A catch all abuse audit is a week of reading held unknown mail before you dump leftovers into Gmail. Convenience wants the hose open on day one. Abuse is already in the queue: dictionary local-parts, old campaign names, and harvested admin strings. Classify those messages. Create the typos that are real roles. Keep hold if harvest dominates. Paid forward is a dated exception, not the audit’s prize.
Quick answer for a catch all abuse audit
How to audit catch-all abuse before enabling forwarding: verify the domain, publish one MX set, delete leftovers, create every printed alias, and leave unknown recipients held. MailerZ Free already holds those leftovers. For seven days, open the store and tag each unknown local-part as a typo of a live role, an old printed name you should create, or harvest. Harvest winning the count is a no-go for paid catch-all forward. Header From stays the original sender. Envelope SRS may rewrite the return path. The product is not IMAP and not a junk filter.
Catch all abuse audit setup is the same inbound path plus a classification sheet. Catch all abuse audit best practice is to refuse forward until the sheet exists. See aliases and catch-all and the policy article on hold vs forward vs reject. Addy’s public writing is competitor research, not MailerZ docs: Addy blog.
Free is one domain, three aliases, one seat, 14-day store, send-as disabled, SMTP and API disabled. If the hold window is 14 days, start the audit immediately after MX is exclusive. Do not wait two weeks and then wonder where the evidence went. Solo is $40 per year with a 90-day store and unknown forwarded on the published card—confirm the live toggle. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Confirm on MailerZ pricing.
The audit does not require SOC 2, a SIEM, or a second mailbox product. It requires exclusive MX, named aliases, and a human who can tell helloo@ from viagra@. If nobody will look at the queue, you are not ready to forward leftovers. You are ready to keep hold and staff the three names you actually print.
The user problem and the decision criteria
People enable catch-all forward because a customer once typed the wrong name. They do not measure how many wrong names arrive. On a domain that has been public for years, the wrong names are mostly bots. The customer typo is the exception. An audit makes that ratio visible before Gmail Primary becomes the measurement tool.
| Question | If yes | If no |
|---|---|---|
| Is leftover MX gone? | The hold queue is complete enough to judge. | Stop. The audit is missing senders. See troubleshooting. |
| Are all printed names aliases? | Leftovers are truly leftovers. | Create them. You are not auditing abuse yet. |
| Are most unknowns typos of live roles? | Create those aliases. Forward still optional. | Harvest. Keep hold. |
| Is the destination daily Gmail? | Need a high bar before paid forward. | A review mailbox can take a dated hose. |
| Will someone review leftovers weekly after go-live? | A short forward window can be staffed. | No-go. Hold or you will ignore junk and mail alike. |
| Is this a migration week with old strings in the wild? | Create the old strings as aliases, or date a forward. | Do not enable forward “just in case.” |
What catch-all abuse looks like in the hold queue
Dictionary harvest: info@, admin@, office@, sales1@, first names, and product words. High volume, many sending IPs, bodies that are ads or empty. This is the no-go pile. Enabling forward trains Gmail to treat your domain as a junk source and hides the one real typo in the noise.
Old campaign names: promo2021@, noreply-launch@, a webinar slug. Medium volume, sometimes real partners. The fix is an explicit alias if you still want the mail, plus an update to the partner. Catch-all forward keeps the graveyard alive forever.
Typos of live roles: helloo@, billng@, a missing hyphen. Low volume, recognizable senders. Create the alias or fix the print. That is not abuse. That is incomplete naming. An audit that only sees these is a go for staying on hold with better aliases, not a mandate to forward everything.
Bounce-back and forged mail: messages that look like your own domain talking to itself, or DSNs for mail you never sent. Hold keeps them out of Gmail. Forward can turn your inbox into a backscatter viewer. Do not enable destination auto-replies on leftovers. IETF RFC 5321 — Simple Mail Transfer Protocol is transport, not a license to generate collateral bounces.
Security-sounding leftovers: security@, abuse@, postmaster@. If you print these, they must be named aliases someone reads. If you do not print them and they appear in hold as harvest, leaving them unknown is fine. Creating empty security@ to “look professional” and then forwarding catch-all is how you miss a real report in a pile of spam.
