Catch-all & Routing

Catch-all email for agencies managing many client domains

One noisy client is not a reason to forward unknowns on every zone you operate.

MailerZ editorial · Secuno LLC16 min read

Catch-all email for agencies managing many client domains should be a per-zone policy, not a house default. Hold unknowns on everyday production. Print named roles the client will still pay for next year. Use paid catch-all forward only while you cut leftover MX. Agency pricing buys capacity. It does not make harvested names safe.

Catch all agency email: per-domain hold versus house-wide forward
Capacity is not a reason to ingest every guessed local-part.

Quick answer for catch all agency email

Catch all agency email is not “accept everything on every client.” It is a written rule: named aliases for printed roles, unknowns held, forward only during a dated migration, leftover MX treated as a stop. The client still reads Gmail or Outlook. You still do not host IMAP.

A guide that tells agencies to enable catch-all so they never miss a lead is selling a flood. Leads arrive at hello@ and sales@ when those names exist. Harvest arrives at every other string. Hold lets you promote a real leftover. Forward trains scrapers that the domain answers the phone.

Agency plan capacity — more domains, more aliases, more seats — exists so each client can have a short public list. It is not a license to skip the list. If a client wants forty public names, write them. If they want infinity, they want hold plus a conversation, not a wildcard culture.

You will still hit leftover registrar or suite MX on client zones. That is the first ticket. Catch-all cannot review mail that Google still accepted. Cut, probe from another mailbox, then talk about unknowns.

MailerZ Free is one domain, three aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.

catch all agency email guide: the real decision

Agencies inherit hosts that already accepted everything. The client believes catch-all is “how email works.” Your job is to replace that belief with a list and a hold queue, not to recreate the flood on a new vendor.

Junior operators copy one Cloudflare or registrar pattern across the book of business. One client’s migration window becomes everyone’s forever forward. That is how agency inboxes die.

Billing fights start when a client thinks unlimited aliases means unlimited catch-all. Explain the difference before the invoice. Named aliases are inventory. Catch-all is policy.

Criteria: who owns each client zone, where leftover MX still lives, which names are printed, who reviews hold, and whether any role must send as the domain. If send-as is required, Free is the wrong plan for that zone.

Agency catch-all decisions per client zone
Client situationPolicyPlan note
New brochure site, three printed rolesNamed + holdFree can lab; paid if send-as
Cutover from a host that accepted allPaid forward, two weeks, then holdWatch the store daily
Client demands every spellingHold + educationDo not encode panic in MX
Forty client domains, no listStop onboardingAgency capacity will not save you

Prove the hop on one domain before you print a new address on a invoice or a form.

Start free — one domain

Technical mail flow for catch all agency email

Each client domain is its own MX decision. Senders look up that zone, not your agency domain. You publish MailerZ MX on the client zone after verification. Aliases map to destinations the client already reads — often the agency shared inbox during build, then the client later.

Unknowns follow that zone’s policy. Mixing destinations across clients is a tenant mistake. Do not forward client A leftovers into client B’s Gmail.

SRS and Header From behave as on any other domain. Do not rewrite From to “look professional.” Authentication will fail.

Send-as is per approved identity. A contractor should not use one SMTP password across every client. Revoke when the contract ends.

Transport still follows IETF RFC 5321 — Simple Mail Transfer Protocol. Envelope commands are not the header block people see. MailerZ may rewrite only the envelope return path with Sender Rewriting Scheme. MailerZ is a product of Secuno LLC. It is inbound MX plus authenticated SMTP. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. It is not Google Workspace, not IMAP, not webmail, and not an open relay. Unhosted or unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Probe from another mailbox. MailerZ is not SOC 2, not ISO 27001, and not HIPAA.

Client domain MX cut with named aliases and a hold queue
Each zone gets a list. The spreadsheet is the product.

catch all agency email setup: step-by-step setup

Onboard with a lab domain first. Then repeat the same steps on the client zone with their leftover MX in the ticket from minute one.

  1. Collect the printed address list and a screenshot of current MX. Save the old set before you delete anything.
  2. Add and verify the client domain. Recreate named aliases. Map destinations you can defend in writing.
  3. Publish MailerZ MX. Delete leftover hosts. Confirm public lookup. Probe from another mailbox.
  4. Leave unknowns held unless you are in a written cutover window.
  5. If cutover, enable paid forward with an end date. Review daily. Promote leftovers to names.
  6. Disable forward. Hand the destination to the client if they now own the inbox.
  7. Attach send-as only on paid plans when the client must reply as the domain.
  8. Record leftover MX, alias list, and credential owners in the same runbook you use for DNS.

Client clicks for Gmail live in Google Gmail Help — Send mail from a different address. Outlook uses a manual SMTP identity when you also send as the domain. Incoming mail stays at the destination mailbox.

Failure modes and proof

House-wide forward because one client complained. Revert. Fix that zone’s list.

