Booking.com has introduced Messaging Security Settings as part of its security enhancements to help protect properties and guests from phishing attacks.
These settings control which email addresses and website links can be shared with guests through Booking.com messaging. If an email address or link hasn't been approved in your Booking.com Extranet, Booking.com may prevent it from reaching your guests.
For ChargeAutomation users, this is particularly important because Booking.com may block important ChargeAutomation communications and links, including:
Pre-check-in links
Payment Page links
Payment Request links
Other ChargeAutomation guest links
Emails sent from ChargeAutomation
Who should update these settings?
Who should update these settings?
All ChargeAutomation users who have Booking.com as a booking source should review and update these settings as soon as possible.
Updating your Booking.com Messaging Security settings helps ensure that your ChargeAutomation links and emails continue to reach your guests.
It can also resolve issues where:
Pre-check-in links appear as [Link was removed]
Payment Page links aren't delivered through Booking.com messaging
Payment Request links aren't delivered through Booking.com messaging
Emails from ChargeAutomation are rejected
What you need to add to Booking.com
What you need to add to Booking.com
There are two important sections to configure in Booking.com's Messaging Security settings:
Approved email addresses
Approved links
1. Add ChargeAutomation's email address
In your Booking.com Extranet, add the following email address to your approved email addresses:
You should also add any other email addresses or domains that your property uses to communicate with guests.
2. Add ChargeAutomation domains
In the approved links section, add the ChargeAutomation domains that your guests may receive.
Important: Add the domain only, not the complete URL.
For example, don't add an entire guest link such as:
https://app.chargeautomation.com/....
Instead, add:
app.chargeautomation.com
What to do if you are using a custom domain
What to do if you are using a custom domain
If you use ChargeAutomation's custom domain feature, you must also authorize your custom domain in Booking.com.
You can find your custom domain in ChargeAutomation by clicking your logo in the top-right corner of the page and selecting Custom Domain.
For example, if your custom domain is:
www.xyz.mydomain.com
we recommend adding both:
www.xyz.mydomain.com
and
xyz.mydomain.com
This helps ensure that links using either version of your domain are accepted by Booking.com.
How to update your Booking.com security settings
How to update your Booking.com security settings
You must have admin access to your Booking.com Extranet to manage these settings.
Booking.com also requires you to complete two-factor authentication (2FA) before you can access or edit the security settings.
For a single property
Sign in to your Booking.com Extranet.
Go to Property.
Select Messaging preferences.
Click Security settings.
Complete two-factor authentication.
Add [email protected] under your approved email addresses.
Add app.chargeautomation.com under your approved links.
If you use a custom domain, add your custom domain as well.
For multiple properties
If you manage multiple properties through a Booking.com group account:
Sign in to your Booking.com Extranet.
Select a property from the homepage.
Go to Property > Messaging preferences > Security settings.
Complete two-factor authentication.
Add the required email addresses and domains.
Use Apply to all properties if you want the same security settings applied across your properties.
Important: Don't enable "Block all links"
Important: Don't enable "Block all links"
Booking.com allows you to completely block links from reaching guests.
If you enable Block all links, Booking.com will also block the ChargeAutomation links you've added to your approved list.
If you need to send ChargeAutomation links to guests through Booking.com messaging, make sure Block all links is turned off.
The same applies to Block all email communication. If this setting is enabled, even approved email addresses will not be able to reach your guests.
What happens if you don't update these settings?
What happens if you don't update these settings?
If the required ChargeAutomation domain isn't approved by Booking.com, links may be removed from messages and your guests may see:
[Link was removed]
This can prevent guests from accessing important ChargeAutomation pages, including their pre-check-in or payment pages.
If ChargeAutomation emails are not coming through, the sender's email address may also need to be added to your Booking.com approved email addresses.
Quick setup checklist
Quick setup checklist
To make sure your Booking.com and ChargeAutomation communications work correctly, confirm the following:
Your Booking.com account has the required admin access
[email protected] is added to your approved email addresses
app.chargeautomation.com is added to your approved links
Your ChargeAutomation custom domain is added, if applicable
Both the www and non-www versions of your custom domain are added, if applicable
You have completed two-factor authentication when updating the settings
Block all links is turned off
Block all email communication is turned off
You can read the Booking.com Partner Help article here
Still having issues?
If you've completed the setup above and ChargeAutomation links are still being removed or emails aren't reaching your guests, please contact ChargeAutomation Support with an example of the affected booking or message so we can investigate further.
