Catch-all & Routing

Why catch-all forwarding can become a spam cannon

Unknown FORWARD dumps harvested names into one inbox. Hold unknown. Time-box any audit. Leave the destination mailbox MX alone.

MailerZ editorial · Secuno LLC16 min read

Catch-all forwarding becomes a spam cannon when every guessed local-part on your domain is accepted and dumped into one inbox. The wildcard feels convenient on day one. Directory harvests, partner leaks, and typo dictionaries turn it into a hose. The fix is named aliases plus hold-unknown, not a new mailbox and not a Gmail filter pretending to be policy.

Diagram of catch all forwarding spam: harvested local-parts accepted and dumped into one Gmail inbox
The cannon is the policy that accepts names you never printed.

Quick answer for catch all forwarding spam

Catch-all means the receiving system treats unknown local-parts as valid recipients. Forwarding means those recipients are copied to a destination mailbox. Together they tell the internet: any string before the at-sign will reach a human. IETF RFC 5321 — Simple Mail Transfer Protocol will deliver to that local-part if MX accepts it. Spammers do not need your org chart. They need a domain that answers yes.

Named aliases are the opposite policy. Only the local-parts you created forward. Unknown mail holds or bounces. You still recover real typos by promoting them to named aliases after you see them in a hold queue. That is typo recovery without a cannon. See aliases and catch-all for the product control, and delivery and recovery for hop history when you need to prove a message was held instead of lost.

MailerZ Free holds unknown recipients. That default exists because silent FORWARD on a public domain is how small teams lose Gmail in a month. Paid catch-all FORWARD, if you enable it, should be a watched window while you inventory printed names, not a forever setting. This article does not promise that hold stops all spam to addresses you actually published. Those still arrive. The cannon is the unpublished names.

Do not disable the whole domain because catch-all went bad. Do not buy a mailbox seat per guessed name. Do not change personal Gmail MX. Change the unknown-recipient policy. Then prove a made-up local-part no longer lands.

User problem and decision criteria

The founder turned on catch-all so jon@ would work when the card said john@. That is a real job. The same toggle also accepted ceo@, office@, hr@, and every first name in a scraped LinkedIn list. Gmail’s filters fought the volume. Legitimate invoices@ hid in the same pile. The team concluded “email is broken” and priced Workspace seats. The inbox was not broken. The recipient policy was.

Decide with four questions. First: which local-parts are printed on invoices, the site, app stores, and printer panels? Those must be named aliases before you touch catch-all. Second: do you have someone who will review a hold queue this week? If no, you cannot run FORWARD-all as an audit. Third: is the destination one Gmail account or a shared mailbox? A cannon into a shared inbox takes down a team, not one person. Fourth: are you confusing plus-addressing with catch-all? you+tag@gmail.com is a Gmail convention. Catch-all is every local-part on your domain.

Criteria that matter: a hold-unknown default, a way to promote a held typo to a named alias, hop history that shows accept versus hold, and alias limits you can count. MailerZ Free allows ten aliases. If you have twelve printed names, you need a paid plan or fewer public strings. Criteria that do not matter: a promise that spam will vanish, a review count, or “unlimited aliases” that really means unlimited unknown FORWARD.

Role addresses make the cannon worse. support@ is a contract. If catch-all is on, support1@ and suport@ also land. Some of those are helpful typos. Most are probes. You want the contract named and the probes held. That is deliberate catch-all handling, not a religion against wildcards.

Directory harvest is not theoretical. Common local-parts are public knowledge. So are role names. Once a domain MX answers, senders try those strings. A catch-all that forwards is a confirmation that the domain accepts mail. Some operators then see backscatter: your server or the destination generates bounces that confuse the next hop. Hold-unknown reduces that confirmation. It does not make the domain invisible. MX still exists. The difference is whether guessed names become inbox noise.

Another failure mode is using catch-all as a CRM. People say “we will see who writes us.” That is not a pipeline. That is an unstaffed ticket pile with no names. If you want discovery, run a time-boxed FORWARD with a person assigned, export the local-parts that were real, promote them, and turn FORWARD off. A cannon that runs for a year is not discovery. It is neglect.

Agencies that inherit a client domain should assume catch-all is on until they prove otherwise. Send the made-up local-part test on day one, before you print new role addresses. If the test lands, you inherited a cannon. Defuse it before you add support@, or the new role drowns on the same day you launch it. Clients will blame the new alias. The policy was already wrong.

