Troubleshooting & SMTP Codes

Email forwarding not working: 20 checks in the right order

Do not start at SPF. Empty history plus leftover MX is the usual miss.

MailerZ editorial · Secuno LLC18 min read

Email forwarding not working is usually leftover MX, a missing alias, HOLD on an unknown local-part, a self-send lie, or a destination reject you have not read. Order matters. Public MX and hop history beat inbox folklore. Run the twenty checks below in sequence. Stop when the class is named. Do not republish DNS between every guess.

Email forwarding not working: ordered checks beat random DNS edits
Start at nameservers and MX. End at the destination folder. Do not skip hops.

Quick answer for email forwarding not working

Most “not working” tickets die by check six if you refuse to skip. People start at SPF because it is fashionable. SPF does not receive mail. MX does.

RFC 5321 is the transport. Your checklist should sound like transport: who answers, which local-part, what the next hop said.

Empty MailerZ history plus leftover MX is the most expensive miss. The sender reached someone else. Your inbox stayed quiet. You will waste a day on DKIM if you skip public MX.

A 550 unknown recipient is success of a kind: the hop reached MailerZ and the map had no row. Add the alias or leave HOLD. Do not enable catch-all FORWARD to silence the 550.

A 250 plus missing UI is a destination search problem or a filter. Search all mail. Then junk. Then rules.

If you change three DNS records before classifying, you will not know which change “fixed” it. One class, one change.

Authoritative mail transport is defined in IETF RFC 5321 — Simple Mail Transfer Protocol. Product path: troubleshooting, delivery recovery, and docs.

User problem and decision criteria

The user wants mail now. Decision criteria: can you query two resolvers, can you open history, do you know the exact local-part, is the destination spelled correctly, was the test self-send.

Criteria that do not belong: adding a second MX, rewriting Header From, buying Workspace to debug, or an inboxing percentage.

Agencies should screenshot NS and MX before they touch anything. Rollback needs the old set.

If the store window aged out, say so and request a new probe. Guessing after fourteen days on Free creates mythology.

Shared inboxes hide mail in another person’s folder. Ask who owns the destination before you declare the domain down.

Portals that cannot follow forwards will keep failing after a perfect map. Name that limitation. Do not open the zone to please them.

If send-as is the actual complaint, you are on the wrong checklist. AUTH and Free-plan refuse are outbound. This list is inbound first.

If two people edit DNS, you will flap. One editor. Authoritative nameservers only.

Technical mail flow

Where forwarding breaks
Empty history means the message never hit this MX. A 550 is a different story.

Sender looks up MX. If two owners exist, your flow never starts for some senders.

MailerZ matches local-part. Miss plus HOLD stores. Miss plus reject returns 550. Miss plus FORWARD is a product choice on paid, not a debug tactic.

Forward hop uses SRS on the envelope. Header From stays. Destination answers 4xx, 5xx, or 250.

After 250 the destination files. That file is not MailerZ.

Tools on this site help you read MX and leftovers. They do not replace history.

Step-by-step setup / decision path

Twenty checks in order
NS, MX, alias, HOLD, probe, history, folder. Stop at the first true class.
  1. 1–2: Confirm the domain and the exact local-part in the ticket. Confirm who owns the destination inbox.
  2. 3–4: Lookup NS. Edit that panel only. Lookup MX from two resolvers.
  3. 5–6: Require exclusive MailerZ MX. Delete leftovers and unexpected null MX.
  4. 7–8: Confirm verification TXT. Confirm the alias exists and the destination spelling.
  5. 9–10: Confirm HOLD versus FORWARD. Confirm you are not on a stale cached map in your head—refresh the app.
  6. 11–12: Send a unique probe from a third mailbox. Refuse self-send as proof.
  7. 13–14: Open hop history. Copy code, host, and recipient. Classify 4xx vs 5xx vs 250.
  8. 15–16: If 250, search all mail and junk at the destination. Check rules and blocked senders.
  9. 17–18: If sending was the complaint, switch checklists: dashboard SMTP, plan caps, Free has no send-as.
  10. 19–20: Write the class in one sentence. Change one fact. Re-probe. Do not flap MX overnight.

