Email

Catch-All Addresses

A catch-all delivers mail sent to any address at your domain into one mailbox, even when the address does not exist, so a message to saels@ instead of sales@ still reaches somebody instead of bouncing.

It is a useful safety net and a genuinely bad default. This article covers exactly where the setting lives, what it does, and the reasons most domains are better off without one.

Where the Setting Lives

The catch-all is configured per domain, from any mailbox on that domain.

  1. Sign in to KPanel and click Email in the left sidebar.
  2. Click any mailbox on the domain you want to configure.
  3. Open the Deliverability tab.
  4. Scroll to the Catch-all address card.

The card carries a pill reading Enabled or Disabled, and describes itself as: "Deliver emails sent to any address at this domain to a single mailbox, even if the address does not exist."

Catch-all card on the Deliverability tab in KPanel

Changing the catch-all requires domain write permission on the account, which is a different permission from the one that governs mailboxes. If the control is locked for you, ask an Owner or Admin on the account.

Turning It On

  1. Choose a mailbox from the Select target mailbox... dropdown.
  2. Click Enable.

The card then shows Routing to: followed by the target address, and the pill changes to Enabled.

The target must be a mailbox on the same domain as the catch-all. You cannot point a catch-all at an address on another domain or at an external address: if you try, the panel refuses with "target must be a mailbox on this domain". If the dropdown is empty you will see "No mailboxes on this domain yet." and need to create one first.

There is one catch-all per domain. Enabling a new one replaces the previous target rather than adding a second.

Turning It Off

Click Disable on the same card. Mail to addresses that do not exist then bounces normally, and the sender is told the address is invalid, which is usually what you want.

Why Most Domains Should Not Have One

A catch-all makes every possible address at your domain valid. That has three consequences.

It attracts a great deal of junk. Spam operations generate address lists by guessing common local parts against a domain: info@, admin@, sales@, office@, and thousands of random strings. Without a catch-all all of those bounce and the domain gets marked as a poor target. With one, every single guess lands in your target mailbox. This is the single most common reason a mailbox fills up unexpectedly. See My Mailbox Is Full.

It hides mistakes instead of surfacing them. When somebody writes to a misspelled address and gets a bounce, they correct it and try again, and both of you learn about the typo. With a catch-all, the message lands quietly in a mailbox where nobody is expecting it, and the sender believes it went to the right person.

It makes address enumeration free. An attacker probing your domain learns nothing from a catch-all, because every address appears to exist. That sounds like a defence and is not: it means you also learn nothing about what is being probed, and you receive all of it.

Better Alternatives

Nearly every reason people want a catch-all is served better by something more specific.

What you actually wantUse this instead
Catch a handful of likely typos of a real addressAliases on the mailbox, one per variant
Route a departmental address to a personAn alias or a forwarder
Route a departmental address to several peopleA distribution group or a shared inbox
Give an old employee's address somewhere to landA forwarder to their replacement
Use a throwaway address per service you sign up toAliases, so you can delete the one that starts getting spam

Aliases in particular do almost everything people ask a catch-all for, without the downside: they land in the same inbox, they are free to create, and you can see and delete them individually. The alias list is on the Aliases tab of the mailbox.

When a Catch-All Genuinely Makes Sense

There are real cases:

  • You are migrating from another provider and do not yet know every address that was in use. Turn the catch-all on for a few weeks, watch what actually arrives, create proper mailboxes or aliases for the addresses that matter, then turn it off.
  • You have just taken over a domain and want to see what mail it receives before deciding how to structure it.
  • A single-person domain where one mailbox handles everything anyway and the junk volume is tolerable.

If you turn a catch-all on for a migration, put a reminder in your calendar to turn it off. Almost every over-full mailbox with a catch-all was switched on temporarily by somebody who intended to review it later.

Catch-All and Deliverability

A catch-all changes what your domain accepts, not what it sends. It has no effect on SPF, DKIM or DMARC, and it will not help or hurt whether your outgoing mail reaches inboxes.

It does have an indirect effect worth knowing: a mailbox filling with junk from a catch-all is a mailbox that will eventually hit its storage limit and start refusing all mail, including the legitimate messages you actually care about. That failure looks like a delivery problem and is really a housekeeping one.

Troubleshooting

Mail to a nonexistent address still bounces after I enabled the catch-all. Confirm the pill reads Enabled and check you are looking at the right domain: the catch-all is per domain, and an account with several domains needs one per domain. Also confirm the target mailbox is Active and under its storage limit.

The catch-all is on but mail is going to the wrong mailbox. A real mailbox, alias or forwarder on that exact address always wins over the catch-all. The catch-all only handles addresses that nothing else matches. Check the Mailboxes, Aliases and Forwarders lists for the address in question.

The Enable button does nothing and the target dropdown is empty. There are no mailboxes on that domain yet. Create one, then set the catch-all.

I am suddenly getting hundreds of junk messages a day. Check whether a catch-all is enabled. If it is, disable it, then create aliases for the handful of addresses that genuinely receive mail.

I cannot find the card. It is on the Deliverability tab of a mailbox, not on the domain page. If the mailbox is on a Kapsule-managed subdomain rather than your own domain, the Deliverability tab shows "Managed by Kapsule" instead and there is nothing to configure.

Related reading: Email Aliases, Email Forwarding, My Mailbox Is Full, and Why Are My Emails Going to Spam?.

Still need help?

Email us at support@kapsulehost.com or open a chat in KPanel.

Open KPanel
Catch-All Addresses