Security & Abuse

How to disable a compromised alias without breaking the domain

Kill the prefix. Leave MX. Hold unknowns. Rotate SMTP only if it could send.

MailerZ editorial · Secuno LLC16 min read

Disable a compromised email alias by removing or remapping that custom domain alias — that email forwarding alias and role address — without touching exclusive MX or the other names. Keep the domain. Rotate send-as if the leaked string could send. Do not enable catch-all to “keep receiving the leak.” Hold unknowns. Probe sibling aliases from another mailbox. Envelope SRS only. Header From stays on inbound you still want. Confirm /pricing. Not HIPAA. Not SOC 2.

One local-part off, zone stays
Disable the leak. Keep MX.

Quick answer for disable compromised email alias

Disable or remap the leaked local-part. Keep exclusive MX. Rotate send-as if needed. Probe the names you still print. That is disable compromised email alias without breaking the domain.

A custom domain alias is one row. The zone is hop one.

Create a replacement string only if you will print it. Update vendors.

Do not catch-all the old name forever.

MailerZ Free is one domain, three aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.

Google’s own Send mail as steps live in Google Gmail Help — Send mail from a different address. Workspace as a product is described on Google Workspace — product overview. Transport still follows IETF RFC 5321 — Simple Mail Transfer Protocol.

custom domain alias: the real decision

Deleted MX because spam@ leaked.

Catch-all to keep the leaked string alive.

Forgot SMTP rotate.

Criteria: leaked row gone, MX exclusive, secrets rotated, neighbors probed.

Keep versus kill
ItemKeepKill
Domain / MXYesNo
Other aliasesYesNo
Leaked local-partNoDisable
Send-as pair if usedNo — rotateOld secret

Prove inbound from another mailbox before you print hello@ on a homepage.

Start free — one domain

Technical mail flow for disable compromised email alias

After disable, RCPT TO the leak should hold or reject per policy — not land in Primary.

Other aliases still match. Exclusive MX still accepts hop one.

Old send-as still leaves as the domain until you rotate.

Self-send to the leak is not proof the dest is clean.

MailerZ is inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not Google Workspace, not IMAP, not webmail, not an open relay. Unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA.

Rotate send-as the same hour
A leftover pair still sends as the leak.

email forwarding alias

Name the leaked string, the dest, and every CMS that could send as it. Then click.

  1. Disable or delete the leaked alias.
  2. Hold unknowns. Do not catch-all the leak.
  3. Rotate send-as if that From existed. Revoke CMS copies.
  4. Keep exclusive MX. Do not delete leftovers you already cut — and do not add any.
  5. Create a replacement only if you will print it. Update vendors.
  6. Probe remaining printed names from another mailbox.
  7. Search dest spam for the leak subject if you need evidence.
  8. Tell vendors the new string. Do not announce MX is down.

Failure modes and proof

MX deleted.

Catch-all the leak.

Secret left in WordPress.

Self-send only.

Printed replacement before it existed.

Leftover MX is the usual ghost. Check a public lookup before you blame Gmail.

Open leftover MX troubleshooting

MailerZ workflow and product boundary

Related: features, security, aliases and catch-all, send and reply.

Abuse response is hops and maps. Not a police report.

Related pages: features, security, aliases and catch-all, and send and reply.

Hold, do not catch-all the abuse
Harvest is not continuity.

role address

One alias slot changes. The domain does not. Confirm /pricing if you add a replacement on a full Free plan.

Google helpful-content is not an incident plan. /security is the questionnaire.

MailerZ Free is one domain, three aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.

Field notes you can reuse

Reassign-on-leave is planned disable. This is abuse disable.

Loops are dest forwards. Different ticket.

14-day hops may show the abuse if we accepted it.

SOC 2 is still no.

Agencies: per-client leak, per-client rotate.

Do not mail SMTP in the incident thread.

Legal@ leaks need counsel on the replacement string.

