Web

What Is a Catch-All Email Address? Uses, Risks and Alternatives

Talha Aslan 19 min read 2 views

What is a catch-all email address?

A catch-all email address collects every message sent to your domain that does not match a real mailbox. If you only have info@example.com, a typo such as ifno@example.com still reaches the inbox you chose. Control panels also call this feature the default address.

We are a digital marketing and web team, not a hosting company. This guide is for site owners, ecommerce managers and developers who run their own cPanel account. Our explanations rely on cPanel, Google Workspace, Postfix and RFC documentation. However, menu labels can differ between hosting providers.

First we cover the definition and the mechanics. Then we walk through the cPanel steps. After that we look at spam, security and a side effect called backscatter. Finally we compare aliases, explain how to switch the feature off and give you a short decision list.

How does a catch-all email address work?

A sending server looks up the MX record for the domain in the recipient address. Then it connects to your mail server and says it has a message for that address. Your server then checks the part before the at sign against its own records. If it finds a match, it first delivers the message to that mailbox.

If there is no match, the server has two options. It can reject the message, or it can send it to a fallback rule. Catch-all is the second option. In other words, every unknown address goes to one destination that you pick.

So the decision happens when the server checks the recipient. Because of that, the panel keeps mailboxes and aliases in a lookup table. When the address is missing from the table, the last rule takes over. With catch-all on, that rule says accept and deliver here. With catch-all off, it says reject.

However, there is one subtle point. If a server accepts a message and then cannot deliver it, it has to generate a bounce. If it rejects the message before accepting it, the sending side handles the failure. So that difference matters in the backscatter section below.

What is a catch-all email good for?

A catch-all email setup is good at catching mail that would otherwise vanish. First, people make typos. Someone types contcat@ instead of contact@. Also, another sender uses an address from an old business card that you no longer run.

Therefore the feature lowers the chance of lost mail. It helps most on a brand new domain, when you do not yet know which addresses people will use. For example, you can watch what arrives during the first weeks and then create permanent addresses based on real traffic.

For instance, consider a hypothetical campaign. You give each channel its own address, such as ads@, newsletter@ and expo@. With catch-all on, you see which address received mail and measure the source. This is an invented example, not a real case. Still, it shows the logic: the setting is useful until the measurement ends.

However, the benefit has a price. However, next to the mail you wanted, a lot of unwanted mail arrives. So the real question is not whether it is useful. The question is whether the benefit outweighs the cost.

When does a catch-all email address make sense?

Catch-all makes sense in low-volume, short-term situations. The cases below are typical.

  • The first few weeks after you set up a new domain, before your address plan settles.
  • A domain migration, because you may not know every old address that people still use.
  • Third, a short experiment where each campaign gets its own address.
  • Finally, a temporary observation period on an account with very few mailboxes and a strong spam filter.

In short, the common thread is time. Also, in each case you do not leave the setting on forever. When the observation ends, you create the real addresses one by one and switch catch-all off.

Who should not use a catch-all email address?

If your domain has been active for years, a catch-all email box usually does more harm than good. Because of their age, addresses at older domains circulate on spam lists. Bots also guess common names and send to every one of them. With catch-all on, all of that lands in your inbox.

Online stores and company teams also should avoid it. For example, orders, invoices and support threads often share one mailbox. A real customer request can disappear under a pile of junk. In other words, that means lost sales and a weaker reputation.

Likewise, small businesses fall into the same trap. If you open the mailbox once a month, you will not notice one price request buried in spam. Yet that request could be the most valuable message of the month. So do not turn the feature on unless someone owns the mailbox.

Then there is quota, which is another problem. If the catch-all mailbox fills up, real mail bounces once the limit is reached. The setting can therefore cause the very losses it was meant to prevent.

Where is the default address setting in cPanel?

In cPanel, the catch-all setting sits on the Default Address screen under the Email section, as the cPanel documentation describes. The screen decides where mail for your domain goes when it matches no mailbox. Also, some localized interfaces use a different label.

First, a domain list sits at the top of the screen. If you own several domains, you configure each one separately. According to the documentation, a domain forwarder runs before the default address. So knowing that order helps you understand unexpected routing.

Also, the menu name can change with your provider. If you cannot find the screen, your provider may have disabled it. In that case, ask the support team.

If one account hosts several domains, each add-on domain appears as its own entry. Do not assume the setting on the main domain applies to the others. Check every domain and send a test message to each.

How do you set up a catch-all email in cPanel?

The setup takes only a few minutes. However, keep the order, because a wrong choice can delete all mail silently. Then follow the steps below.

  1. Sign in to cPanel and open Default Address from the Email section.
  2. Pick your domain from the "Send all unrouted email for the following domain" list.
  3. Choose the routing type. The next section compares the options.
  4. Enter a mailbox that you actually monitor as the destination.
  5. Click Change and wait for the confirmation message.
  6. Send a test message from your own outside address to a random address and check the result.

