Workday recommends that you build from least to most restrictive segment.
    Security:
    Security Configuration
    domain in the System functional area.
  4. Access the
    Domain Security Policies for Functional Area
    report.
    In the System functional area, select the
    Set Up: Inbound Email
    domain and click
    Edit Permissions
    to grant your segmented security group access to the domain.
    Security:
    Security Configuration
    or
    Security Activation
    domain in the System functional area.
  5. Access the
    Edit Tenant Setup - System
    task.
    In the
    System Setup
    section, select
    Allow Attachments within Emails
    to ensure that email ingestion can receive attachments into your tenant.
    Security:
    Set Up: Tenant Setup - System
    domain in the System functional area.
  6. Access the
    Create Email Ingestion Receiving Domain
    task.
    Create a receiving domain for email ingestion and configure it in your DNS provider configuration.
    Option Description
    Subdomain
    Enter the subdomain for the Email Ingestion domain. Example: Invoices
    Domain
    Enter the domain to use for Email Ingestion. Example: GMS.com
    Example: If your subdomain is Invoices and your domain is GMS.com, your Email Ingestion receiving domain is Invoices.GMS.com.
    Security:
    Set Up: Inbound Email
    domain in the System functional area.
  7. Copy the Canonical Names (CNAMEs) and Mail Exchange (MX) values into the DNS host.
  8. Access the
    Verify Email Ingestion Receiving Domain
    task.
    1. Select your receiving domain from the
      Receiving Domain
      prompt.
    2. Click
      Refresh
      to ensure that the values in the
      Verified
      column of the
      DNS Records
      grid change to
      Yes
      .
    Security:
    Set Up: Inbound Email
    domain in the System functional area.
  9. Access the
    Configure Email Ingestion Settings
    task.
    Option Description
    Notification Type
    Select the Supplier Invoice notification type to which you want to link the receiving domain.
    Receiving Domain
    Select the receiving domain to use with the selected notification type.
    Allowed Senders
    (Optional) Add a row for each email address from which you want the receiving domain to accept inbound emails.
    Security:
    Set Up: Inbound Email
    domain in the System functional area.
  10. Configure the
    Email Ingestion Tab
    in the Work Area.
Workday processes emails for the notification types you configure into your Workday tenant. Workday routes any email attachments to OCR for scanning and invoice creation.
When an authorized vendor submits an email invoice, Workday automatically processes the email content as a supplier invoice request.
After emails start delivering through your domain, you can access the
Inbound Email Ingestions By Date Range
report to track the:
  • Status of system events launched by inbound emails.
  • Type of requests received through the domain.
  • Issues that might cause the process to fail.
If you opt out of the Email Ingestion Innovation Service, you must also:
  • Run the
    Delete Email Ingestion Settings
    task.
  • Run the
    Delete Email Ingestion Receiving Domain
    task.
  • Work with your IT Administrator to remove the information added for Email Ingestion from your DNS configuration.