Catch-all & Routing

Hold vs forward vs reject unknown recipients: best practice

Create printed aliases. Probe an unknown name. Keep Free hold until a typo is worth a dated forward. Do not ingest the internet into Primary.

MailerZ editorial · Secuno LLC16 min read

Unknown recipient hold forward reject is a policy choice after MX already answers. Hold keeps guessed names out of Gmail and stores them for a short window. Forward dumps leftovers into the inbox you use for work. Reject tells the sending server the user does not exist and keeps no copy for you. MailerZ Free holds. Paid plans can forward catch-all when you choose that tax. Name aliases first. Do not pick a leftover policy to hide missing routes.

Diagram of hold vs forward vs reject unknown recipients: hold on Free, paid forward, SMTP reject
Best practice is named aliases plus a leftover policy you can explain on a sales call.

Quick answer for unknown recipient hold forward reject

Best practice is not a slogan. Create every printed local-part as an alias. Publish one MX set. Delete leftover Google or host MX. Probe named aliases from another mailbox. Then decide what happens to names you did not create. MailerZ Free holds those messages. They do not appear in Gmail. You can inspect them inside the 14-day store. Paid plans may forward unknown recipients when that policy is on. Solo’s published card includes unknown forwarded; confirm the live toggle on MailerZ pricing and in the dashboard before you assume Gmail will stay quiet.

Reject is the third industry option: the MX returns a permanent failure such as 550 for an unknown mailbox. IETF RFC 5321 — Simple Mail Transfer Protocol allows a receiver to refuse a recipient. That is honest when you will never want the typo. It is also final: there is no hold queue to promote into an alias tomorrow. MailerZ’s documented Free behavior is hold, not a customer-facing “reject all unknowns” marketing switch. Do not invent a reject button that is not on the product. Explain reject so you can compare hosts. Then use hold or paid forward as the policies MailerZ actually ships.

Secondary phrasing—unknown recipient hold forward reject guide, unknown recipient hold forward reject setup, unknown recipient hold forward reject best practice—is one job. The guide is the three outcomes. The setup is aliases plus exclusive MX plus an unknown probe. Best practice is: never enable forward to hide the fact you never created billing@. See aliases and catch-all and the spam-tax article on catch-all convenience vs spam risk.

Addy’s public writing is useful competitor research on catch-all toggles. It is not MailerZ documentation: Addy blog. Header From on inbound stays the original sender. Envelope SRS may rewrite the return path. The product is not IMAP, not a junk filter, and not an open relay.

Free is one domain, ten aliases, one seat, 14-day store, send-as disabled, SMTP and API disabled. Solo is $40 per year, 25 aliases, 90-day store, 2,500 outgoing, 20 send-as per hour. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Paid store is 90 days. Those numbers are capacity, not an inbox-placement SLA.

The user problem and the decision criteria

Teams argue about leftovers because they skipped naming. The website says Contact. The invoice says billing. The registrar still has admin. Only hello@ exists. Customers write to the printed strings. Someone enables catch-all forward so “nothing is lost.” Gmail drowns. Someone else wants every unknown bounced so “spam stops.” A third person wants a queue. Those are three products. Pick with tests, not fear.

Decision criteria for unmatched local-parts
QuestionIf yesIf no
Is every printed name an alias?Leftover policy is insurance.Create the names. Policy is not a shortcut.
Must a typo still reach a human this week?Hold and staff the queue, or a short paid forward.Hold or reject. Do not hose Primary.
Is the destination your daily Gmail?Prefer hold. Forward is a tax on attention.A review mailbox can take a forward window.
Has the domain been public for years?Expect harvest. Hold. Watch the queue.A quiet new domain may tolerate a short forward.
Do you need the bytes tomorrow?Hold keeps a window. Reject does not.Reject is acceptable if you will never promote the name.
Must someone reply as the leftover string?Create a named alias and paid send-as. Leftovers are not identities.Inbound policy is enough.

The unknown recipient hold forward reject best practice is sequential. Names first. Exclusive MX second. Unknown probe third. Policy last. Reversing that order is how leftover MX and catch-all forward get blamed for each other.

What hold, forward, and reject actually do

Hold accepts the SMTP transaction for the operator’s store, then does not inject the message into the destination inbox. On MailerZ Free, unknown recipients are held. You get evidence: who wrote, to which invented name, at what time. You do not get a Gmail thread. The window is 14 days on Free and 90 days on paid plans. When the window ends, the leftover is gone. Hold is not an archive and not a compliance vault.

