Email forwarders are one of the most useful and most misunderstood features on your Ultra Web Hosting account. A forwarder lets you send mail arriving at one address off to another address without keeping a mailbox at all, and a catch-all can sweep up everything sent to your domain. Both are handy in the right situation and quietly harmful in the wrong one. This guide covers how to set up forwarders and catch-all addresses in cPanel, when each is the right tool, and the deliverability traps that make forwarded mail land in spam or bounce outright.
- Forwarder vs Mailbox vs Alias: What Is the Difference
- Create a Single Forwarder in cPanel
- Forward One Address to Several Recipients
- Forward an Entire Domain
- Set a Catch-All or Default Address
- Why a Catch-All Is Usually a Bad Idea
- The Deliverability Catch With Forwarding
- When to Use a Real Mailbox Instead
- Troubleshooting Forwarders
A Forwarder Relays, a Mailbox Stores
A forwarder takes mail sent to one address and passes it to another. It stores nothing, uses no disk quota, and cannot be logged into. Reach for a forwarder when you want an address that lands somewhere you already read mail. Reach for a real mailbox when you need to store, send from, or log into the address.
- Forwarders live under cPanel Email > Forwarders
- They forward one address, several addresses, or a whole domain
- A catch-all (Default Address) sweeps up everything else
- Forwarding to Gmail or Outlook can break authentication, so read Section 07 first
Catch-All Is a Spam Magnet
A catch-all address accepts mail for every possible name at your domain, including the thousands of random and mistyped addresses spammers guess at. Turn one on and it fills with junk within days, and worse, it can make your server generate backscatter that harms your sending reputation. The safe default is Discard with an error to sender, not Catch-All. Section 06 explains when a catch-all is genuinely worth the trouble.
- Symptom: a flood of spam to addresses you never created
- Cause: the domain accepts mail for any local part
- Fix: set the Default Address to Discard with an error, not to a mailbox
01. Forwarder vs Mailbox vs Alias: What Is the Difference
These three terms get used interchangeably, but they behave differently, and picking the wrong one is the root of most forwarding confusion.
- A mailbox is a real account with a password and disk storage. You log in with Webmail, Outlook, or your phone. It receives mail, keeps it, and can send mail from that address. It uses your account's disk quota.
- A forwarder stores nothing and has no password. Mail arriving at the forwarder address is immediately relayed to one or more other addresses and then it is gone from our server. You cannot log into a forwarder, and you cannot send mail from it on its own.
- An alias is the term some mail systems use for a forwarder that points at a local mailbox, effectively giving one mailbox a second name. In cPanel the mechanism is the same forwarder feature. If you want a second address that drops into an existing mailbox, you create a forwarder from the alias to that mailbox.
If you need to keep mail on the server, log into the address, or send outbound mail from it, you want a mailbox, not a forwarder. Creating mailboxes and aliases is covered in How to Create Email Accounts and Aliases.
Relays and Forgets
Good for pointing an address at somewhere you already read mail. No storage, no login, no quota used.
- Stores nothing on our server
- No password, cannot be logged into
- Cannot send mail from the address by itself
- Can break SPF and DKIM at the destination
Stores and Sends
Good for any address you actually work from. Keeps mail, has its own login, and sends outbound cleanly.
- Real storage with Webmail and IMAP access
- Own password and login
- Sends outbound mail that passes your SPF and DKIM
- Uses disk quota on your plan
02. Create a Single Forwarder in cPanel
The most common case is forwarding one address to another, for example sending everything for [email protected] to your personal Gmail or to an existing mailbox.
- Log in to cPanel and open Forwarders (under the Email section).
- Click Add Forwarder.
- In the Address to Forward field, type the local part of the source address, for example
sales, and select the domain from the dropdown. - Leave Forward to Email Address selected, and enter the full destination address, for example
[email protected]or an existing mailbox on your domain. - Click Add Forwarder.
That is the whole job. Mail sent to the source address now relays to the destination immediately. Nothing is stored on our server, so if the destination stops accepting mail, the forwarded messages bounce rather than pile up somewhere.
You can forward an address to a mailbox that already exists on the same domain. This is how you give one inbox a second name without paying for a second account. Create the mailbox first, then forward the extra address to it.
03. Forward One Address to Several Recipients
Sometimes you want one address, say [email protected], to reach a whole team. There are two clean ways to do this in cPanel.
Add Several Forwarders on the Same Address
You can create more than one forwarder with the same source address. Each one sends a copy to a different destination.
- In Forwarders, click Add Forwarder.
