Catch-All Email Addresses: Setup, Routing and When to Avoid Them

Guides › Catch-All Email Addresses: Setup, Routing and When to Avoid Them · 3 min read 6 sections
1

What a catch-all address is (and isn't)

A catch-all (or wildcard) address accepts mail sent to any address at your domain, including ones that were never deliberately created — a typo, an address made up years ago on a business card, or one nobody remembers setting up. Instead of bouncing unrecognised addresses, everything lands somewhere.

It is not a routing feature by itself. On its own, a catch-all is just "do not bounce, deliver everything to this one mailbox" — which is exactly why it needs a routing rule sitting behind it to be useful rather than a mess.

2

Why teams turn catch-all on

Common, legitimate reasons:

  • An old business or domain has years of addresses handed out informally (info@, sales@, a founder's first-name address) and nobody has a full list of what is actually in use.
  • A website or webstore auto-generates addresses (order-1234@, ticket-5678@) and every one of them needs to arrive somewhere without pre-creating a mailbox for each.
  • Migrating domains and wanting a safety net so nothing addressed to the old naming scheme silently bounces during the transition.
3

The cost: catch-all is a spam magnet

Spammers routinely guess addresses at a domain to find live ones. A domain with no catch-all bounces the guesses, which tells the sender the address does not exist and, over time, makes your domain a less attractive target for that kind of scanning. A domain with an open catch-all accepts every guess silently, which:

  • Makes your domain a soft target for dictionary/guessing attacks, since nothing ever bounces to tell them they got it wrong.
  • Fills the catch-all destination with far more junk than a normal mailbox, unless it is filtered separately.
  • Hides genuinely important mail (a real customer who mistyped an address) inside a much larger volume of noise, which is easy to miss.
4

Routing catch-all mail to the right person automatically

A catch-all is far more useful once it is paired with rules that look at the original recipient address (the header the mail was actually sent to, sometimes called the "envelope-to") and route accordingly:

  • Known aliases (sales@, info@, a former employee's address) route to the current owner.
  • Addresses matching a known pattern (order-*, ticket-*) route to the relevant system or team.
  • Everything else — the genuine unknown guesses — lands in a single monitored "catch-all overflow" mailbox that someone checks periodically, rather than mixing with mail people actually expect.

This turns catch-all from "deliver everything to one inbox and hope" into a safety net that still routes known mail correctly and isolates the noise.

5

A safer alternative: specific addresses plus one monitored catch-all

If you can, maintain a real list of addresses that should exist and bounce everything else — this is the standard advice from most mail security guidance, because it removes the address-guessing incentive entirely. Where that is not practical (a legacy domain with genuinely unknown historical addresses, for example), keep the catch-all but:

  • Route it through spam filtering at least as strict as your normal mailboxes, not less.
  • Send catch-all overflow to its own mailbox, not directly into a person's primary inbox.
  • Review the overflow mailbox on a schedule rather than never — that is usually where a real customer's typo turns up.
6

How Hexamail Can Help

Hexamail Server and Hexamail POP3 Downloader both support catch-all collection with rule-based redistribution by recipient header, subject, or sender, so a wildcard address can still route known mail correctly while isolating genuine overflow into its own mailbox. Hexamail Guard applies the same spam filtering to catch-all traffic as to named addresses, rather than treating it as a lower-priority stream.