On this page
A catch-all is a default address that accepts mail for any local part at your domain, even addresses you never created. Forwarders copy incoming mail from one address to another destination. Both features are easy to turn on in cPanel, but a catch-all quickly becomes a spam magnet, and careless forwarding often fails SPF checks at Gmail and similar providers. The reliable path is a real mailbox first, a single forward only when you need it, and the catch-all left off.
Create the real mailbox first
If the address belongs to a person or a role, create that mailbox in cPanel before you add any forward. Open Roundcube and send a test message so you know delivery works on this server. Only after that should you decide whether a second copy needs to go somewhere else. Skipping the mailbox step is how an address like info@ becomes a black hole that also pushes junk toward an external inbox.
Add a forwarder only when you need one
In cPanel, open Forwarders and map one local address to one destination you control. Test with a message sent from outside your domain, not from the same domain. The receiving side often sees the forwarder’s IP in the Received headers and still checks SPF against the original envelope sender. Gmail in particular may file that mail as suspicious even when your server accepted it cleanly. You may think mail is down, while the copy on this server is fine and the external inbox simply rejected the forward.
Forwarding an entire catch-all to Gmail almost never works well. Gmail treats much of that traffic as forged under SPF, and the catch-all also gathers every misspelled spam probe aimed at your domain. You end up combining a junk magnet with a broken forward.
Turn the catch-all off
In cPanel, open Default Address and set it to bounce unknown local parts, or route them to a mailbox you actually read. Do not point the default address at Gmail. If you briefly needed unknown local parts during a migration, set a clear end date and remove the catch-all when the move is done. Plus-addressing such as [email protected] already gives you disposable tags on a normal mailbox without accepting every possible local part.
Keep the order simple: create the mailbox, test it, add one optional forward if you must, and leave the catch-all disabled. Reversing that order is how you spend a week arguing with Gmail about mail that was never theirs to accept. Do not put an autoresponder on a catch-all, and do not stack five forwards on unknown addresses. If a role must fan out to several people, use a real mailbox with a list manager rather than a catch-all plus multiple forwards. Plus-addressing stays on the same mailbox, so [email protected] is still sales@ and does not require a Default Address rule.
Tagged
Was this article helpful?
Be the first to rate this article.