Twenty checks is a sequence, not a score. Stopping at the first true class is the skill.

If two resolvers disagree, wait on TTL or fix the authoritative zone. Do not add records in the registrar if NS points elsewhere.

Print this order in the agency runbook. The unpaid weekend is almost always skipped leftover MX or self-send.

Failure modes and proof

Started at SPF: days lost. Proof: MX still dual.

Self-send: false fail or false pass. Proof: third mailbox differs.

Typo destination: Microsoft or Google 550. Proof: character compare.

HOLD expected, user wanted FORWARD: not an outage. Proof: plan and setting.

Empty history, leftover MX: mail at old host. Proof: public MX.

Null MX: reject all. Proof: 0 .

Aged-out store: no artifact. Proof: timestamps.

Shared folder: mail in another tab. Proof: destination search.

Portal cannot forward: sender limit. Proof: only that sender fails.

Outbound AUTH mixed in: wrong list. Proof: the error is SMTP client.

Dual MX added during debug: worse. Proof: new leftover.

Header rewrite demand: product boundary. MailerZ will not.

MailerZ workflow and product boundary

MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a campaign ESP.

Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Exclusive MX. Hold unknown on Free. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you send. Do not invent 587 or 465 as MailerZ facts.

Free: one domain, three aliases, one seat, fourteen-day store, fifty outgoing a month, no send-as. Solo forty dollars a year, fifteen aliases, ninety-day store, one hundred outgoing, five send-as per hour. Starter eight monthly or eighty yearly. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote the pricing page. No SOC 2, ISO, HIPAA, SLA, or inboxing percentage.

Delivery history and stored failures are why this order works. Without artifacts you will edit DNS from a feeling. Use troubleshooting and delivery recovery as the working set.

Cost, alternatives, and trade-offs

A twenty-minute ordered pass is cheaper than a weekend of TXT edits.

Workspace does not debug leftover MX.

A second forwarder during an outage is how you get two outages.

Agencies should sell this sequence as incident response, not as “we will try things.”

Catch-all FORWARD to “make it work” costs junk for months.

If you skip tools and guess, you pay in reputation at the destination.

Free store expiry is a cost: probe while the window is open.

Honest “HOLD is working as designed” saves a useless upgrade conversation—or names a real paid need.

How to keep the twenty checks honest

Print the twenty checks as a numbered card in the incident channel. The first person to jump to DKIM owes the channel a leftover-MX lookup. Social pressure is part of the runbook. Fashionable records waste hours.

Checks 1–4 are identity. Wrong domain, wrong local-part, wrong destination owner, wrong NS panel. Half of “not working” dies there. A client who says “the company email” may mean a Google Group you never mapped.

Checks 5–8 are publication. Two resolvers. Exclusive MX. No null MX if you meant to receive. Verification present. If the registrar zone is a ghost, you will “fix” records nobody publishes.

Checks 9–12 are product state. Alias exists. Destination spelling. HOLD versus FORWARD. App refreshed so you are not arguing with a stale tab. People debug yesterday’s map.

Checks 13–16 are evidence. Third-mailbox probe. History code. 4xx versus 5xx versus 250. Destination search including junk and rules. If you skip evidence you will flap MX.

Checks 17–20 are scope control. Outbound AUTH is another list. Write the class. One change. Re-probe. Overnight flaps are forbidden unless leftover MX is the class and the editor is named.

When two resolvers disagree, you are in TTL or split publication. Wait or fix the authoritative zone. Adding the old host “temporarily” is how you stay disagreed forever.

When history is empty and MX is exclusive, ask whether the sender actually sent and whether the time window is inside the store. Empty history is not automatically MailerZ guilt.

When history is 550 unknown, the domain works. The row is missing. Create the alias. Do not enable catch-all to hide a typo in the runbook.

When history is 250 and the user still sees nothing, you are in search, junk, rules, or a different account. Watch them search. Do not take “I checked” as a check.

Tools on this site help with MX and leftovers. They do not replace sitting on a screenshare for checks 15–16.

If you are an agency, time-box the twenty checks at thirty minutes. If you are still in SPF folklore at minute thirty, you skipped order.

Order is the product

Email forwarding not working is usually a skipped step, not twenty independent bugs. Use a fixed order and stop at the first fail. One: nameservers that actually publish the zone. Two: exclusive MailerZ MX, leftovers deleted. Three: the alias is named and mapped, or the unknown is held. Four: HOLD versus FORWARD policy matches what you think. Five: probe from a third mailbox with a unique subject — not Gmail to the same Gmail. Six: hop history for accepted then forwarded. Seven: destination folder including spam. Copy the SMTP reply before you change records. MailerZ stores hops in the retention window. Fourteen days on Free. Ninety on paid. Confirm /pricing. The store is not an archive.

Empty history after a “sent” plugin means hop one never ran or the local-part was unnamed or held. Asking recovery to fetch a leftover MX miss is asking for a log that does not exist. Print public MX from 8.8.8.8 and 1.1.1.1. If either shows Google, Microsoft, Cloudflare routing, or registrar forwarding, you are not in a dest-filter problem. Delete leftovers. Priority is order, not load balancing. Wait TTL. New subject. Then continue the list.

Null MX rejects all inbound. A leftover and MailerZ together split senders. Domain Connect and email wizards restore leftovers. Recheck after wizards. Verification TXT is ownership, not a substitute for MX. Two SPF records are a send problem, not an inbound miss. Do not “fix forwarding” by adding a second MX for backup.

Dest 250 plus spam is still forwarded. Classify is hop four. We do not promise Primary. We do not sell an inbox SLA. Dest 4xx is try later — quota and greylist live there. Dest 5xx is a final no for that attempt. Free send-as 550 is a plan boundary, not inbound forwarding. Unauthorized send is 550 5.7.1. MailerZ is not an open relay.

Checks that waste a day if you run them first

Rebuilding aliases before printing MX. Enabling catch-all to “see if it helps.” Opening port 25 on a VPS. Pasting a Gmail password into a CMS. Mailing SMTP secrets to support. Self-send loops. Buying a suite seat because spam happened. Changing Header From stories — we do not rewrite Header From, Subject, Date, Message-ID, body, or MIME. Envelope SRS only.

Loops: dest forwards back to the public alias. Disable the dest rule. Hold unknowns. One dest you control. A loop looks like a spam spike in history with repeating subjects.

Twenty checks, one stop rule

NS match. Apex MX exclusive. No leftover. Alias exists. Dest mailbox exists and is not full. HOLD not hiding the leftover. Third-mailbox probe. Unique subject. History accepted. History forwarded. Dest 250 or a printed 4xx/5xx. Spam folder checked. Filters checked. Second dest named if you fan-out. Send-as only if the ticket is outbound. Plan card if 550 is Free. Pair copied if outbound. Auth records only if you send. Wizard recheck. Neighbor aliases still work. That is twenty. Stop at the first red. Do not run all twenty as a ritual after leftover MX is already printed.

A worked ticket: plugin said sent. Gmail empty. Self-send green. Public MX still Workspace. History empty. Checks one through three failed. They never needed check twelve. Delete leftover, wait two views, new subject from Outlook.com, accepted then forwarded, dest spam once, then Primary on the next operational mail. No new aliases.

Related: delivery recovery, troubleshooting, docs, features. RFC 5321. Google and Microsoft dest docs for folders. Commercial pages nofollow. Not SOC 2. Not HIPAA.

Close the ticket with artifacts

Attach timestamp, unique subject, public MX text, history screenshot without secrets, dest folder. Do not attach passwords. If the hop never happened, say leftover or held. If the hop happened and spam ate it, say classify. If 4xx, say dest retry. If 5xx, paste the enhanced line. Start free to prove inbound on a breakable domain. Sign in if the zone already lives here.

Agencies run the order per client. A template that restores leftovers will fail check two tomorrow. Offboard deletes MX you own. The next action is check one, not a new slug. That is email forwarding not working, in the right order.

Review after a nameserver move or a helper click. Print the order on the wall. If you cannot print exclusive MX, you are not ready for catch-all or send-as.