Volume without diversity is also a signal. One local-part with two hundred identical bodies is a campaign against a guessed name. Ten local-parts with two messages each, all near a live role’s spelling, is human error. The catch all abuse audit cares about unique names first. Message count is the tie-breaker when a name might be both a typo and a harvested string.
Language and charset can fool a tired reviewer. A message that looks like a customer invoice may still be a phishing PDF aimed at accounts@ you never created. If you did not print accounts@, treat it as harvest until a known vendor confirms they have that string on file. Do not enable catch-all forward because one PDF looked official. Create billing@ if that is the printed invoice address, and tell the vendor the exact name.
Timing clusters matter. A burst of unknowns in the hour after you publish MX is often scanners noticing a new mail host. A burst the day after a press mention is often people guessing role names. A steady drip for years is a list. The first two can still be hold-only. The third is a hard no-go for unpaid attention in Primary.
Technical mail flow during the audit
Senders look up MX and offer the recipient. Named aliases store, return 250, and forward. Unknowns on Free are held. The audit reads that hold object: local-part, timestamp, apparent sender, and whether Header From matches what you expect. Envelope SRS may rewrite the return path. Header From is not rewritten.
Authentication records do not classify abuse. IETF RFC 7208 — Sender Policy Framework (SPF), IETF RFC 6376 — DomainKeys Identified Mail (DKIM), and IETF RFC 7489 — Domain-based Message Authentication, Reporting, and Conformance (DMARC) authorize outbound send-as. A passing DMARC on a leftover does not make the leftover a role you should ingest. A failing DMARC on a leftover does not prove MailerZ failed. The audit question is existence and intent of the local-part, not a score.
Recovery storage is 14 days on Free. That is the audit clock. Paid 90-day store gives agencies more room, not a reason to skip classification. Opening a held body for break-glass review can create an audit row. That is a control, not a SOC 2 badge. Do not send SMTP passwords or verification tokens to support.
Self-send lies. Probe named and unknown paths from another provider. Unique subjects. Match history. If the unknown probe arrives in Gmail during an audit you thought was hold-only, stop. You are already forwarding or you are not on MailerZ MX.
Delivery history is the other half of the lab. A named alias should show a destination SMTP response. A held unknown should not show a Gmail injection you can find in Primary. If history says delivered to the destination for a name you did not create, the audit assumption is already false. Screenshot the event, check the catch-all toggle, and check MX. Do not keep classifying a queue that is not the queue you think it is.
Leftover host MX is the usual liar. Some senders still hit Google or cPanel. Those messages never enter hold, so your harvest count looks low and you might score a false go. Query two public resolvers at the start and at the end of the week. If the set changed, restart the clock. Propagation is cache, not a progress bar. IETF RFC 1035 — Domain names is still the DNS text operators pretend they can hurry.
Step-by-step catch all abuse audit setup
Snapshot public MX from two resolvers
If Google, Microsoft, or a host still answers, delete leftovers first. An audit on split MX under-counts harvest and over-trusts the hold queue.
Export the printed name list
Website, invoices, app stores, banks, registrar, partner sheets. Create those aliases. Free allows three. Solo allows 15 at $40 per year. If you cannot fit the printed list, unprint names or upgrade. Do not use catch-all as overflow.
Prove each named alias
Other mailbox. Unique title. Header From intact. History matches the destination.
Prove hold with one invented name
If it lands in Gmail, you are not auditing hold. Fix policy or MX before the week starts.
Run a seven-day classification
Columns: local-part, count, class (typo / old print / harvest / forged), action (create alias / ignore / later). Fifteen minutes a day is enough for most founder domains.
Act on typos and old print before any forward
Create the aliases. Update partners. The leftover set should shrink. If it does not shrink, you are looking at harvest.
Score go or no-go
Harvest-majority: keep hold. Typo-majority after aliases exist: still prefer hold; dated forward only if a migration requires it. Nobody staffing the queue: no-go.
If go, write a stop date
Paid forward with a calendar reminder. Review Gmail spam daily during the window. Disable forward when the date hits. Recreate any leftover that was actually a role.
