How to Reject Emails Sent to Unknown or Non-Existent Email Addresses in Google Workspace – Disable Catch-All Email
When an organization uses Google Workspace for business email, administrators normally create specific email addresses such as: sales@yourdomain.com accounts...
When an organization uses Google Workspace for business email, administrators normally create specific email addresses such as:
Ideally, email should be accepted only when the recipient is a legitimate user, alias, or permitted Google Group.
For example, suppose your company has these valid addresses:
accounts@yourdomain.com
sales@yourdomain.com
support@yourdomain.com
But somebody sends messages to:
abc@yourdomain.com
random@yourdomain.com
sales123@yourdomain.com
anything@yourdomain.com
If these addresses don't exist, you may want Google Workspace to reject the message rather than deliver it to another mailbox.
This is particularly important if a catch-all email configuration was previously enabled.
What Is a Catch-All Email Address?
A catch-all mailbox receives messages addressed to email addresses that don't otherwise exist in your domain.
For example, assume your domain is:
example.com
and your only real mailbox is:
If catch-all routing is configured to send unrecognized mail to info@example.com, messages addressed to addresses such as:
sales@example.com
abcdef@example.com
test123@example.com
wrongname@example.com
can all end up in info@example.com, even though those individual addresses were never created.
Google Workspace supports catch-all routing by applying a Gmail routing rule to the Unrecognized/Catch-all account type.
This can be useful in some organizations because it prevents mail from being lost because of typing mistakes.
However, it is not always desirable.
Why You May Want to Disable Catch-All Email
For many businesses, accepting messages only for specifically authorized addresses provides cleaner and more predictable mail handling.
1. Reduces Unwanted Email
Spammers frequently send messages to common or randomly generated addresses such as:
admin@domain.com
office@domain.com
billing@domain.com
contact@domain.com
accounts@domain.com
If catch-all routing is enabled, some of these messages can reach your catch-all mailbox even when those addresses were never created.
2. Prevents Confusion
Employees may start receiving messages intended for departments or email addresses that don't actually exist.
3. Makes Your Email Structure Clear
If an address hasn't been created as a user, alias, or permitted group, the sender receives a non-delivery response rather than assuming the address is being monitored.
4. Reduces Catch-All Mailbox Clutter
Catch-all mailboxes can accumulate significant amounts of irrelevant email over time.
5. Prevents Accidental Use of Incorrect Addresses
Suppose the correct address is:
but a customer sends mail to:
With a catch-all mailbox, the incorrect address might still work.
Without catch-all handling, the sender gets a delivery failure and can correct the recipient address.
Desired Google Workspace Configuration
The intended configuration is:
Existing user → Accept
Existing email alias → Accept
Authorized Google Group → Accept according to the Group's permissions
Non-existent/unknown address → Reject/Bounce
For example:
| Recipient | Exists? | Expected Result |
|---|---|---|
| sales@example.com | Yes | Delivered |
| accounts@example.com | Yes | Delivered |
| support@example.com | Yes | Delivered |
| abc@example.com | No | Rejected |
| random123@example.com | No | Rejected |
| wrongaddress@example.com | No | Rejected |
This means your domain doesn't function as a catch-all destination.
Step 1 – Sign In to Google Admin Console
Sign in to the Google Admin console using an account with the required administrator privileges.
The administrator needs access to Gmail settings.
Open:
Admin Console → Apps → Google Workspace → Gmail
Step 2 – Open Gmail Routing
Navigate to:
Admin Console → Apps → Google Workspace → Gmail → Routing
Google Workspace uses Gmail routing settings to control how incoming and outgoing messages are processed.
Google currently provides both Default routing and Routing settings, so both areas should be reviewed if your domain is unexpectedly accepting mail for non-existent users.
Step 3 – Look for a Catch-All Routing Rule
Under Routing, inspect all configured rules.