Technical mail flow

Hold unknown versus catch-all FORWARD everything for catch all forwarding spam
Policy after MX is the cannon or the hold queue. DNS is not the toggle.

MX names the host. The sending server delivers the message there. The alias service then matches the local-part. A named alias forwards to the destination. An unknown local-part follows the unknown policy: hold, reject, or FORWARD. Catch-all FORWARD is that third path for every miss. Envelope recipient on the forward hop is often rewritten so the personal provider accepts the copy. MailerZ uses SRS on the envelope only. Header From, Subject, Date, Message-ID, body, and MIME stay as written. You still see who mailed the guessed name. That is useful in an audit and painful in a cannon.

Destination filters are not a substitute. Gmail and Outlook will classify some of the hose. They will also bury a real vendor who used a slightly wrong local-part. Operators then enable catch-all “so we do not miss typos” and keep the hose. The hold queue separates those jobs: typos wait where a human can promote them; harvested names do not land in the same unread count as invoices.

Outbound is unrelated unless you also send as the domain. SPF, DKIM, and DMARC do not disable inbound catch-all. Republishing sending records because inbound is noisy is a different incident. Copy dashboard SMTP values only if paid send-as is in scope. MailerZ Free has no send-as. Open-relay attempts get 550. Disallowed authenticated traffic gets 550 5.7.1.

Leftover MX from Google or Microsoft can look like a catch-all bug. Some mail still hits the old host, which may have its own unknown-recipient behavior. Proof requires a public MX lookup, not only the alias dashboard. One MX set, then the unknown policy on that set.

Stored copies on MailerZ last fourteen days on Free and ninety days on paid plans. A cannon fills that window with junk you do not want to mine. Turning FORWARD off does not purge Gmail. Clean the destination with its own tools. The alias layer stops new unknown forwards.

Step-by-step setup / decision path

Five steps to defuse catch all forwarding spam without changing the main inbox
Inventory, hold, prove a never-created name, time-box any FORWARD audit.
  1. Export or write every local-part you have printed. Site, invoices, app stores, DNS comments, Slack display names, printer panels. If you cannot list them, you are not ready to leave FORWARD on.
  2. Create those strings as named aliases to the destination inboxes that already own the job. Do not point every name at the founder if billing belongs to finance.
  3. Switch unknown recipients to hold. If the product only offers on/off catch-all with silent FORWARD, you do not have a safe control. MailerZ Free holds unknown. Use that.
  4. Prove the cut. From a mailbox that is not the destination, send a uniquely titled message to a local-part you never created. You want hold or reject, not a Gmail row. Then send a unique message to a named alias and confirm Header From plus hop history.
  5. If you still fear missed typos, enable FORWARD only for a calendar week you will staff. Each day, promote real names to aliases and leave the rest held. On Friday, turn FORWARD off. Write what you promoted.
  6. Search Gmail filters and Outlook rules for attempts to “manage catch-all.” Those rules are not policy. They hide the cannon and make proof harder.
  7. Leave personal mailbox MX alone. You are changing a custom-domain recipient policy, not Gmail’s hosts.
  8. If alias slots are full, pause unused names or move to a paid plan before you invent another wildcard. Free is ten aliases. Solo is twenty-five aliases at forty dollars a year. Confirm live ceilings on pricing.

If several domains share one destination inbox, defuse each domain’s unknown policy. A cannon on a parked domain still lands in the same Gmail. People forget parked names. Look them up.

Document the hold queue owner. An unowned hold queue becomes a silent grave, and someone will turn FORWARD back on “temporarily.” Temporary without a calendar date is the cannon again.

If you operate multiple brands on one MailerZ account, defuse each domain separately. A quiet brand with catch-all on will still dump into the shared founder inbox you used as a default destination. Shared destinations multiply cannons. Point held unknowns at a review mailbox if the product allows, not at the CEO.

Failure modes and proof

Named alias disabled, catch-all still on: the leaked name still lands. Operators think pause failed. Proof: send to that name after pause. If it arrives, unknown policy is FORWARD.

Gmail filter used as catch-all off: hop history still shows accepts. Proof: open delivery rows for a made-up local-part.

Split MX: some networks hit the alias service (held), others hit leftover Google MX (accepted). Proof: public MX lookup shows more than one provider.

FORWARD audit with no owner: a month later the inbox is the cannon again. Proof: the calendar has no end date and no promoted-alias list.

Treating hold as loss: a vendor used a typo, the message sat in hold, nobody looked, they say you are down. Proof: hop history shows held, not missing. Staff the queue or promote common typos in advance.

Plus-address confusion: someone disables Gmail plus tags and thinks catch-all is off. The custom domain still forwards unknowns. Proof: the test address is on your domain, not @gmail.com.

Open-relay myth: people disable catch-all hoping it stops outbound spam. Catch-all is inbound policy. Outbound abuse is credentials and send-as. MailerZ is not an open relay. 550 / 550 5.7.1.

Archive fantasy: legal wants a year of every guessed name. Forwarding retention is fourteen or ninety days. The cannon is also a bad archive. Buy an archive product if you need years. See docs for how recovery is described, not as records retention.

Autoresponders on catch-all: every probe gets a “we got your mail” from the brand. That confirms the cannon to senders. Turn off auto-reply on unknown paths.

Shared Slack email-in: Outlook forwards everything to Slack, including the hose. Disable destination-side forwards that mention the domain, not only the alias toggle.

MailerZ workflow and product boundary

MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. It is not Workspace, not Microsoft 365, not IMAP, and not an open relay.

Free: one domain, ten aliases, one seat, fourteen-day store, send-as disabled, hold unknown. That hold is the anti-cannon default. Solo: forty dollars per year, twenty-five aliases, ninety-day store, 2,500 outgoing per month, 20 send-as per hour. Starter: eight dollars a month or eighty a year. Business: nineteen or one hundred ninety. Agency: thirty-nine or three hundred ninety. Quote the pricing page if numbers move.

Envelope SRS only. Headers and body intact. Recovery is not an archive. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you use paid send-as. Do not invent ports. This article does not invent SOC 2, ISO, HIPAA, SLAs, or inboxing rates.

To defuse a cannon in MailerZ: list printed names, create named aliases within plan limits, keep unknown on hold, prove a never-created local-part, time-box any FORWARD experiment. Destination inboxes stay where they are.

Cost, alternatives, and trade-offs

The cheap wrong move is more Gmail filters and a bigger Workspace quote because “email is noisy.” The cheap right move is hold-unknown on a forwarding plan. MailerZ Free can prove the path if three named aliases cover what you print. When you have more printed names, Solo at forty dollars a year is usually cheaper than a year of ignoring the hose.

Suites can reject unknown local-parts too, if you do not create users for them. They still cost per seat when you create a user per role. Compare seats versus aliases when the only pain was catch-all FORWARD.

Privacy-mask apps are not catch-all on your brand domain. They issue provider-owned addresses. Different job. Bulk ESPs are not inbound catch-all. Different job.

Doing nothing keeps the cannon. People create a second Gmail, forward the first, and now two stores eat the same hose. Policy first. Clone later only if the destination itself is the incident.

A staffed FORWARD week has a labor cost. Pay it once to inventory names. Do not pay it forever as unread count.

If a client demands catch-all forever, write that they accepted residual noise. Charge for the staffing or decline the wildcard. Silent yes is how agencies inherit cannons.

Hosting panels that ship “catch-all to admin” as a default are a common source. The domain was never meant to receive guessed names. The panel checkbox was left on during a WordPress install. Defuse that checkbox even if you later point MX at MailerZ. Two systems that both accept unknowns is a double cannon.

Marketing lists bought by someone else will keep mailing info@ and hello@ whether you created those aliases or not. If those strings are not printed by you, do not create them just because the list exists. Hold lets you see the volume without training Gmail that your brand accepts every greeting. Create hello@ only when you put it on the site.

Seasonal shops turn catch-all on for a product launch “so press can guess.” Press will guess wrong names and so will scrapers. Publish one press alias, give it to journalists, and hold the rest. A launch week is the worst week to open a wildcard. Volume hides the one interview request you actually needed.

Worked scenarios that keep the cannon off

A personal domain with a homepage you@ does not need catch-all FORWARD. Create the printed name. Hold the rest. A cousin who mails youu@ once can be promoted after you see the hold. That is a one-row change. Leaving FORWARD on so cousins never have to spell is how a harvest learns the domain answers yes to every guess.