A simple go / no-go score
Count unique unknown local-parts in the week, not just message volume. Ten harvest names with a hundred messages is still harvest. Two typo names with three messages is a naming fix.
| Week result | Action | Forward? |
|---|---|---|
| Mostly harvest | Keep hold. Do not staff Primary with bots. | No |
| Mostly old print | Create those aliases. Tell partners. | Only if you cannot list them all, and only dated |
| Mostly typos of live roles | Create aliases or fix the website. | Usually no |
| Empty queue | Either MX is exclusive and the domain is quiet, or nobody is sending yet. | No “just in case” |
| Queue expired before you looked | You missed the 14-day Free window. Restart after MX is clean. | No |
Agencies copy this score per client. A new brand and a ten-year parked domain are not the same audit. Agency capacity (100 domains, 500 aliases on the $39 / $390 card) is not a reason to skip the week. Harvest on client five will still land in someone’s Gmail.
Personal domains usually finish the week empty or with a few typos. That is a success for hold, not a reason to enable Solo’s unknown-forwarded default without looking. Confirm the dashboard. Published cards are not a substitute for the toggle you actually have.
Write the score in the same place you keep the alias catalog: date, unique leftover count, harvest share, aliases created that week, and the decision. Next quarter, compare. If harvest share dropped after you created old print names, the audit worked. If harvest share stayed high and someone enabled forward anyway, you have an operations problem, not a MailerZ problem. The catch all abuse audit best practice is to treat that write-up as the change-control record for leftover policy.
Do not store full message bodies in a shared spreadsheet. Local-part, count, class, and action are enough. Bodies can contain invoices, password resets, and personal data. The hold store already has the bytes for 14 or 90 days. Copying them into a doc creates a second store you will forget to delete. That is the opposite of a careful audit.
Failure modes and proof
| What you see | Likely cause | Proof to collect |
|---|---|---|
| Empty hold, angry customers | Leftover MX or uncreated printed names. | Public MX. Alias list versus website. |
| Hold full of ads on day one | Harvested domain. Expected. | Classification sheet. No-go for forward. |
| Unknown probe in Gmail | Already forwarding or wrong MX. | Dashboard policy. Two resolvers. |
| Self-send empty | Gmail short-circuit. | Different provider. |
| Evidence gone on day 15 | Free 14-day store. | Restart the week. Do not invent a vault. |
| Forward enabled mid-audit | Someone “fixed” a typo with the hose. | Turn it off. Recreate the missing alias. |
| SMTP 550 on send | Unauthorized From. Not inbound leftover policy. | Exact response. Paid send-as on a named identity. |
Proof is the classification sheet plus MX plus one unknown probe. Inbox placement is not an audit result. A spam folder full of leftovers after you enabled forward is a failed audit, not a MailerZ outage.
MailerZ workflow and product boundary
MailerZ is a custom-domain email delivery layer operated by Secuno LLC. Site: mailerz.net. App: mail.mailerz.net. Positioning: named aliases, hold on Free, optional paid forward after you understand leftovers. The audit is how you earn the right to touch that toggle.
What MailerZ does
- Hold unknown recipients on Free so an audit is possible.
- Accept named aliases into Gmail or Outlook.
- Allow paid catch-all forward when configured.
- Preserve Header From. Envelope SRS only.
- Store 14 or 90 days. Record delivery history.
- Paid SMTP from approved identities only.
What MailerZ does not do
- Classify harvest for you or promise a spam score.
- Create IMAP mailboxes or Gmail users.
- Rewrite header From, Subject, Date, Message-ID, body, or MIME.
- Offer send-as on Free or send-as for harvested names.
- Promise inbox placement, uptime SLAs, or review counts.
- Claim SOC 2, ISO 27001, or HIPAA. Security.
- Act as an open relay or campaign sender.
Cost, alternatives, and trade-offs
The audit costs an hour across a week. Paid forward without an audit costs days of Gmail. Workspace seats do not replace the week; they move leftovers into a hosted store you still have to read. Cloudflare Email Routing can also accept leftovers in that DNS. It is not MailerZ leftover-MX handling or a 14-day hold lab. Read Cloudflare — Email Routing documentation if that is the stack you are leaving.
| Approach | You get | You give up |
|---|---|---|
| Hold + weekly classify | Evidence. Clean Primary. | Typos wait until you create aliases. |
| Forward without audit | Speed. | Harvest in the working inbox. |
| Dated forward after a clean week | Migration coverage. | You must disable it on the date. |
| Review mailbox forward | Primary stays cleaner. | You still accepted junk at MX. |
Annual Starter, Business, and Agency include two months free versus monthly. Solo has no monthly option. Seats operate the router. They are not analysts. Assign a human to the sheet. Fifteen minutes a week after go-live is the maintenance version of the same audit.