Mail still at Google: leftover MX. Catch-all will not see it.

Shared SMTP across clients. A leak becomes a multi-tenant incident. Separate credentials.

Field notes you can reuse

Worked example: forty brochure sites

An agency inherits forty domains with registrar forwarding and a host that accepted everything. The account lead wants catch-all on all forty “so we do not miss leads.” That is how the agency inbox dies. Catch all agency email setup is a factory: printed names, one MX set, hold, leftover cut, probe. Repeat. Forward is a dated exception on the few zones still mid-cutover.

Price the factory in the SOW. If catch-all is not written, the client will hear infinity. Named aliases are inventory. Catch-all is policy. Agency plan ceilings let you hold 100 domains and 500 aliases on the published Agency card. Confirm pricing. Those numbers are not a wildcard culture.

Offboard is part of security. When a client leaves, remove MX you own, revoke SMTP, stop forwarding leftovers into the agency Gmail. Keeping their harvest because someone forgot DNS is how you read another company’s spam for a year.

Who may click DNS

If the client owns Cloudflare and you own the registrar, write who edits NS and who edits MX. Dual control without a map is how leftovers return. Authoritative nameservers win. The pretty registrar panel may be a copy.

Save the old MX set before every delete. Agencies skip this and then cannot roll back a bad Friday. The migration planner exists for that screenshot habit.

Do not promise SOC 2 because a procurement form has a checkbox. Send /security. Do not invent ISO. Do not promise inbox placement. Catch all agency email best practice includes saying no.

Send-as across the book

Separate SMTP credentials per client. A contractor who can send as every hello@ is an incident waiting for a laptop in a cafe. Free client zones cannot send-as. Do not point their WordPress at MailerZ SMTP until they pay.

Lab the pattern on a domain you can break. Then touch the first paying zone. Teaching junior staff on a live dental office is how you buy flowers.

Operator brief

A longer operator brief for catch all agency email

Teams that bookmark Catch-All Email for Agencies Managing Many Client Domains usually arrive after a missed invoice, a form that never notified anyone, or a migration that looked clean in one resolver. The useful brief is still boring. Name the store. Name the printed local-parts. Name the nameservers that actually answer. Publish one MailerZ MX set. Delete leftover hosts. Probe from a mailbox that is not the destination. Only then talk about catch all agency email as a send-as, catch-all, or comparison problem.

MailerZ remains inbound MX plus authenticated SMTP around Gmail or Outlook. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. It is not a hosted mailbox, not IMAP, not webmail, and not an open relay. Unauthorized send is 550 / 550 5.7.1. Free cannot finish send-as: SMTP and API stay off. Solo is $40 per year when the domain From must travel. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm the live pricing page. Those numbers are ceilings, not an inbox-placement service-level agreement.

If leftover Google, Microsoft, Cloudflare routing, or registrar MX is still public, stop widening catch all agency email. The map you built never saw that copy. Priority numbers are an order, not load balancing. A higher preference host is idle while a leftover host still accepts mail. Save the old MX set before you delete anything. Check more than one public view because TTL lies.

Catch-all forward is not a safety feature for catch all email for agencies managing many client domains. Hold unknowns on everyday production. Review the store. Promote a leftover only when a real person used it. Paid forward belongs to a dated cutover. Fan-out of unknowns into two inboxes trains two spam buttons. Plus addressing on Gmail is not a custom-domain unknown policy. MailerZ will not strip plus tags on your domain the way Gmail does on @gmail.com.

Send-as is a second hop. Creating an inbound alias does not approve outbound. Catch-all does not mint a From. Copy the dashboard host, port, and TLS pair together. Set From to an identity you created. Do not paste a Gmail password into a CMS, a cron file, or a ticket. Do not mail SMTP secrets to support. Send a 550 line, a timestamp, and a Message-ID. Rotate if a secret already leaked.

Self-send from Gmail to the same Gmail account can short-circuit. That green result is why people swear catch all agency email works while customers vanish. Use a second provider. Put a unique subject on the probe so delivery history is searchable. If Header From was rewritten by some other forwarder, authentication stories get noisier. MailerZ does not rewrite Header From on inbound.

Agencies should keep catch all agency email per client zone. Separate SMTP credentials. Do not pour every client into one catch-all because the spreadsheet got long. Agency plan capacity exists so you can hold more domains and aliases. It does not replace a named list. Offboard means delete MX you own, revoke SMTP, and stop forwarding leftovers into the agency inbox.

Legal and security questions have published answers on the security, privacy, terms, DPA, and subprocessors pages. MailerZ is not SOC 2, not ISO 27001, and not HIPAA. The 14-day Free store, the 90-day Solo–Agency store, and the 180-day Unlimited store are recovery windows for hops this layer saw. They are not an archive and not legal hold. If counsel wants eDiscovery, buy eDiscovery.