A shop that prints orders@ and returns@ should create those two names and nothing else on day one. Press will invent pr@. Scrapers will invent admin@. Hold shows you the volume. Create pr@ only when you give that string to a journalist. Launch week is the worst week to open a wildcard: volume hides the one interview you needed.

An agency that inherits a client with “catch-all to the founder” should treat that as a finding, not a feature. Export the last week of unknown local-parts from hop history if you have it. Promote only the strings a real person used. Set unknown to hold before you print a new footer. If the client demands forever FORWARD, write that they accepted residual noise and staff the queue, or decline the wildcard. Silent yes is how you inherit a cannon you cannot bill for.

Catch-all FORWARD plus paid send-as is worse than inbound-only FORWARD. Unknown recipients that bounce at the destination still trained your brand as a valid mailbox. If someone later sends as a harvested local-part, receivers see a domain that already accepted that name inbound. Hold-unknown keeps the inbound map honest. Send-as still requires a named identity. Do not let a wildcard mint a From.

Hold and reject are not the same lever. Hold keeps a copy you can promote. Reject tells the sending server the local-part does not exist. Use hold when you still expect typos from customers who saw a printed name. Use reject when the public list is frozen and you do not want a recovery queue. Free holds or rejects unknowns; it does not silently FORWARD them. Paid FORWARD is optional and should be dated.

A legitimate FORWARD window is a staffed cutover: you are moving from a host that accepted everything, you need a week to see which leftovers are real, and someone opens the store every day. Write the end date on a calendar. After that date, return to hold. A FORWARD policy with no owner and no end date is the cannon with a nicer name.

Leftover MX can fake a policy win. You set hold on MailerZ, then a leftover Google MX still accepts info@ into a Workspace user you forgot. Public MX from two resolvers is the proof, not the dashboard toggle. Delete the leftover. Wait TTL. Probe a never-created local-part again. If it still lands in Gmail, you are not looking at MailerZ catch-all. You are looking at a split.

Autoresponders on unknown paths confirm the cannon. Every probe gets “we got your mail.” Turn auto-reply off on anything that is not a named, staffed alias. Destination-side forwards into Slack do the same: the hose becomes a channel. Disable those forwards before you debate the alias toggle.

FAQ

What is the safest way to handle catch all forwarding spam?
Name every printed local-part as an alias. Set unknown recipients to hold. Prove a made-up name does not reach Gmail. Use catch-all FORWARD only as a short, staffed audit. Do not keep silent FORWARD on a public domain. Leave the destination inbox MX alone.
Does this require a new mailbox?
No. Catch-all is a recipient policy on the custom domain. MailerZ is Mail Box portal webmail (Inbox, Sent, New email). It is not IMAP or POP. Gmail or Outlook stays the store. A new mailbox does not close a wildcard that still forwards.
Will it work with Gmail or Outlook?
Yes for destinations those products already provide. Catch-all FORWARD dumps harvested names into the same inbox those products filter. Hold-unknown keeps that dump out. Self-send tests hide both results.
What DNS records are involved?
Usually none if MX already points at the alias service. You only touch DNS for leftover Google or Microsoft MX, or for sending records if you also send. Catch-all is not an MX type. It is a local-part policy after MX delivers.
What should I test before production?
Send a unique message to a named alias and confirm delivery. Send a unique message to a local-part you never created and confirm hold or reject, not a Gmail arrival. Repeat after any policy change. Self-send from Gmail to Gmail can hide the cannon.

Key takeaways

  • Catch-all forwarding becomes a spam cannon when unknown local-parts all land in one inbox.
  • Name printed aliases first. Hold the rest.
  • Prove a made-up local-part does not reach Gmail after you change policy.
  • Gmail filters are not catch-all off. Hop history is the proof.
  • Time-box any FORWARD audit and assign an owner.
  • Leftover MX can mimic a policy bug. Look up MX in public.
  • A new mailbox seat does not close a wildcard.
  • MailerZ Free holds unknown. That is the default that keeps the cannon off.

Conclusion

Convenience without hold-unknown is a hose. List the names you printed, make them aliases, hold the rest, and prove a never-created string stays out of Gmail. Leave the main inbox where it is.

If you want that policy on a domain you already own, start on MailerZ with unknown held, add the three most important named aliases, and expand on a paid plan when the printed list is longer.

Start free on MailerZ