You're particularly interested in a rule configured for:
Inbound email
and:
Account types to affect → Unrecognized / Catch-all
A typical catch-all rule may also contain:
Change envelope recipient
followed by:
Replace recipient
and an existing mailbox such as:
or:
Such a configuration means an email sent to an unrecognized address can be redirected to the specified mailbox.
Step 4 – Disable or Delete the Catch-All Rule
If you no longer want to receive messages sent to non-existent addresses, locate the catch-all rule and:
Disable
or
Delete
the catch-all routing setting.
Disabling is usually preferable initially because you can restore the configuration if necessary.
Once you have confirmed everything is working as intended, you can decide whether the obsolete rule should be permanently deleted.
Step 5 – Check Default Routing
This is an important troubleshooting step.
Navigate to:
Admin Console → Apps → Google Workspace → Gmail → Default routing
Inspect existing rules carefully.
Look particularly for rules that:
- Affect all recipients
- Affect unrecognized recipients
- Replace envelope recipients
- Add additional recipients
- Route messages to another mailbox/server
- Redirect unknown addresses
- Perform actions on non-recognized addresses
An old Default Routing rule can sometimes explain why mail is still being delivered somewhere even after a catch-all configuration has apparently been removed.
Do not delete legitimate routing rules blindly. Organizations may use Default Routing for split delivery, dual delivery, gateways, compliance, archiving, or other mail-flow requirements.
Step 6 – Review Email Aliases
An address that appears "unknown" may actually be configured as an alias.
For example:
Main user:
Aliases:
sales@example.com
enquiry@example.com
Mail addressed to sales@example.com or enquiry@example.com is therefore legitimate and can be delivered to John's mailbox.
Check:
Admin Console → Directory → Users → Select User
and review the user's alternate email addresses/email aliases.
Remove only aliases you genuinely no longer require.
Step 7 – Check Google Groups
An email address doesn't necessarily need to be a licensed Google Workspace user to be valid.
For example:
might be a Google Group rather than an individual mailbox.
Therefore, also check:
Admin Console → Directory → Groups
before concluding that an address is unknown.
A Google Group can have its own email address and delivery/access rules.
Step 8 – Test With a Genuine External Email Account
After making the changes, test the configuration from an external account.
For example, if your Workspace domain is:
example.com
and this user exists:
send one message to:
It should be delivered normally.
Now send another message to a completely fabricated address such as:
provided you have confirmed that this address is not:
- A Workspace user
- An alias
- A Google Group
- A routing destination
The message should not silently arrive in an unrelated mailbox.
Instead, the sender should eventually receive a delivery failure/non-delivery notification when Google determines that the recipient doesn't exist.
What Does "Address Not Found" Mean?
When mail is sent to a non-existent recipient, the sender may receive a delivery error indicating that the address could not be found or that the recipient doesn't exist.
This is the expected behavior when your goal is to accept mail only for valid recipients.
It essentially means:
"This domain exists, but this particular recipient address is not a valid destination."
Important: Don't Confuse Catch-All With Email Aliases
These are two different concepts.
Email Alias
An alias is an intentionally created alternate address.
Example:
User:
Alias:
Both are valid addresses.
Catch-All
Catch-all handling accepts or redirects messages addressed to otherwise unrecognized addresses.
Example:
could be redirected to another mailbox even though "anything" was never specifically created.
If you want mail delivered only to explicitly configured addresses, catch-all behavior is generally not what you want.
Recommended Business Configuration
For most organizations that want tightly controlled email addressing, a practical structure is:
Users
Create individual mailboxes for employees who need their own accounts.
Examples:
john@example.com
accounts@example.com
Aliases
Use aliases when multiple addresses should deliver to the same person.
Example:
User:
Aliases:
sales@example.com
enquiry@example.com
Groups
Use Google Groups for department or team addresses where multiple people need access or distribution.
Examples:
support@example.com
sales@example.com
management@example.com
Unknown Addresses
Do not configure catch-all routing if you want unknown addresses to be rejected.
