A catch-all (or wildcard) address accepts mail sent to any address at your domain, including ones that were never deliberately created — a typo, an address made up years ago on a business card, or one nobody remembers setting up. Instead of bouncing unrecognised addresses, everything lands somewhere.
It is not a routing feature by itself. On its own, a catch-all is just "do not bounce, deliver everything to this one mailbox" — which is exactly why it needs a routing rule sitting behind it to be useful rather than a mess.
Common, legitimate reasons:
- An old business or domain has years of addresses handed out informally (info@, sales@, a founder's first-name address) and nobody has a full list of what is actually in use.
- A website or webstore auto-generates addresses (order-1234@, ticket-5678@) and every one of them needs to arrive somewhere without pre-creating a mailbox for each.
- Migrating domains and wanting a safety net so nothing addressed to the old naming scheme silently bounces during the transition.
Spammers routinely guess addresses at a domain to find live ones. A domain with no catch-all bounces the guesses, which tells the sender the address does not exist and, over time, makes your domain a less attractive target for that kind of scanning. A domain with an open catch-all accepts every guess silently, which:
- Makes your domain a soft target for dictionary/guessing attacks, since nothing ever bounces to tell them they got it wrong.
- Fills the catch-all destination with far more junk than a normal mailbox, unless it is filtered separately.
- Hides genuinely important mail (a real customer who mistyped an address) inside a much larger volume of noise, which is easy to miss.
A catch-all is far more useful once it is paired with rules that look at the original recipient address (the header the mail was actually sent to, sometimes called the "envelope-to") and route accordingly:
- Known aliases (sales@, info@, a former employee's address) route to the current owner.
- Addresses matching a known pattern (order-*, ticket-*) route to the relevant system or team.
- Everything else — the genuine unknown guesses — lands in a single monitored "catch-all overflow" mailbox that someone checks periodically, rather than mixing with mail people actually expect.
This turns catch-all from "deliver everything to one inbox and hope" into a safety net that still routes known mail correctly and isolates the noise.
If you can, maintain a real list of addresses that should exist and bounce everything else — this is the standard advice from most mail security guidance, because it removes the address-guessing incentive entirely. Where that is not practical (a legacy domain with genuinely unknown historical addresses, for example), keep the catch-all but:
- Route it through spam filtering at least as strict as your normal mailboxes, not less.
- Send catch-all overflow to its own mailbox, not directly into a person's primary inbox.
- Review the overflow mailbox on a schedule rather than never — that is usually where a real customer's typo turns up.
Hexamail Server and Hexamail POP3 Downloader both support catch-all collection with rule-based redistribution by recipient header, subject, or sender, so a wildcard address can still route known mail correctly while isolating genuine overflow into its own mailbox. Hexamail Guard applies the same spam filtering to catch-all traffic as to named addresses, rather than treating it as a lower-priority stream.