Comparisons only help after the hop is honest. Cloudflare Email Routing is inbound routing. A privacy-mask product hides a destination on a provider domain. A suite hosts mailboxes, Calendar, and admin. Proton-class mailboxes encrypt a store. MailerZ is the delivery layer when you already have Gmail or Outlook and you need a domain route you can prove. Cite the other product’s documentation. Do not invent feature parity.

When Catch-All Email for Agencies Managing Many Client Domains is closed, the next physical action is a lookup and a probe, not another tab. Start free on one domain you can break. Sign in if the zone already lives here. Review quarterly, or sooner after a nameserver move, a plugin swap, or a staff departure. That is how catch all agency email stays a runbook instead of an incident.

A second worked pass for catch all agency email: write the last change on a sticky note before you open the dashboard. Nameserver move, leftover MX, new form plugin, contractor laptop, or a registrar forwarding toggle are the usual five. MailerZ history only shows hops that reached this layer. If the sticky note says leftover MX, you do not have a catch all agency email mystery. You have a split. Delete the leftover. Wait for TTL. Probe again.

A third worked pass: print the public list. If you cannot print it, you are not ready for production unknowns and you are not ready for a bigger alias ceiling. Unlimited aliases as marketing will not save a missing list. Three named aliases on Free are enough to stop printing a personal Gmail on a homepage. Grow the list when a real person used a leftover, not when a harvest guessed admin@.

How an agency desk actually runs catch-all

A working agency desk treats catch-all as a ticket type, not as a default DNS habit. The incoming request is usually “turn it on so we never miss a lead.” The outgoing answer is a printed list, a hold queue owner, a leftover MX screenshot, and a dated forward window only if the old host accepted everything. If the client will not name a reviewer, you do not enable forward. You keep named aliases and you keep hold. That is how you stay in business when forty zones share one operator.

Monday is leftover MX. Tuesday is named roles. Wednesday is a fake local-part probe that must not land in Gmail. Thursday is send-as only for clients who paid and who must reply as the domain. Friday is revoke credentials for anyone who left. None of those days is “enable catch-all on the whole book.” Agency at $39 or $390 buys capacity. Confirm pricing. Capacity is not a vacuum.

Write the policy in the SOW. If it is not written, the client hears infinity. Named aliases are inventory. Catch-all is policy. Offboard deletes MX you own and stops leftovers from arriving in the agency inbox. That paragraph is the difference between a desk and a spam sink.

Train account managers to open the store before they ping engineering. A long hold queue is often a missing list, not a broken product. Promote two real leftovers. Leave the harvest held. Repeat the same factory on the next zone. Lab it once on a domain you can break.

When a client demands every spelling of support, give them one printed address and a human. Do not encode panic in MX. When a host already accepted everything, use paid forward for a written two-week window, review daily, then return to hold. When leftover registrar MX is still live, catch-all policy is incomplete because some senders never arrive. Cut first. Then name. Then hold. That order is the whole agency product.

One noisy domain can wait. Forty quiet domains with named aliases is the book you want. Separate SMTP per client so a leaked form does not send as every hello@ you operate. Free client zones cannot send-as. Do not point their WordPress at MailerZ SMTP until they pay. Lab the pattern once. Then touch the first paying zone.

FAQ

What is the safest way to handle catch all agency email?
Per client domain: named aliases, unknowns held, leftover MX deleted, paid forward only during a dated cutover. Review the store. Do not enable house-wide forward.
Does this require a new mailbox?
No. Clients keep Gmail or Outlook. You may use a temporary agency destination during build, then remap.
Will it work with Gmail or Outlook?
Yes for inbound. Send-as needs a paid plan and a client identity. Free has no send-as.
What DNS records are involved?
Verification TXT, one MailerZ MX set on the client zone, leftover host removal, and sending authentication if they send as the domain.
What should I test before production?
External probe to each named alias, a fake local-part that should hold, and a public MX view. Save the old MX set before delete.

Key takeaways

  • Catch-all is per domain, not a house default.
  • Hold is the everyday agency policy.
  • Paid forward is a dated cutover tool.
  • Agency plan is capacity, not a vacuum.
  • Leftover MX is the first ticket.
  • Do not mix client destinations.
  • Separate SMTP credentials per client.
  • No SOC 2, no inbox SLA.

Conclusion and next action

Agencies stay sane by naming roles, holding unknowns, and cutting leftover MX one zone at a time. Catch-all forever is how you inherit a spam desk.

Next action: run the lab domain on Free, write the client SOW line for hold versus forward, then cut the first paying zone with a saved old MX set.

Start free on a domain you can break. Sign in when the book of business already lives here.

Per-domain policy

Start free on a lab domain, then apply the same cut to clients.

Prove hold, named aliases, and leftover MX on one zone before you touch a paying client.

Review quarterly, or sooner if provider behavior, pricing, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.