Also, do not send test mail to real customers or colleagues. Instead, test only from an address you control. Check the inbox and the spam folder a few minutes later.

Which default address options exist, and which one should you choose?

First, the cPanel documentation lists five options. They look alike at first, yet the results differ a lot. The table below summarizes them and adds the warnings from the documentation.

OptionWhat it doesWhen it fits
Discard with an error message at SMTP timeRejects the message before accepting it and tells the sender.The safest choice for most sites.
Forward to an email addressSends all unrouted mail to the address you pick.Fine for short observation, but it brings spam.
Forward to your system accountDelivers mail to the account's system mailbox.Avoid it unless you have a specific reason.
Pipe to a programHands the message to a script you point to.Only for automation under developer control.
Discard silentlyDeletes the message without telling the sender.The documentation advises against it.

As a rule, start with the first option. If you really need to catch mail, switch to the second and set an end date.

Next, here are the details. With rejection, the server answers before it accepts the message. A real person who mistyped the address sees the error at once and fixes it. With forwarding, the mail reaches your inbox, but the sender never learns about the mistake. Silent deletion is the worst choice, because neither side notices the problem.

However, piping to a program is for developers only. A script processes every message, so a bug in the script affects all incoming mail. Also, the security and maintenance load is high. Unless you need automation, skip this option.

Why does a catch-all email increase spam?

First, spammers collect addresses in three ways. They use leaked lists, they scrape web pages and they guess names. In the third method, a bot tries hundreds of names such as info, sales and john at your domain.

With catch-all off, your server rejects the wrong guesses. So the bot cannot easily learn which addresses are real. With catch-all on, every guess looks like a success. As a result, the bot may flag your domain as a rewarding target and keep sending.

Then the spam volume in your inbox rises. The cPanel documentation gives a clear warning here. If spammers target your domain and you forward mail to a default address, that address can receive a large amount of spam.

Spam is not only annoying, it also uses resources. Each message takes storage and needs scanning on the server. On shared hosting with resource limits, heavy spam can turn into quota and performance trouble. Besides, no filter classifies every message correctly, so some of it still reaches the inbox.

What is backscatter, and how does it relate to catch-all?

Backscatter is a bounce notice for a message you never sent. First, the spammer forges the sender address. The target server first accepts the message, then fails to deliver it, and then sends the bounce to the owner of the forged address. That victim could be you, or it could be someone else.

The Postfix backscatter document explains the cause in this order. In short, the server accepts the message and rejects it later. As a fix, it recommends rejecting invalid recipients during the SMTP conversation, before the server accepts the message.

Catch-all makes the problem bigger in the following way. First, the server treats every address as valid and accepts the mail. If a rule or a filter rejects it afterward, the server creates a bounce. Therefore a badly configured catch-all can make your domain send backscatter to strangers. As a result, your IP address may end up on blocklists.

RFC 5321 touches on the topic as well. Notification messages travel with an empty return path, which aims to prevent error loops. However, that rule does not remove the harm of bouncing to a forged sender. So the real fix is still to reject before acceptance. Discuss the details with your server administrator or provider.

Is a catch-all email address a security risk?

Yes, it is. However, most of the risks are about lost control, not direct attacks. An unlimited set of addresses at your domain can be used to sign up for services you do not know about. In that case, verification and password reset messages land in your catch-all mailbox.

  • Phishing messages can reach you and your staff through fake addresses that carry your company name.
  • Anyone with access to the mailbox can see verification and reset mail for accounts opened under your domain.
  • Also, a pile of spam hides real security alerts.
  • Real messages bounce once the quota fills up.
  • Forwarded spam can damage the reputation of your sending server.

None of these risks is a disaster alone. Together, however, they turn catch-all from a set-and-forget option into something that needs care. For the wider web security picture, read our OWASP Top 10 guide.

How do you use defined aliases instead of a catch-all email?

An alias is a defined alternate address that sends mail to another mailbox. For example, you point sales@example.com at your support inbox. Catch-all takes everything, while an alias takes only the addresses you wrote down.

However, the fix is simple. You define the likely addresses and their common misspellings one by one. For instance, you create separate aliases for info, contact, hello and sales. This way you catch the usual typos and still keep out bots that guess at random.

Even with a limited number of aliases, you stay in control. When your needs change, adding or deleting an alias takes seconds. You can also open a temporary address per campaign and delete it when the work ends.

First, role addresses are a good starting point for naming. Info, contact, sales, support and billing are enough for most sites. For personal addresses, use a first name and last name pattern. Keep a note of the target mailbox and the responsible person for every alias. That way it stays clear who reads which mail.

Catch-all or alias: which one is better?

