A catch-all email account in cPanel forwards to a designated mailbox every message sent to any non-existent address on your domain. That way, even if someone misspells your address, the email still reaches you.
What Is a Catch-All and When Should You Use One?
Suppose your official address is [email protected] but a client types [email protected] by mistake. Without a catch-all, that message bounces. With one, it lands in your inbox.
A catch-all makes sense when:
- Your domain appears on printed materials and typos are likely.
- You use many temporary aliases (e.g.,
[email protected]) without creating a dedicated account for each. - You're migrating email and need to guarantee no old messages are lost during the transition.
- You haven't yet defined all your company's permanent accounts.
It also comes with trade-offs — mainly spam — which we'll cover below so you can decide whether enabling it is the right call for your situation.
Step-by-Step: Enabling Catch-All in cPanel
1. Log In to cPanel
Open your browser and go to https://yourdomain.com:2083 (or the login URL your host provided). Enter your cPanel username and password.
2. Open "Default Email Address"
On the main dashboard, find the Email section and click Default Email Address. This is where cPanel controls what happens to mail sent to non-existent addresses.
3. Choose What to Do with Undeliverable Messages
You'll see several options:
| Option | What it does | When to use it |
|---|---|---|
| Discard (send error to sender) | Returns a bounce to the sender | When you do NOT want catch-all |
| Forward to an email address | Delivers all undeliverable mail to a specific mailbox | Classic catch-all |
| Forward to the system | Server handles it (usually returns a technical bounce) | Rarely useful |
| Pipe to a program | Passes email to a server-side script | Advanced integrations |
4. Select "Forward to an Email Address"
Choose that option and enter the destination address — for example [email protected], or a dedicated account you created specifically to catch these messages, such as [email protected].
Click Change (or Save). The change takes effect immediately — no service restart needed.
5. Verify It Works
From an external account (Gmail, Outlook), send an email to an address you know doesn't exist on your domain, such as [email protected]. Within a few seconds it should appear in the mailbox you configured.
Risks of Catch-All and How to Mitigate Them
Enabling catch-all has one significant downside: spam. Spammers scan domains by sending emails to thousands of name combinations. Without catch-all, those emails bounce and senders learn the addresses don't exist. With catch-all, everything lands in your mailbox.
To reduce the noise:
- Enable SpamAssassin on the destination account. In cPanel, go to Spam Filters and turn it on with a score threshold of 5 or lower.
- Create an email filter that automatically moves high-scoring SpamAssassin messages to a Spam folder.
- Review the catch-all mailbox periodically — don't use it as your primary inbox.
- Consider disabling the catch-all later once all your real accounts are set up and there's no longer a risk of losing messages.
If spam becomes unmanageable, an alternative is to set the catch-all to silently discard instead of forwarding — spammers don't get a bounce (so they can't confirm your domain is active), and your inbox stays clean.
Catch-All vs. Aliases vs. Forwarders
These three cPanel features are easy to mix up:
- Catch-all account: captures everything arriving at non-existent addresses on the domain. It's a generic wildcard.
- Email alias: a named alias that routes to a specific account (e.g.,
[email protected]→[email protected]). Only works for explicitly defined addresses. - Forwarder: similar to an alias, but can also route copies to external addresses outside your domain.
The catch-all is the "last resort" — it fires only when no alias, forwarder, or real account matches the recipient address.
Want to dive deeper into your business email setup? Browse more guides on the business email section of our blog.
Key Takeaways
- Catch-all is configured under Default Email Address in cPanel and takes effect immediately — no restart required.
- Select "Forward to an email address" and specify the mailbox where undeliverable messages should land.
- The biggest risk is spam: enable SpamAssassin and create filters on the destination account.
- Don't confuse catch-all with aliases or forwarders — catch-all only activates when no other rule matches.
- Review whether you still need catch-all periodically; disabling it when it's no longer necessary cuts down on spam.
Looking for hosting with cPanel, professional email, and expert support? elenlace.com has plans that include business email addresses, SSL certificates, and Spanish-speaking technical support — everything your company needs to get started.
FAQ
Does catch-all affect mail server performance?
On shared hosting with SpamAssassin active, a domain that attracts heavy spam can fill the catch-all mailbox quickly. In practice, if your domain isn't well-known to spammers the impact is minimal. If you start receiving hundreds of spam messages a day, consider disabling catch-all or switching it to silent discard.
Can I enable catch-all on just one domain when I have several in cPanel?
Yes. The default email address setting is per domain. You can enable it on one domain and leave it off on others — just select the correct domain from the dropdown menu at the top of the Default Email Address page before saving.
Does catch-all work with Google Workspace or Microsoft 365?
Not through cPanel, because in those services email routing is handled by Google's or Microsoft's servers, not your hosting server. Both platforms have their own catch-all equivalent — called "default routing" or "catch-all recipient" — which you configure inside their respective admin consoles.
Can I forward catch-all messages to multiple people?
cPanel only accepts a single destination address in the Default Email Address field. The workaround is to first create a mailing list (email list) in cPanel with all the recipients who need to receive those messages, then point the catch-all at that list address.
Prefer it done for you? El Enlace handles hosting and professional web development.
Useful resources
Other providers and guides worth comparing: