Ask Leo! by Leo A. Notenboom

I keep getting bounce emails for addresses on my domain that don't exist. How can I stop this?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » EMail » Spam

Summary: As a result of techniques used by spammers you may get bounces for email you never sent. There's little you can do.

Lately I have been receiving returned emails that were originally sent by a randomly generated email address in my domain. These accounts don't exist, but when the mail is returned we get the returned email. How can I stop this?

The painfully short answer is that you probably can't. Though there are some ideas to at least make it a little less painful.

For what it's worth, you're not alone. You are so not alone.

What's happening is a variation of what's called a "dictionary attack" though in this case attack is perhaps the wrong term. Spammers will often search the domain name registry for domains that they can then assume are real. Once they have the domains, they send their spam to randomly selected common names or just randomly manufactured email addresses on that domain. Hundreds of them. Thousands of them. AND they use them as fake return addresses as well which is what you're seeing.

It's very similar to the situation created by certain types of viruses I discussed in my previous article: Someone's sending from my email address! How do I stop them?!.

Most of the randomly generated email addresses miss - they're not valid accounts and as a result they get bounced back to the "From" address. In your case the from address is also a random and invalid address on your domain and your mailer is presumably letting you know about it.

What to do?

Well, as the owner of several email domains I used to like being able to have what's called a "catch all" address - meaning that mail sent to any address on my domain would get to me. It was a great way to see who's using mail email addresses for what purpose by just using some bogus address on my domain and seeing what email got sent to it.

Unfortunately that also meant that any email address on my domain was valid and would get to me.

I don't do that any more. Dictionary attacks like I've just described result in a flood of email to all sorts of random addresses on my domains. I now only look at the addresses I actually define.

So sadly, don't use catch-all addresses.

Unfortunately some email addresses should be looked at. Not only my own, but addresses like "webmaster" are standard ways for some forms of notification. I do know that many domain owners no longer look at these either due to the volume of spam. I happen to have a reasonable spam filter which catches about 90% of the spam.

Invest in a good spam filter.

Finally, and probably most relevant to your situation, if a bounced email message gets sent to an invalid address (because the original "came from" an invalid address it sounds like your email system is notifying you, or forwarding those invalid bounces to a known good address. If you can, I'd turn that off and let those bounces to invalid addresses just disappear.

Related:

Article C1983 - June 4, 2004

Helpful? Get new articles weekly by email in my FREE newsletter!

Your Name:
Your Email:


Why Subscribe?

Recent Comments
1 Comment

I really like your answer's they have helped me lots of time

Posted by: alta hubbard at March 11, 2006 2:44 PM

Post a comment on "I keep getting bounce emails for addresses on my domain that don't exist. How can I stop this?":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...


Question? Ask Leo!