Next, here is a comparison of the two approaches. The table is a summary based on general logic. Results in your own setup may differ.

CriterionCatch-allDefined alias
Typo coverageCatches all of them.Catches only the variants you define.
Spam loadHigh.Low.
Backscatter riskGrows if misconfigured.Invalid recipients get rejected, so risk drops.
ControlUnlimited addresses, little control.Every address is your decision.
UpkeepEasy to set up, the mailbox needs cleaning.A small extra task for each new address.

So for most businesses, aliases are the more balanced choice. Catch-all only makes sense as a temporary, monitored tool.

What happens if you turn catch-all off, and how do you do it?

If you turn catch-all off, mail to unknown addresses no longer reaches your inbox. The sender gets an error notice, so that person learns the address was wrong. In most cases that is the behavior you want.

To switch it off, return to the same Default Address screen. Set the option to discard with an error message at SMTP time and click Change. Do not delete the old destination mailbox right away. Review what arrives there for a few days.

However, that review matters. If the mailbox holds real customer mail, move it to the right place and create aliases for those addresses. Then you can clean up the old mailbox. It also helps to put the right contact address into the rejection message if your panel allows it.

Instead, do this move in steps rather than all at once. First list the addresses that receive mail for a week. Then create aliases for the real ones. After that, switch catch-all off and check the behavior with your own test messages in the first days. This order keeps the risk of lost mail low.

How does catch-all email work in Google Workspace?

Google Workspace also has a similar setting. Google Workspace Admin Help describes a catch-all address as the address that receives messages sent to a nonexistent user or a misspelled address at your domain.

According to that article, you first create or confirm the address you want to use. Then you follow Apps, Google Workspace, Gmail and Routing in the Admin console. Under the account types section, you tick "All inactive and unrecognized accounts". The change can take a while to spread.

Put simply, the logic matches cPanel. Therefore the spam and security warnings above apply in the same way. Outside Google, menu names may differ, so rely on your provider's own help pages there.

In a company account, only an administrator can switch this on. Also, responsibility should be clear. When you pick the destination, remember that several people may reach that mailbox. Verification and password reset mail can show up there, so limit access to the people who truly need it.

How can you reduce spam while catch-all stays on?

If you must keep catch-all on, you can limit the damage. None of these steps solves the problem fully, but together they lighten the load.

  • Turn on your hosting provider's spam filter and check its sensitivity.
  • Use a mailbox only for this job and keep it apart from your main inbox.
  • Clean the mailbox often and watch the quota.
  • Also, set a deadline. For example, put a reminder in the calendar to switch it off after two weeks.
  • Do not forward the destination mailbox to an outside provider, because forwarded spam can hurt your reputation.

Also check your domain's authentication records. SPF, DKIM and DMARC make it harder for others to spoof your domain. You can test your records with our SPF, DKIM and DMARC checker. To see your current DNS records, our DNS lookup tool helps too.

What is the difference between catch-all email and email forwarding?

However, people often mix up the two ideas. Email forwarding sends mail from a defined address to another address. Catch-all gathers mail for undefined addresses into one destination. In short, one serves known addresses and the other serves unknown ones.

Also, forwarding has its own subtleties. How it affects SPF and DKIM checks is a separate topic. We do not repeat it here, because our forwarding guide in the same series covers it step by step.

You can also use both together. According to the cPanel documentation, a domain forwarder runs before the default address. That way, your known addresses follow their own rules and everything else follows the default rule.

How do website forms and WordPress notifications interact with catch-all?

Your website often sends mail from your domain. For example, order notices, form replies and password reset links count here. The sender address of these messages is often something like noreply@example.com, which has no real mailbox behind it.

With catch-all on, replies and automatic notices sent to that address land in your destination mailbox. For instance, a customer may hit Reply, and nobody reads the answer. As a result, the mailbox fills with both customer mail and automatic noise.

With catch-all off, the reply goes back to the sender as an error. That is useful information, because the customer learns that nobody watches the noreply address. A better fix is to show a monitored mailbox as the reply address in your forms. You set that in your site's email sending settings.

How does catch-all email affect deliverability?

Deliverability is the chance that your mail reaches the recipient's inbox. However, catch-all affects it indirectly. If the mailbox fills with spam, you bounce real mail. Then senders may read that as a sign of a problem domain.

A server that produces backscatter also loses reputation. Receiving providers and blocklist services can flag servers that send bounces to forged senders. Such a flag may push your own outgoing mail into spam folders. So the trouble does not end with incoming mail.

For this reason, think of your email setup as one whole. Keeping incoming mail clean protects the reputation of outgoing mail as well. Check your records regularly and talk to your hosting provider if you see anything unexpected.

When should you leave this to your hosting provider?

First, let us be honest. You do not need to configure everything yourself. In the cases below, hand the job to your hosting provider or server administrator.

