Enabling catch-all feels like insurance: every local part under the domain lands somewhere. In practice bots and dictionary probes use the same door. An open catch-all domain pulls garbage addressed to inventable mailboxes into your own inbox and becomes a spam factory you operate yourself.
Even with MX at securemail.eurovdc.eu (priority 10), accepting unknown RCPT addresses advertises “someone is home.” SPF v=spf1 mx ip4:45.84.90.12 -all constrains your outbound path; inbound dictionary spam still fills the catch-all target. Zones on ns1.eurovdc.eu / ns2.eurovdc.eu are managed correctly in DNS — catch-all remains a mail-policy choice.
What catch-all accepts
Everything not already a mailbox or alias is rewritten to one goto destination. Real accounts keep their paths; the leftover bucket grows quota, spam folders, and false positives. Setup and risk matrix: email aliases, forwarding and catch-all.
How you generate “your own” spam
- Dictionary and typo probes (infoo, sales1, random hex) are accepted — no RCPT reject.
- Backscatter risk rises when forged From traffic triggers bounces from your side.
- Staff invent ad-hoc addresses that “just work,” inventory drifts, audits fail.
- Filter thresholds climb; real business mail drowns in the same mailbox.
When a temporary open is justified
Short domain migration, a time-boxed campaign, or a documented rule. Set an end date, use a monitored destination, watch daily volume, then disable. For routine corporate use create explicit aliases or mailboxes: create and manage email accounts.
Practical alternatives
- Map roles (
info@,billing@,support@) as aliases or mailboxes. - Forward former-employee addresses one by one — do not lean on catch-all.
- A few brand typo aliases beat an open domain.
- If you forward externally, monitor the target quota and spam folder separately.
EU-hosted mailboxes in Sofia: corporate email. Keep catch-all off while MX/SPF stay aligned as above.
FAQ
What happens to mail to unknown addresses when catch-all is off?
The server rejects with a 5xx user-unknown. The sender sees it immediately; your mailbox stays clean.
Is catch-all a fix when alias quota is exhausted?
No. Clean unused aliases or raise capacity. Catch-all is not a quota workaround.
Does catch-all break SPF/DKIM?
It does not rewrite your outbound auth. Damage comes from inbound volume, bounces, and mailbox pollution.
After a migration ends?
Disable catch-all, list remaining real addresses, and confirm a random local part is rejected.
Safe to catch-all-forward to a free Gmail?
Volume and spam pile into that account’s filters. A dedicated corporate mailbox with catch-all off is usually cleaner.