Forward accepts the transaction and sends the message to a verified destination, the same way a named alias does. Convenience for typos and old campaign strings. Spam risk for dictionary harvest. Paid MailerZ catch-all forward is this path. Solo’s card lists unknown forwarded; treat that as a plan default you must still understand, not as a requirement to keep Gmail noisy forever. You can still name aliases and reduce what “unknown” means.

Reject refuses the recipient at SMTP time. The sending server gets a permanent failure. A well-behaved sender may bounce to the envelope return path. A spammer learns the name is unused, or learns nothing useful, depending on how they probe. You keep no body to promote into an alias later. Reject is clean for operators who will never want leftovers. It is hostile to the customer who typed helloo@ the week you launched. MailerZ does not sell reject as the Free default. Free holds so you can still recover a real typo inside the store window.

None of the three policies create send-as. None rewrite Header From. None fix leftover MX. None promise Primary. Gmail can still file a forwarded leftover in spam, and can still hide a named alias. Policy is about whether the hop is attempted.

Technical mail flow

The sending server looks up MX and offers RCPT TO. IETF RFC 5321 — Simple Mail Transfer Protocol is the transport text. If the local-part matches a hosted alias, MailerZ stores required content, returns 250, and forwards. Header From stays the original sender. Envelope MAIL FROM may use SRS. History records the destination response.

Mail-flow for unknown recipient hold forward reject: envelope match versus leftover policy
Named aliases are the match path. Hold, forward, and reject are only for no-match.

If the local-part does not match, policy runs. Hold: store, do not inject Gmail. Forward: treat like an alias to the catch-all destination. Reject (industry): 550, no store. Leftover MX short-circuits all three. Some senders still talk to old Google or cPanel. Those messages never reach MailerZ hold. You will swear the policy is broken. Query two public resolvers. Use troubleshooting and the leftover MX tool before you flip hold to forward.

Authentication is outbound. IETF RFC 7208 — Sender Policy Framework (SPF), IETF RFC 6376 — DomainKeys Identified Mail (DKIM), and IETF RFC 7489 — Domain-based Message Authentication, Reporting, and Conformance (DMARC) authorize sending as your domain. They do not decide leftover inbound policy. A reject at MX is not a DMARC reject. Do not confuse domain authentication policy with recipient existence policy. They live in different layers and fail in different tickets.

Self-send from Gmail to the same Gmail account can hide named and leftover paths. Probe from an unrelated provider. Unique subjects. Match history to the inbox or to the hold queue. That pair is the only proof that matters.

Delivery recovery storage is 14 or 90 days. It applies to accepted content MailerZ stored. A true SMTP reject at another host never creates that object. Do not expect a hold queue on a server that bounced the recipient. If you migrate from a host that rejected unknowns to MailerZ Free, you will suddenly see held leftovers you never saw before. That is visibility, not a new attack. Staff the queue for a week before you enable paid forward.

Multi-destination aliases do not change leftover policy. If sales@ lands in two Gmail accounts, that is a named route with two destinations. An unknown local-part still hits hold or catch-all forward, not “every teammate.” Do not confuse a shared role with a dictionary of names. Shared destinations are for people who must see the same printed address. Leftover policy is for names nobody printed.

Open-relay refusal is a different 550. MailerZ rejects unauthorized outbound send. That is not unknown-recipient inbound policy. Operators mix the two in tickets because both say 550. Read the enhanced status. Unhosted or unauthorized send gets 550 / 550 5.7.1. An inbound leftover on Free should be a hold event, not an outbound auth failure. Keep those artifacts separate when you write to support.

Step-by-step unknown recipient hold forward reject setup

Setup path: name aliases, exclusive MX, probe unknown, then set leftover policy
No hosted walkthrough video. Policy last. Names and MX first.
  1. Inventory printed local-parts

    Website, invoices, app stores, banks, registrar, partner sheets. Free allows ten aliases. If you have twelve printed names, you need Solo or you need to unprint names.

  2. Create those aliases and verify destinations

    Map roles to Gmail or Outlook someone reads. Complete destination verification. Do not loop destinations. Shared destinations are fine. Catch-all is not a substitute.

  3. Publish exclusive MX

    One set. Delete leftovers. Split records lose mail before hold or forward can help.

  4. Prove each named alias

    Other mailbox. Unique title. Header From intact. History matches the destination response.

  5. Probe one unknown name

    On Free, expect hold. If Gmail receives it, you are already forwarding or you are on the wrong MX.

  6. Staff the hold queue for a week

    Real typos of live roles become aliases. Dictionary harvest stays held. That week is the unknown recipient hold forward reject guide in practice.