This provides a clean structure:
User → Deliver
Alias → Deliver
Authorized Group → Deliver
Unknown address → Reject
Security Considerations
Disabling catch-all email should not be considered a replacement for anti-spam or email authentication.
Google Workspace administrators should separately configure and maintain:
- SPF
- DKIM
- DMARC
- Two-Step Verification
- Administrator account security
- Gmail anti-spam settings
- Appropriate routing rules
- User and Group access controls
SPF, DKIM, and DMARC deal primarily with email authentication and spoofing. They don't determine whether an arbitrary recipient address in your organization should exist.
Recipient validation and catch-all handling are separate mail-flow considerations.
Troubleshooting: Unknown Emails Are Still Being Received
If emails addressed to non-existent recipients continue to arrive after catch-all has been disabled, investigate the following.
Check 1 – Routing
Go to:
Apps → Google Workspace → Gmail → Routing
Review every active rule.
Check 2 – Default Routing
Check:
Apps → Google Workspace → Gmail → Default routing
Look for old rules affecting unrecognized recipients.
Check 3 – User Aliases
Verify whether the supposedly unknown address exists as an alias.
Check 4 – Google Groups
Check whether the address belongs to a Group.
Check 5 – Multiple Domains
If your Workspace account has secondary domains or domain aliases, verify that the address isn't being recognized through another domain configuration.
Check 6 – External Mail Routing
Organizations using another mail server, SMTP gateway, split delivery, dual delivery, or third-party email security service should inspect those configurations as well.
Check 7 – Allow Time for Changes
Google states that Gmail routing changes can take up to 24 hours, although they normally take effect sooner.
Therefore, don't assume a setting has failed immediately after changing it.
Example Configuration
Suppose your company owns:
mycompany.com
and you've created only:
info@mycompany.com
sales@mycompany.com
accounts@mycompany.com
Your requirement is:
info@mycompany.com → ACCEPT
sales@mycompany.com → ACCEPT
accounts@mycompany.com → ACCEPT
but:
abc@mycompany.com → REJECT
test@mycompany.com → REJECT
xyz@mycompany.com → REJECT
random@mycompany.com → REJECT
In this situation, you generally do not need to create hundreds of rejection rules.
Instead, ensure that you have not configured a catch-all mechanism that redirects unrecognized recipients to another mailbox, and review Routing and Default Routing for rules that alter this normal behavior.
Frequently Asked Questions (FAQ)
1. What is a catch-all email in Google Workspace?
A catch-all configuration routes messages addressed to otherwise unrecognized or non-existent addresses in your domain to a designated mailbox or Group.
2. Should I enable catch-all email?
It depends on your requirement. Catch-all can prevent messages from being lost due to mistyped addresses, but it can also result in unwanted messages being delivered.
3. I want only created email addresses to receive email. What should I do?
Do not use a catch-all routing rule for unrecognized recipients. Review Gmail Routing and Default Routing to ensure unknown addresses aren't being redirected elsewhere.
4. Where is the catch-all configuration in Google Workspace?
The current Google documentation directs administrators to:
Admin Console → Apps → Google Workspace → Gmail → Routing
Catch-all rules use the Unrecognized/Catch-all account type.
5. Can I disable a catch-all without deleting users?
Yes. Catch-all routing and user accounts are separate. Disabling a catch-all rule doesn't delete legitimate Workspace users.
6. Will existing users continue receiving email?
Yes, provided you don't accidentally modify routing rules that affect those users.
7. Will email aliases continue working?
Yes. A valid alias remains a recognized email destination.
8. Will Google Groups continue receiving messages?
Generally yes, subject to the Group's own permissions and configuration.
9. What happens when somebody emails an invalid address?
If there is no user, alias, Group, or routing rule accepting that address, the message can be rejected and the sender typically receives a non-delivery/bounce notification.
10. Why am I still receiving emails addressed to addresses I never created?
Check for:
- Catch-all routing
- Default Routing rules
- Gmail Routing rules
- User aliases
- Google Groups
- Domain aliases
- Secondary domains
- External gateways or mail servers
11. Is an alias considered an authorized email address?
Yes. An alias that you intentionally create is a recognized destination associated with another account.
12. Do I need to create a rejection rule for every fake address?
Normally, no. There are potentially unlimited combinations of addresses. The better approach is to ensure unknown recipients aren't being captured by catch-all or another routing mechanism.
13. Does disabling catch-all improve security?
It can reduce unnecessary exposure and mailbox clutter by preventing arbitrary recipient names from being routed into a mailbox. However, it should be only one part of your overall email-security configuration.
14. Is catch-all related to SPF, DKIM, or DMARC?
No. SPF, DKIM, and DMARC primarily authenticate email and help protect against spoofing. Catch-all controls how messages addressed to unrecognized recipients are handled.
15. Can I use Google Groups instead of creating additional licensed users?
For departmental/distribution addresses, Google Groups can often be appropriate. Whether a Group meets your requirements depends on how you want members to receive and respond to messages.
16. How long do Gmail routing changes take?
Google states that changes can take up to 24 hours, although they usually take effect sooner.
17. Should I delete a catch-all rule immediately?
You can disable it first, test your legitimate addresses, aliases, and Groups, and then delete it after confirming that mail flow is correct.
18. What is an "Unrecognized/Catch-all" recipient?
It refers to recipient addresses that Google Workspace treats as unrecognized for purposes of the routing rule, rather than normal recognized Users or Groups.
19. Can an old routing rule cause unknown addresses to continue working?
Yes. This is why both Routing and Default Routing should be reviewed when troubleshooting unexpected mail delivery.
20. What is the recommended final test?
Send two external test messages:
Test A: Send to a known valid mailbox.
Expected: Delivered
Test B: Send to a completely fabricated recipient at the same domain.
Expected: Rejected/Bounced
If both tests behave correctly, your domain is functioning as intended.
Conclusion
If your organization wants to receive email only on specifically authorized Google Workspace addresses, you should avoid catch-all routing for unknown recipients.
The key configuration areas are:
Google Admin Console → Apps → Google Workspace → Gmail → Routing
and:
Google Admin Console → Apps → Google Workspace → Gmail → Default routing
Review and disable any rule that redirects Unrecognized/Catch-all recipients to another mailbox when that behavior is no longer required.
After configuration, your intended mail flow should be:
Authorized user → ACCEPT
Authorized alias → ACCEPT
Authorized Google Group → ACCEPT according to Group settings
Unknown/non-existent address → REJECT
This creates a cleaner and more controlled Google Workspace email environment where only addresses intentionally configured by the administrator function as valid email destinations.
Tags
#GoogleWorkspace #GoogleWorkspaceAdmin #Gmail #GmailAdmin #GoogleAdmin #EmailSecurity #EmailRouting #GmailRouting #CatchAllEmail #DisableCatchAll #UnknownRecipient #InvalidRecipient #EmailBounce #EmailAdministration #BusinessEmail #GoogleWorkspaceSecurity #GmailSecurity #EmailConfiguration #MailRouting #GoogleAdminConsole #WorkspaceAdmin #EmailTroubleshooting #GmailTroubleshooting #EmailAlias #GoogleGroups #DomainEmail #CorporateEmail #EmailManagement #MailServer #InboundEmail #RecipientValidation #EmailPolicy #EmailDelivery #GmailDelivery #WorkspaceSecurity #EmailBestPractices #GoogleWorkspaceGuide #GmailGuide #EmailAdministrator #EmailDomain #CatchAllMailbox #GmailCatchAll #RejectUnknownEmail #RejectInvalidRecipient #AuthorizedEmail #WorkspaceRouting #DefaultRouting #GoogleWorkspaceTips #GmailSettings #EmailInfrastructure
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.