Quarterly leftover review still after the incident.

Deeper field notes for disable compromised email alias

The zone is not the incident

Disable compromised email alias is a row operation. The domain, exclusive MX, verify TXT, and the other aliases stay. Panic-deleting MX takes hello@ and billing@ down because newsletter@ leaked. That is how a scrape becomes an outage. Disable the leaked local-part. Hold unknowns so the scrape does not become catch-all continuity.

If the leaked string could send, rotate send-as the same hour. Revoke WordPress, plugins, and chat pastes. Unauthorized 550 after rotate is success. Free had no send-as — still disable the inbound row.

Replacement strings

Create the new local-part before you print it. Update vendors. Probe the new name and the neighbors. Do not promise the old string will keep working. If counsel needs the old name on a PDF, they date the change. MailerZ will not keep a leaked row alive as a courtesy hop.

Evidence

History of hops we accepted. 14/90 days. Not a police report. Not HIPAA. /security is the questionnaire. Related: features, aliases and catch-all, send and reply. Reassign-on-leave is the planned version of disable. This is the abuse version.

Agencies: per-client leak. Do not disable MX on the agency lab because a client alias leaked.

A complete worked story

They deleted MX because newsletter@ leaked

A scraped newsletter@ started getting abuse. They removed all MX. hello@ and billing@ died. They put MailerZ MX back, disabled newsletter@, rotated an unused send-as pair, probed hello@ and billing@, and held unknowns. The domain never needed to break. The row did.

Operator brief

A longer operator brief for disable compromised email alias

Teams that bookmark How to Disable a Compromised Alias Without Breaking the Domain usually arrive after a missed invoice, a form that never notified anyone, or a migration that looked clean in one resolver. The useful brief is still boring. Name the store. Name the printed local-parts. Name the nameservers that actually answer. Publish one MailerZ MX set. Delete leftover hosts. Probe from a mailbox that is not the destination. Only then talk about disable compromised email alias as a send-as, catch-all, or comparison problem.

MailerZ remains inbound MX plus authenticated SMTP around Gmail or Outlook. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. It is not a hosted mailbox, not IMAP, not webmail, and not an open relay. Unauthorized send is 550 / 550 5.7.1. Free cannot finish send-as: SMTP and API stay off. Solo is $40 per year when the domain From must travel. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm the live pricing page. Those numbers are ceilings, not an inbox-placement service-level agreement.

If leftover Google, Microsoft, Cloudflare routing, or registrar MX is still public, stop widening disable compromised email alias. The map you built never saw that copy. Priority numbers are an order, not load balancing. A higher preference host is idle while a leftover host still accepts mail. Save the old MX set before you delete anything. Check more than one public view because TTL lies.

Catch-all forward is not a safety feature for how to disable a compromised alias without breaking the domain. Hold unknowns on everyday production. Review the store. Promote a leftover only when a real person used it. Paid forward belongs to a dated cutover. Fan-out of unknowns into two inboxes trains two spam buttons. Plus addressing on Gmail is not a custom-domain unknown policy. MailerZ will not strip plus tags on your domain the way Gmail does on @gmail.com.

Send-as is a second hop. Creating an inbound alias does not approve outbound. Catch-all does not mint a From. Copy the dashboard host, port, and TLS pair together. Set From to an identity you created. Do not paste a Gmail password into a CMS, a cron file, or a ticket. Do not mail SMTP secrets to support. Send a 550 line, a timestamp, and a Message-ID. Rotate if a secret already leaked.

Self-send from Gmail to the same Gmail account can short-circuit. That green result is why people swear disable compromised email alias works while customers vanish. Use a second provider. Put a unique subject on the probe so delivery history is searchable. If Header From was rewritten by some other forwarder, authentication stories get noisier. MailerZ does not rewrite Header From on inbound.