  7. Enable paid forward only with a stop date

    Migration or rename windows. Dedicated review mailbox if you must. Calendar reminder to disable. Do not leave Solo’s unknown-forwarded card running into Primary without watching it.

  8. Do not expect catch-all to send

    Paid send-as is for approved identities. Unauthorized From gets 550. Free has no send-as.

When reject is the honest tool

Reject belongs in this article because operators ask for it, not because MailerZ Free is a bounce factory. Use reject language when you compare hosts that 550 unknown mailboxes on purpose. Use it when a security team wants directory harvest to fail at the door. Use it when you will never promote a leftover into an alias.

Reject is the wrong tool the week after a rebrand. Customers still have the old string. A 550 teaches them the brand is gone. A named alias for the old string, or a short hold you staff, is kinder and cheaper than a week of “your mail bounced” tickets. Reject is also the wrong tool if you have not listed printed names. You will bounce the invoice address and call it security.

Backscatter matters. If a system accepts a forged message and later generates a bounce, innocent envelope senders get collateral. A clean SMTP reject during RCPT TO avoids accepting the body. Hold accepts and stores. Forward accepts and injects. Those are different abuse surfaces. MailerZ hold exists so you can recover a real message, not so you can generate bounce storms. Do not configure destination-side auto-replies on catch-all forward. That is how you become a backscatter source.

If a different host already rejects unknowns and you move MX to MailerZ, expect held leftovers you never saw. That is not MailerZ inventing spam. That is MailerZ showing you the harvest that used to die at 550. Decide with the queue in front of you. Most teams keep hold. A few enable a temporary forward. Almost nobody should want every harvested name in Primary.

Failure modes and proof

Observed failure, likely cause, next action
What you seeLikely causeProof to collect
Gmail flooded after upgradePaid unknown forward on a harvested domain.Disable forward. Keep named aliases. Review hold.
Customer printed name is heldAlias never created.Create the local-part. Do not flip policy.
Some senders vanishLeftover MX, not hold versus reject.Public MX from two resolvers.
Unknown probe in Gmail on FreeWrong MX or unexpected forward.MX set. Destination headers. Dashboard policy.
Self-send emptyGmail short-circuit.Different provider.
Held mail expired14- or 90-day window ended.Not an archive. Recreate the alias if it mattered.
Replies show gmail.comNo paid SMTP. Leftovers are not From identities.From selector. Plan send-as.
SMTP 550 on sendUnauthorized From or open-relay refusal.Exact response. Not leftover inbound policy.

Proof is the unknown probe plus public MX plus the hold-or-inbox outcome. Do not send SMTP passwords to support. Inbox placement is not proof of policy. A spam folder full of leftovers is proof you forwarded unknowns.

MailerZ workflow and product boundary

MailerZ is a custom-domain email delivery layer operated by Secuno LLC. Site: mailerz.net. App: mail.mailerz.net. Positioning: named aliases, multi-destination routing, and deliberate leftover handling. Hold on Free. Optional paid forward. Not a reject-as-a-service brand.

What MailerZ does

  • Accept named aliases on verified domains.
  • Hold unknown recipients on Free.
  • Allow paid catch-all forward when configured.
  • Preserve Header From. Envelope SRS only.
  • Store 14 days on Free or 90 days on paid plans.
  • Record delivery history.
  • Paid SMTP from approved identities only.

What MailerZ does not do

  • Offer send-as on Free or send-as for harvested local-parts.
  • Create IMAP mailboxes or Gmail users.
  • Rewrite header From, Subject, Date, Message-ID, body, or MIME.
  • Promise inbox placement, uptime SLAs, or review counts.
  • Claim SOC 2, ISO 27001, or HIPAA. Security.
  • Act as an open relay or campaign sender.
  • Guarantee a customer-facing reject toggle as the Free default.

Cost, alternatives, and trade-offs

Policy is cheap. Attention is not. Hold costs a weekly review of a short queue. Forward costs Gmail time. Reject costs the customer who typed the wrong name and the support thread that follows. Named aliases cost slots: three on Free, 15 on Solo at $40 per year, then 50 / 200 / 500. That is still cheaper than a Workspace seat per guessed string.

Honest trade-offs
ApproachYou getYou give up
Named aliases + Free holdClean inbox. 14-day evidence.Uncreated names never reach Gmail.
Paid catch-all forwardTypos arrive.Harvested junk in the destination.
SMTP reject at some other hostNo store. Directory harvest fails at the door.No typo recovery. Not MailerZ Free’s default.
Forward to a review mailboxPrimary stays cleaner.You still accepted the spam at MX.
Cloudflare routing leftoversInbound policy in that DNS.MailerZ leftover-MX stop and stored hops. Cloudflare — Email Routing documentation

Annual Starter, Business, and Agency include two months free versus monthly. Solo has no monthly option. Seats operate the router. They are not extra leftover pipes. Do not buy Agency to “afford reject.” Reject, hold, and forward are not priced as three SKUs. Alias count and domain count are the cards that scale.