Do not buy extra seats to “watch catch-all.” Watching is a person and a calendar, not a login. Do not buy Workspace to get a better leftover policy. The suite can accept or reject unknowns depending on configuration, and you still pay per mailbox. Use Workspace when humans need hosted mail and Calendar. Use MailerZ hold when you need a lab for leftovers next to Gmail you already trust.
Registrar cost does not change when you keep hold. The incremental cost of a failed audit is support time and a dirty Primary. The incremental cost of a passed audit that still chooses hold is almost nothing: you already pay for the domain and the Free or Solo card. That is the point of the week. You are buying information, not a new product SKU.
If you later need send-as for a named role you created during the audit, that is a separate paid path. Free has no send-as. Solo starts send-as at 5 per hour and 100 outgoing per month. Catch-all forward will not send as harvested names. Unauthorized From still gets 550. Keep the audit scoped to inbound leftovers so you do not mix two jobs in one ticket.
FAQ
What is the safest catch all abuse audit before forwarding?
Clean leftover MX, create every printed alias, leave unknowns held for at least a week, and classify the queue: typos of live roles, old printed names, or dictionary harvest. Only enable paid catch-all forward when harvest is rare and someone will watch Gmail. Do not enable forward to hide missing names.
Does this require a new mailbox?
No. The audit uses MailerZ hold and delivery history, not a new IMAP store. Destinations stay Gmail or Outlook. A dedicated review mailbox is optional if you later forward leftovers on purpose.
Will it work with Gmail or Outlook?
Yes for named aliases into verified destinations. Held unknowns stay out of those inboxes until you create an alias or enable paid forward. Free has no send-as. Catch-all does not mint From identities.
What DNS records are involved?
A verification TXT, one MX set, leftover host MX removed, and SPF, DKIM, and DMARC if you send as the domain. An audit on split MX is fiction: some senders never reach the hold queue.
What should I test before production?
Probe each named alias from another mailbox. Probe one invented name and confirm hold on Free. After a week of classification, decide go or no-go on paid forward. Self-send can hide both paths.
Key takeaways
- A catch all abuse audit reads held unknowns before paid forward.
- Classify typos, old print, and harvest. Act on the first two as aliases.
- Harvest-majority is a no-go for catch-all forward.
- Free holds leftovers and stores 14 days. Start the week immediately.
- Leftover MX makes the queue a sample, not a census.
- Header From stays the original sender. Envelope SRS only.
- Do not enable forward to hide missing names.
- If you forward, write a stop date and staff Gmail daily.
- MailerZ is not SOC 2, not IMAP, and not a spam-filter SLA.
- Do not copy held bodies into a shared spreadsheet. Local-part, count, and class are enough.
- Restart the week if leftover MX changed mid-audit. The queue is only a census when MX is exclusive.
- Write the go or no-go with a date. Treat leftover policy as change-controlled, not a midnight toggle.
Conclusion and next action
Catch-all forward is easy to enable and expensive to staff. The audit is the cheaper path: exclusive MX, named aliases, a week of hold, a sheet, a go or no-go. Most founder domains should stay on hold. Migration weeks can earn a dated hose. Harvested domains should never “just enable catch-all.”
Next action: add one domain, create the printed aliases, probe an unknown name, and start the seven-day sheet. Do not touch paid forward until the sheet exists. If the week is harvest, leave hold on and unprint names you will not staff. If the week is typos, create those aliases and run one more quiet day before you call the domain production-ready.
Ready to audit leftovers on hold
Start free with one domain and prove the path.
Three aliases on Free. Unknown held. Paid forward only after a week you can explain.
Review quarterly, or sooner if leftover policy or store windows change. Author: MailerZ editorial, Secuno LLC.