The short version

  • A catch-all email alias turns your whole domain into alias space — any address at it (anything@yourdomain) works instantly, with no need to create each one first.
  • You switch it on per domain in EmailAlias (Premium, on a verified custom domain): pick the inbox to forward to, flip the toggle, and every address starts auto-creating a real alias on its first email.
  • The usual downside of a catch-all is spam — EmailAlias tames it with per-alias kill switches, a one-click “Disable all,” and built-in rate limits, so you get the convenience without the flood.

A catch-all email alias is the simplest way to get an endless supply of addresses on your own domain without creating a single one in advance — you just invent an address on the spot and it works. In EmailAlias this is a per-domain toggle on any verified custom domain, and the moment it’s on, anything@yourdomain quietly becomes a working alias that forwards to you. This guide shows exactly how to set up a catch-all email alias, what happens when mail arrives, and — honestly — how to keep the one real downside, spam, firmly under control.

What a Catch-All Email Alias Is

Normally an email alias is an address you create one at a time: you make shopping@yourdomain, hand it out, and mail to it forwards to your real inbox. A catch-all email alias flips that around. Instead of registering each address first, you tell your domain to accept every address and forward it — so anything@yourdomain reaches you, whether or not you ever set it up. The domain “catches all” the mail.

That means you can invent an address in the moment — at a checkout, on a form, over the phone — and it simply works. We won’t re-explain the mechanics in depth here; our guide to what a catch-all email address is covers the full definition and the email forwarding underneath. This guide is about using one in EmailAlias: turning it on, what you get, and how to keep it tidy.

How to Set Up a Catch-All Email Alias

Setting up a catch-all email alias in EmailAlias takes a verified custom domain and a Premium plan. Once those are in place, it’s a single toggle. Here’s the whole flow:

  1. Add and verify your domain. In the dashboard, open Custom Domains and add your domain, then publish the DNS records it gives you (ownership, MX, SPF, DKIM, DMARC). When every check passes, the domain shows as verified — catch-all only appears for verified domains.
  2. Open the domain’s card. Each verified domain has a Catch-all section with a toggle and a “Forward catch-all mail to” picker.
  3. Choose the destination. Pick the inbox that should receive the caught mail. It must be your account’s primary email or a forwarding destination you’ve already verified — you can’t point a catch-all at an address you don’t control.
  4. Flip the toggle on. That’s it. From this moment, any address at the domain forwards to your chosen inbox.

There’s nothing to configure per address and no wildcard record to hand-edit at your registrar — EmailAlias already receives your domain’s mail through the MX record you set during verification, so turning catch-all on is purely a setting on our side. If you ever want to stop, the same toggle switches it back off.

catch-all email alias: one glowing domain funnelling many envelopes into a single inbox
With catch-all on, every address at your domain funnels into the one inbox you chose — no need to create each alias first.

What Happens When Mail Arrives

With catch-all on, the magic happens the first time a brand-new address receives a message. Say you gave a shop acme-shop@yourdomain that you never created. When their first email lands, EmailAlias does three things automatically:

  • Creates a real alias for that address. The address becomes a normal alias in your account, marked as auto-created so you can tell it apart from ones you made by hand.
  • Forwards the message to the destination you picked, exactly like any other alias.
  • Lists it in your dashboard, where it now behaves like every other alias — you can label it, re-route it, or switch it off.

So a catch-all doesn’t dump mail into a mysterious bucket; it mints a proper alias on demand. The domain card even shows a running count of how many aliases catch-all has auto-created, so you always know how much it has generated. Addresses that have already been auto-created simply keep forwarding — the auto-create step only happens the first time each new address is seen.

The part that varies from message to message is the bit before the @ — the local part of the email address. A catch-all accepts any local part at all: a tidy one like newsletter@, a random one like x7f2@, or a company name you coined at a checkout. Each distinct local part becomes its own alias the first time it’s used, which is exactly why you can invent them freely and still end up with a clean, per-address list afterwards rather than one undifferentiated pile of mail.

Why Use a Catch-All Email Alias

The appeal of a catch-all email alias is pure convenience — you never have to stop and create an address before you need it. That unlocks a few everyday wins:

  • Hand out addresses anywhere, instantly. At a till, on a paper form, or reading one aloud over the phone, you can give store-name@yourdomain on the spot and know it’ll reach you — no app, no setup.
  • Never miss mail from a typo or a guess. If a sender slightly mistypes your address, or writes to hello@ or info@ that you never set up, it still arrives instead of bouncing.
  • Keep the one-address-per-company habit effortlessly. Give every service its own address without the friction of creating each one, so you still know exactly who leaked or sold your address if spam starts.
  • Catch anything sent to your domain. Old addresses, role addresses, forgotten sign-ups — a catch-all sweeps them all to one place.