Workspace can reject or accept unknowns depending on how the suite is configured. You still pay seats. You still clean leftover MX if you leave. Do not buy the suite to solve a leftover-recipient argument. Buy it when you need hosted mailboxes and the office apps.

Time is the hidden line item. Ten minutes naming three aliases is cheaper than a week of leftover mail in Primary. A Free-plan branded-reply promise is more expensive than Solo. Budget one external unknown-recipient probe as part of cutover. If nobody owns the hold queue, hold becomes a graveyard and you will miss the one typo that was a customer. Assign a person. Fifteen minutes a week on Free is enough for most founder domains.

Agencies should copy a leftover policy per client, not invent poetry. New client domains start on hold after named roles exist. Harvested client domains stay on hold until a week of queue review. Temporary forward only during MX cutover, with a ticket that has a close date. Agency is $39 or $390 with room for many domains. That capacity is not a reason to forward unknowns on every property.

Personal domains follow the same tests with a smaller catalog. you@ plus hello@ is enough for most people. Hold the rest. Plus tags on Gmail are not leftover policy on your zone. If you still use plus addressing inside the destination, that is a filter trick, not MX-level reject. Keep the layers straight or you will disable catch-all and wonder why you+shop@gmail.com still works.

FAQ

What is the safest unknown recipient hold forward reject setup?

Create every printed local-part as an alias, publish one MX set, and leave unknowns held on Free. Paid catch-all forward is a watched window, not a shortcut for missing names. Reject at SMTP is what some hosts do with 550 user unknown; MailerZ’s documented Free behavior is hold, not a bounce you configure as a marketing toggle.

Does this require a new mailbox?

No. Hold, forward, and reject are policies for unmatched recipients after MX already points at a receiver. MailerZ is not IMAP. Named aliases still land in Gmail or Outlook. Hold keeps leftovers out of that inbox.

Will it work with Gmail or Outlook?

Yes for named aliases into verified destinations. Hold never reaches those inboxes. Paid forward does, including junk. Reject never stores a message for you to open. Free has no send-as. Catch-all does not mint From identities.

What DNS records are involved?

A verification TXT, one MX set, leftover host MX removed, and SPF, DKIM, and DMARC if you send as the domain. Unknown-recipient policy is not a DNS record. Split MX makes hold, forward, and reject look random because some senders never reach you.

What should I test before production?

Probe each named alias from another mailbox. Then send to a local-part you did not create. On Free it should be held. If it appears in Gmail, you are forwarding unknowns or you are not on the MX you think you are. Self-send can hide both outcomes.

Key takeaways

  • Unknown recipient hold forward reject is leftover policy after named aliases exist.
  • Hold keeps Gmail clean and stores a short window. Free does this.
  • Forward is a paid hose. Useful for a dated migration window.
  • Reject is an SMTP 550 some hosts use. MailerZ Free holds instead.
  • Do not enable forward to hide missing names.
  • Leftover MX makes every policy look random.
  • Header From stays the original sender. Envelope SRS only.
  • Authentication records are not leftover policy.
  • Probe an unknown name before production.
  • MailerZ is not SOC 2, not IMAP, and not a spam-filter SLA.
  • Staff the hold queue weekly or hold becomes a graveyard.
  • Outbound 550 is not leftover inbound policy. Keep the artifacts separate.

Conclusion and next action

Hold, forward, and reject are three answers to names you did not print. Best practice is to print fewer surprises: create the aliases, clean MX, probe an unknown, then keep Free hold until a typo is worth a dated forward. Do not bounce customers for strings you still advertise. Do not ingest the internet into Primary.

Next action: add one domain, create the printed aliases, send a uniquely titled probe to a name you did not create, and confirm it is held. Only then decide if anyone should see leftovers in Gmail. If the probe lands in Primary, stop printing new names until MX and policy match the dashboard. If the probe is held and named aliases arrive, you are ready to use the domain in public.

Ready to hold unknowns on purpose

Start free with one domain and prove the path.

Three aliases on Free. Unknown held. Paid forward only when you choose the tax.

Review quarterly, or sooner if leftover policy or alias limits change. Author: MailerZ editorial, Secuno LLC.