- Enter the same source, for example
support, and forward it to the first person,[email protected]. - Repeat Add Forwarder with the same
supportsource, forwarding to[email protected], and so on for each recipient.
Every message to [email protected] now reaches all of them. This is simple, but each recipient gets their own copy and there is no shared history, so replies can get duplicated.
Forward to a Mailing List or Group
For a team address where everyone should see the same thread, a Mailing List is a better fit than a pile of forwarders. cPanel includes a Mailing Lists feature (Mailman) under the Email section. Create the list, add the members, then either give out the list address directly or forward your friendly address to it.
Fan-out forwarding (one address to many) multiplies any spam or deliverability problem across every recipient. If the source address is public and gets a lot of junk, filter it before it fans out, or point it at a single shared mailbox instead. See How to Reduce Spam for filtering options.
04. Forward an Entire Domain
Domain forwarding relays mail for every address at one domain to the matching address at another domain, one to one. If someone writes to [email protected], it goes to [email protected]. This is the right tool after a rebrand, or when you own several spellings of a name and want them all to feed one primary domain.
- In cPanel, open Forwarders.
- Scroll to the Forward All Email for a Domain section (below the address forwarders) and click Add Domain Forwarder.
- Select the source domain from the dropdown, for example
olddomain.com. - In Forward to Which Domain, enter the destination domain, for example
newdomain.com. - Click Add Domain Forwarder.
The mapping is strictly one to one on the local part. [email protected] becomes [email protected], [email protected] becomes [email protected], and so on. The destination domain needs a real mailbox (or its own forwarder) for each name you expect to receive, or those messages will bounce at the far end.
Because it accepts every local part, a domain forwarder inherits the same spam problem as a catch-all: it relays mail for names that were never real, including whatever spammers guess. Read Section 06 before you rely on one for a busy domain. For a small, low-traffic domain it is usually fine.
05. Set a Catch-All or Default Address
The Default Address feature in cPanel decides what happens to mail sent to an address that does not exist on your domain. By default it is set to discard unroutable mail. You can instead point it at a mailbox, which turns it into a catch-all that collects everything not matching a real account or forwarder.
- In cPanel, open Default Address (under the Email section).
- Select your domain from the dropdown.
- To make a catch-all, choose Forward to Email Address and enter the mailbox that should collect the overflow, for example
[email protected]. - To do the safe thing instead, choose Discard with error to sender and enter a short message such as
No such user here. - Click Change.
Read the next section before you choose the catch-all option. In most cases the discard setting is what you want.
If you do run a catch-all, aim it at a dedicated local mailbox you can filter and empty, not at your personal Gmail. Sending a domain's worth of guessed spam onward to an external provider is a fast way to hurt your forwarding reputation. Keep the mess contained where you can manage it.
06. Why a Catch-All Is Usually a Bad Idea
On paper a catch-all sounds convenient: you never miss a message, even to a mistyped address. In practice it is one of the fastest ways to drown an inbox and damage your mail reputation.
Spammers do not need to know your real addresses. They run dictionary attacks, sending to info, admin, john, sales2019, and thousands of other guesses at your domain. With no catch-all, all of those bounce harmlessly. With a catch-all, every single one lands in the collecting mailbox. A domain that had three real addresses can suddenly receive junk for hundreds of imaginary ones.
There is a second, quieter problem: backscatter. If your catch-all forwards onward and the far end later rejects the spam, the bounce can come back to forged innocent senders, making your server look like a spam source. That harms deliverability for your real mail too.
Leave the Default Address on Discard with error to sender. Legitimate senders who mistype an address get a clear bounce telling them the address does not exist, which is exactly what you want. They fix the typo and resend. You keep your inbox clean and your reputation intact.
When is a catch-all genuinely useful? A few real cases:
- Short-term migrations, where you are still discovering which old addresses people actually used and want to see them before recreating each one.
- Per-vendor addresses, where a technical user hands out a unique address to each service (
amazon@,bank@) to track who leaks their data, and wants unplanned ones to still arrive. - Very low-traffic personal domains that no spammer has found yet, where the convenience outweighs the risk.
Even in those cases, point the catch-all at a dedicated, filtered mailbox and revisit it often. If it fills with junk, switch back to discard.
07. The Deliverability Catch With Forwarding
This is the part that surprises people. Forwarding mail to Gmail, Outlook.com, or another big provider can cause the forwarded message to be marked as spam or rejected, even though the original was perfectly legitimate. The cause is email authentication.