In other words, a catch-all gives you the private, per-service address habit with none of the up-front effort. It’s the difference between planning every alias and simply making them up as life throws sign-ups at you — the domain does the remembering.

Keeping Your Catch-All Under Control

Here’s the honest part. A plain catch-all has one real weakness: because it accepts every address, spammers who run directory-harvest attacks — blasting a@, admin@, sales@, and thousands of guesses at a domain — will all land in your inbox, and a raw catch-all gives you no per-address off switch. That’s why our explainer calls an unmanaged catch-all a bit of a spam magnet. EmailAlias is built to give you the convenience without that pain, in a few ways:

  • Every caught address is a real, individual alias. Because each auto-created address is a normal alias, you get a per-address kill switch a raw catch-all never has — disable one noisy alias and the rest keep working.
  • One-click “Disable all.” If a flood does start, the domain card has a Disable all button that switches off every auto-created alias at once. Forwarding stops immediately, nothing is deleted, and any aliases you made by hand are left untouched — so you can re-enable the ones you actually want.
  • Built-in rate limits. EmailAlias caps how many new addresses a catch-all will auto-create per hour, per day, and per domain. A dictionary attack can’t spin up an unlimited pile of aliases, and if the safeguard can’t run for any reason, catch-all fails closed and simply stops auto-creating rather than opening the floodgates.
  • Spam filtering still applies. Caught mail goes through the same alias spam protection as everything else, so obvious junk is handled before it reaches you.
  • Turn it off anytime. Flip the toggle off and no new addresses are auto-created. Addresses already created keep forwarding until you disable them — use “Disable all” if you want to stop those too.

This is what we mean by a catch-all done right: the convenience of accepting everything, paired with the per-alias control and guardrails that a bare catch-all lacks. You decide how open the door is, and you can close it — fully or selectively — in one click.

Catch-All vs One Alias Per Service

A catch-all isn’t the only way to work, and it isn’t always the right one. Here’s how a catch-all email alias compares with deliberately creating one alias per service.

Catch-all versus creating one alias per service, compared on effort, control, and spam exposure
ApproachSetup effortAddresses availableSpam exposureBest for
Catch-all email aliasOne toggle, then noneUnlimited, on demandHigher (accepts every address)Giving out addresses on the fly
One alias per service (manual)Create each oneOnly the ones you madeLower (unknown addresses bounce)Deliberate, tightly controlled use
Both togetherToggle + a few by handUnlimited, plus named favouritesManaged with the controls aboveMost people

The two approaches aren’t rivals — they layer. Many people keep a catch-all on for convenience and create a handful of named aliases by hand for their most important accounts. If you’d rather lock things down tightly, leaving catch-all off and making each alias deliberately means any address you didn’t create simply won’t exist — the strictest setting. EmailAlias lets you run either way, or mix them, on the same domain.

Limits and Plan

A few practical things to know before you switch it on:

  • It’s a Premium feature. Catch-all, like custom domains, is part of Premium ($4/month). The free plan includes 10 aliases you create yourself; catch-all and your own domain come with the upgrade.
  • Custom, verified domains only. Catch-all works on a domain you own and have verified — not on the shared alias domains everyone uses. That’s why it needs the domain-verification step first.
  • The destination must be yours. You can only forward caught mail to your primary email or a forwarding destination you’ve already verified, so nobody can aim your domain’s mail somewhere they don’t control.
  • Auto-creation is rate-limited. The per-hour, per-day, and per-domain caps described above protect you (and the service) from a flood; normal use never comes close to them.

Tips for Running a Catch-All

To get the convenience without the clutter:

  • Use a consistent naming pattern. Give addresses like company-name@yourdomain so that months later you can tell at a glance who each caught alias was for.
  • Label the ones that matter. When an auto-created alias turns out to be important, add a label so it stops looking anonymous in your list.
  • Prune occasionally. Glance at the auto-created count on the domain card now and then; if it’s ballooned from spam guesses, “Disable all” and re-enable only the aliases you recognise.
  • Pair it with a named alias for critical accounts. For your bank or main logins, create a deliberate alias by hand so it never depends on the catch-all staying on.
  • Keep the real inbox private. The whole point is that senders only ever see an address at your domain, never the inbox behind it — the same principle as ordinary private email forwarding, applied to your entire domain.