Agencies should keep disable compromised email alias per client zone. Separate SMTP credentials. Do not pour every client into one catch-all because the spreadsheet got long. Agency plan capacity exists so you can hold more domains and aliases. It does not replace a named list. Offboard means delete MX you own, revoke SMTP, and stop forwarding leftovers into the agency inbox.

Legal and security questions have published answers on the security, privacy, terms, DPA, and subprocessors pages. MailerZ is not SOC 2, not ISO 27001, and not HIPAA. The 14-day Free store, the 90-day Solo–Agency store, and the 180-day Unlimited store are recovery windows for hops this layer saw. They are not an archive and not legal hold. If counsel wants eDiscovery, buy eDiscovery.

Comparisons only help after the hop is honest. Cloudflare Email Routing is inbound routing. A privacy-mask product hides a destination on a provider domain. A suite hosts mailboxes, Calendar, and admin. Proton-class mailboxes encrypt a store. MailerZ is the delivery layer when you already have Gmail or Outlook and you need a domain route you can prove. Cite the other product’s documentation. Do not invent feature parity.

When How to Disable a Compromised Alias Without Breaking the Domain is closed, the next physical action is a lookup and a probe, not another tab. Start free on one domain you can break. Sign in if the zone already lives here. Review quarterly, or sooner after a nameserver move, a plugin swap, or a staff departure. That is how disable compromised email alias stays a runbook instead of an incident.

A second worked pass for disable compromised email alias: write the last change on a sticky note before you open the dashboard. Nameserver move, leftover MX, new form plugin, contractor laptop, or a registrar forwarding toggle are the usual five. MailerZ history only shows hops that reached this layer. If the sticky note says leftover MX, you do not have a disable compromised email alias mystery. You have a split. Delete the leftover. Wait for TTL. Probe again.

A third worked pass: print the public list. If you cannot print it, you are not ready for production unknowns and you are not ready for a bigger alias ceiling. Unlimited aliases as marketing will not save a missing list. Three named aliases on Free are enough to stop printing a personal Gmail on a homepage. Grow the list when a real person used a leftover, not when a harvest guessed admin@.

Kill the string, keep the zone

Disable a compromised email alias by removing or remapping that local-part only. Keep exclusive MailerZ MX. Keep the other named aliases. Do not delete the domain because hello@ leaked on a leftover PDF. Do not enable catch-all “so nothing breaks” — that forwards the leak to a dest and trains spam. Hold unknowns. Review the store for who still writes the old string. Tell real people the new local-part once, in a channel that is not the leaked alias.

If that From could send, rotate the SMTP secret. Copy the new host, port, and TLS pair from the dashboard together. Do not paste the old secret into a ticket. Do not mail the new secret to support. A 550 line, a timestamp, and a Message-ID are enough. Free cannot finish send-as, so a leaked Free From was inbound-only unless they used another relay. Paid send-as means assume the secret is burned if it lived in a CMS, a cron file, or a contractor laptop.

Probe neighbor aliases from another mailbox after you disable the leaked one. Unique subjects. Confirm hello-new@ and billing@ still accept, forward, and land. If they fail, you deleted MX or you pointed the dest at a dead mailbox. Fix that. Do not restore the leaked string to “test.”

What not to do in the first hour

Do not publish a new leftover MX “just for this alias.” MX is per zone, not per local-part. Do not buy a second domain because one string leaked. Do not fan-out the leaked string into two dests so you can “watch” it. Watching a leak is still delivering a leak. Disable or remap. Hold. Rotate. Probe neighbors.

Agencies: revoke the client SMTP if the contractor who leaked the alias also had send-as. Separate credentials exist so one laptop does not mint From for every client. Offboard the person and the string in the same hour. Confirm pricing for seat and alias ceilings. Not an inbox SLA. Not SOC 2. Not HIPAA. Published security, privacy, terms, DPA, and subprocessors pages are the legal set.