What to copy before you change anything

Timestamp. Unique subject. Public NS. Public MX from two resolvers. Alias map screenshot without secrets. HOLD versus FORWARD. History row or the words “empty.” Dest folder. Full SMTP line if one exists. That packet lets you stop at the first red check instead of rotating records at random. Changing MX while you still have a leftover and no print is how people create a second leftover.

If history is empty, checks after hop history are optional color. Fix NS and exclusive MX first. If history shows forwarded and dest 4xx, do not delete MX. Fix dest quota. New subject. If history shows 550 on send-as and the ticket was inbound, you are on the wrong hop. Inbound forwarding does not need send-as. Free 550 is a plan. Confirm /pricing.

If dest 250 and the human looks only in Primary, check spam and filters before you rebuild aliases. Classify is not a MailerZ reject. If subjects repeat and volume spikes, print dest forwards. A loop is not “twenty DNS bugs.” Disable the circular dest rule. Hold unknowns.

Neighbor aliases are the regression test after any fix. Probe hello@ and billing@ once each. If they fail, you broke MX or dest, not “forwarding in general.” Related: delivery recovery, troubleshooting, docs, features. Envelope SRS only. Header From stays. Not an open relay. Not an inbox SLA.

Plugin “sent” is not a check

A form plugin that prints sent only proves its SMTP client got a 250 from someone. If leftover MX answered, that someone was not MailerZ. If MailerZ accepted, the plugin still does not know dest classify. Treat plugin copy as hop-unknown until history and a dest screenshot agree. Do not rebuild aliases because a plugin lied. Do not add a second dest to “see which one works.” Print MX first.

Copy host, port, and TLS from the dashboard together only when the ticket is outbound. Inbound forwarding not working is not a reason to paste SMTP into the plugin. Confirm /pricing if the line is Free send-as 550. Related: delivery recovery, troubleshooting, docs.

When to stop and when to escalate

Stop when leftover MX is printed. Escalate to dest-side support only with a dest 4xx/5xx enhanced line and a history row that shows forwarded. Escalate to MailerZ support with timestamp, subject, MX print, and history — never passwords. Empty history plus leftover MX is not an escalation; it is a delete. Confirm /pricing only for plan 550. Related: delivery recovery, troubleshooting.

Sign-off

First red check named, artifact saved, leftover deleted if that was the red, new subject sent, neighbor aliases probed. Do not run the other nineteen as theater. That is email forwarding not working, closed in order.

If the red was HOLD, name the leftover or leave it held. Do not flip catch-all forward to make the ticket green. Hold review is the control. Confirm /pricing if you need another named alias to promote it.

FAQ

What is the safest way to handle email forwarding not working?
Follow a fixed order: nameservers, exclusive MX, alias map, HOLD versus FORWARD, third-mailbox probe, hop history, then destination folder. Copy the SMTP reply before you change records. MailerZ stores hops in the retention window.
Does this require a new mailbox?
No. Broken forwarding is a routing or hop problem. MailerZ is not IMAP. Keep Gmail or Outlook.
Will it work with Gmail or Outlook?
As destinations, yes, after the hop succeeds. Self-send from those products can skip the hop. Use a third mailbox.
What DNS records are involved?
NS that actually publish the zone, exclusive MX, verification TXT, and one SPF if you send. Null MX rejects all inbound. Leftover Google or Microsoft MX splits senders.
What should I test before production?
A uniquely titled probe from an unrelated provider to each named alias. If any check fails, you are not live.

Key takeaways

  • Order: NS, MX, alias, HOLD, probe, history, folder.
  • Empty history plus leftover MX is the top miss.
  • Unknown recipient is a map miss, not spam.
  • Self-send is not a check.
  • One class, one change.
  • 250 then missing UI is destination search.
  • Outbound AUTH is a different list.
  • Write the sentence so the next person stops looping.

Conclusion

Email forwarding not working yields to order. Name the class. Change one fact. Re-probe.

Start free with one domain and run the twenty checks on a throwaway alias before you print a public address.

Start free on MailerZ