Final Thoughts

A catch-all email alias is the most convenient way to use your own domain for privacy: switch it on once and every address you can imagine already works, ready to hand out the instant you need it. The classic objection — that catching everything invites spam — is real, but it’s a tooling problem, and it’s the part EmailAlias is built to solve. Because every caught address becomes a normal alias, you keep a kill switch for each one, a one-click way to shut them all off, and rate limits that stop a flood before it starts. Turn it on, hand out addresses freely, and if any of them ever turns noisy, close that door and leave the rest open. That’s a catch-all worth running.

Frequently Asked Questions

How do I set up a catch-all email alias in EmailAlias?

Add your domain under Custom Domains and verify it by publishing the DNS records EmailAlias gives you (ownership, MX, SPF, DKIM, DMARC). Once the domain shows as verified, open its card, find the Catch-all section, choose the inbox to forward caught mail to (your primary email or a verified forwarding destination), and flip the toggle on. From that moment every address at the domain forwards to you. There’s no per-address setup and no wildcard record to edit at your registrar — it’s a single switch on EmailAlias’s side, and the same switch turns it off.

What is a catch-all email alias?

It’s a setting that makes every address at your domain work automatically, instead of you creating each alias in advance. With it on, anything@yourdomain forwards to your inbox — so you can invent an address on the spot and it just works. In EmailAlias, the first email to any new address turns it into a real, normal alias in your account (marked as auto-created) and forwards the message. Our separate explainer covers the underlying mechanics in depth; this feature guide is about turning one on and using it.

Does a catch-all email alias get more spam?

It can, because a catch-all accepts every address, so spammers guessing addresses at your domain all reach you — a raw catch-all has no per-address off switch. EmailAlias is built to tame this: each caught address becomes an individual alias you can disable, a one-click “Disable all” switches off every auto-created alias at once without deleting them, caught mail still passes through spam filtering, and rate limits cap how many new addresses can be auto-created per hour, day, and domain. If the safeguard can’t run, catch-all fails closed and stops auto-creating rather than flooding you.

Do I need a custom domain for catch-all?

Yes. Catch-all works on a custom domain that you own and have verified in EmailAlias — not on the shared alias domains available to everyone. That’s why setup starts with adding your domain and publishing its DNS records; once it’s verified, the Catch-all toggle appears on the domain’s card. Both custom domains and catch-all are part of Premium ($4/month). If you don’t have a domain yet, you can still create up to 10 aliases by hand on the free plan.

What happens to aliases a catch-all already created if I turn it off?

Turning catch-all off stops NEW addresses from being auto-created and clears the forwarding destination, but any aliases it already created keep forwarding as normal — switching off the catch-all doesn’t retroactively disable them. If you want those to stop too, use the “Disable all” button on the domain card, which switches off every auto-created alias at once (forwarding stops, nothing is deleted, and aliases you made by hand are left alone). You can re-enable individual ones whenever you like.

Can I still create aliases by hand with catch-all on?

Yes, and it’s a good idea for important accounts. Catch-all and manually created aliases live side by side on the same domain: the catch-all handles addresses you make up on the fly, while a hand-made alias for your bank or main logins stays under your deliberate control and doesn’t depend on the catch-all being on. The “Disable all” bulk action only affects auto-created aliases, so your hand-made ones are never touched by it.

Where do caught messages go?

To the single destination you choose when you turn catch-all on — either your account’s primary email or a forwarding destination you’ve already verified. You can’t point a catch-all at an address you don’t control, which stops anyone from aiming your domain’s mail somewhere it shouldn’t go. Each caught address becomes its own alias, so later you can re-route an individual one to a different verified inbox if you want finer control over where specific mail lands.

Can I set catch-all through the API?

Yes. Catch-all is exposed on the EmailAlias API at PATCH /api/domains/{id}/catch-all, and the official client libraries wrap it (for example setCatchAll in the Node SDK, with equivalents in the Python, PHP, and MCP packages). There’s also an endpoint to bulk-disable the aliases a catch-all created. That means you can enable, disable, and clean up catch-all programmatically from your own scripts or tools, the same way you manage aliases and domains through the API.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.