A leaked careers@ that did not need a zone rebuild

Careers@ sat on a job-board PDF from 2021. Harvest started. The dest Gmail filled. The operator almost deleted the domain from MailerZ. That would have broken invoices@ and hello@. They disabled careers@, held unknowns, created jobs@, told the board once, rotated SMTP because send-as had used a shared secret, and probed invoices@ from Outlook.com. History for invoices@ stayed clean. History for careers@ stopped. The PDF still exists on the internet. Hold plus a dead local-part is the control you actually have.

A second case remapped the leaked string to a quarantine mailbox for a week, then disabled it. That is optional. It is not required. Do not leave the remap forever. Forever remap is still a live target. Disable when the week ends.

Related: features, security, aliases and catch-all, send and reply. This page is the one-string cut. The next action is disable, rotate, probe neighbors.

Order of operations for the first hour

Disable or remap the leaked local-part. Do not touch MX. Do not delete the domain. Do not enable catch-all. Hold unknowns if they were not already held. Rotate SMTP if that From could send. Copy the new pair from the dashboard. Update the one CMS or cron that used the old pair. Do not email the secret.

Tell real people the new local-part in a channel that is not the leak. Probe neighbors with unique subjects from another mailbox. Confirm invoices@ and hello@ still show accepted then forwarded. Check those dests including spam. If a neighbor fails, you broke dest or MX — fix that before you invent a second domain.

Optional: remap the leak to a quarantine mailbox for a dated week, then disable. Do not leave it live. The PDF on the internet will keep attracting harvest. Hold plus a dead string is the durable control. Confirm /pricing if you need another named alias for the replacement string. Free has three. Solo has fifteen. Seats are on the live page.

Write the hour in the ticket: string killed, secret rotated, neighbors probed, humans told. That is a closed compromise of one alias. It is not a SOC 2 incident report and not a HIPAA event. Point counsel at the published security and privacy pages. Related: features, security, aliases and catch-all, send and reply.

Neighbor aliases are the regression test

After you kill the leaked string, invoices@ and hello@ are the proof the zone still works. One foreign probe each. History plus dest. If those pass, you did not break the domain. If they fail, restore MX or dest — not the leak. Confirm /pricing if you need a replacement local-part on a higher alias ceiling.

FAQ

What is the safest way to handle disable compromised email alias?
Disable or remap the leaked local-part. Keep exclusive MailerZ MX and the other aliases. Rotate send-as if that From could send. Hold unknowns. Do not catch-all the leak. Probe remaining printed names from another mailbox. Create a replacement only after you will print it.
Does this require a new mailbox?
No. MailerZ is not IMAP and not webmail. Gmail or Outlook remains the store unless you separately buy a hosted mailbox product.
Will it work with Gmail or Outlook?
Yes for inbound when the destination is a verified mailbox. Branded replies need paid send-as plus Gmail Send mail as or a manual Outlook SMTP identity. Free has no send-as.
What DNS records are involved?
A verification TXT, one MailerZ MX set on the authoritative nameservers, leftover host MX removed, and SPF, DKIM, and DMARC if you also send as the domain.
What should I test before production?
Send a uniquely titled message from an unrelated provider into each named alias. Confirm Header From and delivery history. Do not email yourself from the same Gmail account.

Key takeaways

  • Kill the row.
  • Keep the zone.
  • Rotate send-as.
  • Hold leak.
  • Probe neighbors.
  • Print replacement after create.
  • No MX panic.
  • Revoke CMS.

Conclusion and next action

Disable a compromised alias as a row change. MailerZ will keep the domain’s MX. Rotate secrets. Hold the leaked string. Probe what you still print. Do not burn the zone because one vendor leaked.

Start free. Sign in if the leak is already public and MX was deleted in panic.

Disable the string

Start free to prove the rest of the map after you kill the leaked name.

Do not delete MX because one alias leaked.

Review quarterly, or sooner if Gmail, Workspace, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.