When a message arrives at your domain and you forward it on, our server sends it to the destination, but the From address is still the original sender, not you. The receiving provider checks SPF against the original sender's domain and sees our server sending on their behalf, which fails SPF. It checks DKIM, and if forwarding altered the message at all, that can fail too. The result is a message that looks unauthenticated.
Modern mail systems soften this with SRS (Sender Rewriting Scheme), which rewrites the envelope sender so SPF passes on the forwarding hop. Our mail servers apply SRS, which helps, but it does not fully solve DMARC alignment for every sender. Some strict-policy domains will still have their forwarded mail quarantined at the far end.
If you rely on receiving mail that must never be lost (client work, legal, billing), do not forward it to Gmail or Outlook and hope. The cleaner fix is a real mailbox at the destination provider, or a real mailbox here that you check directly. Forwarding is fine for low-stakes convenience; it is the wrong tool for mail you cannot afford to lose to a spam folder.
Practical guidance:
- For a personal address you glance at occasionally, forwarding to Gmail is fine. Check the spam folder now and then.
- For business mail, create a real mailbox and pull it into your client with IMAP, or set up the account at your preferred provider directly rather than forwarding.
- Make sure your domain has correct SPF, DKIM, and DMARC records regardless. See How Do I Change My MX Records for the DNS side.
08. When to Use a Real Mailbox Instead
Forwarders are the right answer less often than people assume. Create a real mailbox instead whenever any of these is true:
- You need to send mail from the address. A forwarder only relays inbound. To send as
[email protected]you need a mailbox with a login. - The mail matters and must not be lost. Mailboxes store on the server and survive a destination outage. Forwarders bounce when the destination is down.
- You want the mail authenticated. Outbound from a real mailbox on your domain passes your SPF and DKIM cleanly. Forwarded mail carries the original sender and can fail authentication.
- You need history or shared access. A mailbox keeps a searchable record. A forwarder keeps nothing.
A good rule: if the address is a real person or role that works from that identity, give it a mailbox. If the address is a pointer that should quietly land somewhere else you already read, a forwarder is fine. Creating mailboxes is covered in How to Create Email Accounts and Aliases.
09. Troubleshooting Forwarders
Forwarded mail is bouncing. The forwarder relays to whatever destination you set, and if that destination rejects the message, the sender gets the bounce. Confirm the destination address is correct and active. If you are forwarding to Gmail or Outlook and only some messages bounce, it is likely the authentication issue in Section 07, not the forwarder itself.
Forwarded mail lands in the destination's spam folder. Almost always the SPF and DKIM problem from Section 07. Our SRS handling helps, but strict DMARC policies at the original sender's domain can still trip. For important mail, use a real mailbox rather than forwarding.
A mail loop between two forwarders. If [email protected] forwards to [email protected] and b forwards back to a, mail bounces between them until the server detects the loop and rejects it. Fix the forwarders so mail has a single, final destination. This also happens if a forwarder points at an address that itself forwards back into the chain, so map out the full path.
Mail to a nonexistent address gets a 503 or RCPT error. An error such as 503 valid RCPT command must precede DATA or a rejection at the recipient stage usually means the address does not exist and there is no catch-all, which is the correct, safe behavior. See Error 503 valid RCPT command must precede DATA for the details on that specific message.
The forwarder was created but nothing arrives. Check that mail for the domain is actually delivered to our server, not to an external mail host. If your MX record points elsewhere (Microsoft 365, Google Workspace), forwarders in cPanel do nothing because our server never sees the mail. For anything email-related this guide does not cover, see the Email Troubleshooting Guide.
Not Sure Whether You Need a Forwarder or a Mailbox?
Tell us what you are trying to do with the address and we will set up the right thing, whether that is a single forwarder, a domain forwarder, a filtered catch-all, or a proper mailbox. If forwarded mail is landing in spam, we can check your SPF, DKIM, and DMARC and sort out the deliverability side.
Open a Support TicketQuick Recap: Forwarders in Six Points
If you only take six things from this guide, take these:
- A forwarder relays and stores nothing; a mailbox stores, logs in, and sends. Pick by what the address needs to do.
- Add a single forwarder under cPanel Email > Forwarders > Add Forwarder, source address to destination address.
- Fan out to a team with several forwarders on one source, or point it at a Mailing List for a shared thread.
- Domain forwarding maps one to one; it behaves like a catch-all, so use it only on low-traffic domains.
- Leave the Default Address on Discard with error, not Catch-All, because a catch-all is a spam magnet that can cause backscatter.
- Do not forward important mail to Gmail or Outlook; SPF and DKIM can fail on the hop, so use a real mailbox for anything you cannot lose.
Last updated July 2026 · Browse all Email and Webmail articles