  • You need to change server configuration to reject mail at SMTP time.
  • Your server landed on a blocklist or you received a backscatter complaint.
  • You run high mail volume and need to tune the spam filter.
  • You manage several domains or customer accounts and want to apply the setting in bulk.

For example, rejecting unknown local recipients in Postfix is a server setting that the Postfix documentation describes. On shared hosting, that level of change is not in your hands anyway. So you ask your provider for it.

For more on picking a host, read our guide to choosing web hosting. If the question is legal or contractual, this article is not legal advice.

Where does catch-all fit in a business email setup?

In a business email setup, every address has an owner and a purpose. Role addresses such as info, sales, support and billing are defined. Personal addresses belong to employees. A catch-all address stays outside this order as an address with no owner.

For this reason, business setups rarely want it. Nobody takes responsibility for a mailbox without an owner. Instead, mail piles up and nobody looks. The better approach is to define role addresses clearly and reject the rest.

To choose an email platform, see our business email with a custom domain guide. There we compare hosting mail, Google Workspace and Microsoft 365. Also, we do not repeat that comparison here.

What is a short decision guide for a site owner?

To decide, answer the questions below in order. So your answers show whether you should turn the setting on.

  1. Is the domain new and your address plan not settled? Then you can turn it on briefly.
  2. Will someone check the mailbox every day? If not, leave it off.
  3. Are the quota and spam filter adequate? If not, leave it off.
  4. Do customer threads land in the same mailbox? If so, leave it off and use aliases.
  5. Did you set an end date? Without one, the setting gets forgotten.

If most of your answers are no, rejecting at SMTP time plus defined aliases is the best fit. That way, wrong addresses return to the sender and your spam load stays flat.

How do you check your catch-all setting?

After you change the setting, verify the behavior. Otherwise you may not notice a bad configuration for months. Then follow this simple sequence.

  1. From your own outside address, send a message to a random address that does not exist.
  2. If you chose rejection, confirm that you received an error notice.
  3. If you chose forwarding, confirm that the message reached the destination mailbox.
  4. Check the fill level and the spam volume of the destination mailbox every week.
  5. Review your DNS and authentication records.

Also check your domain details with our WHOIS lookup tool. If you do not know where your domain is registered or which DNS provider you use, you cannot change email settings in the right place.

According to RFC 5321, a server can answer with a 550 reply when the recipient is unknown. Therefore that is the standard way to reject. So rejecting is not rude behavior. Instead, it is correct and expected. For details, see RFC 5321.

Conclusion: should catch-all email stay on?

So for most sites, the answer is no. A catch-all email setup is an easy way to catch misspelled addresses. However, it costs you spam, backscatter risk and control. Those costs usually outweigh the short-term benefit.

In practice, the path is simple. Turn it on briefly after a new setup, watch which addresses arrive and define the real ones as aliases. Then switch catch-all off and move to rejection at SMTP time. That way your customers write to the right address and your mailbox stays clean.

If you want to plan your email setup together with your website, see our web design services or our contact page. This article offers general information and is not legal advice.

Frequently Asked Questions

Should a catch-all email stay on?
For most sites, no. A catch-all email setup catches misspelled addresses, but it raises spam and backscatter risk. You can turn it on briefly for a new domain and watch the traffic. Then define real addresses as aliases, switch the feature off and reject unknown recipients at SMTP time. That keeps your mailbox clean.
Where is the catch-all setting in cPanel?
It sits on the Default Address screen under the Email section. You pick the domain, choose the routing type and click Change. Some interfaces use a different label for it. If you cannot see the screen, your hosting provider may have disabled it, so ask the support team, because menu names vary between providers.
Does a catch-all email bring more spam?
Yes, it does. With catch-all on, the server accepts every address. Bots that guess names read that as success and keep sending. The cPanel documentation warns that a default address can receive a large amount of spam. Turn on the spam filter and clean the mailbox often.
What is backscatter?
Backscatter is a bounce notice for mail you never sent. A spammer forges your address, the target server accepts the message and then rejects it later. The fix is to reject invalid recipients during the SMTP conversation, before accepting the message. A badly configured catch-all can make this risk bigger, so take care.
What should I use instead of a catch-all email?
Use defined aliases. Create the likely addresses and common misspellings, such as info, contact and sales, and point them at your existing mailbox. You catch real mail and keep out bots that guess at random. You can also open a temporary alias for a campaign and delete it when the work ends.
Do I lose mail if I turn catch-all off?
No. With the rejection option, the sender receives an error notice and can fix the address. Still, review the destination mailbox for a few days before you switch it off. If real customer mail arrives there, create an alias for that address, then clean up the old mailbox and test with your own message.
  • catch-all email
  • default address
  • cPanel
  • backscatter
  • email aliases
  • spam
  • business email
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.