This may be a bit lengthy, but please bear with me.
I started to have a flood of “bounced” emails appear on catch-all email account a few weeks ago. They were all returned to non-existent addresses on my domain. When I carefully opened at a few of the original messages, they were obviously spam sent to what appeared to be legitimate addresses from what appeared to be non-existent addresses on my domain. The non-existent addresses were 3-6 random characters long.
I immediately changed all of the passwords on my domain and email accounts, but the bounces continued.
Digging deeper, I reviewed the prior email in my catch-all account. I found a pattern of emails from about a week before the flood of bounces. I had received about 10 emails to the non-existent account thisisjusttestmessageatall@<my domain>.com over a 12 hour period. Each one claimed to be from a different, seemingly legitimate email addresses. Each message was received and no responses or bounce notices were sent. When I carefully opened them, each one contained 3 short lines of random phrases.
A few weeks before that, I transferred my stealthed domain account from another registrar to LP (still stealthed ). I do not mean imply any link, but I do not rule it out either and I include the info in case it’s useful to anybody else.
I use a combination of methods to avoid spam and track who has which of my email addresses and the catch-all account helped. Having the continuous flood of bounced emails is not acceptable.
Perhaps worse, it appears that someone is claiming to be originating spam from my domain. That is not acceptable either.
What happened? (fact mixed with theory)
1) My registrar change got logged someplace public. I don’t know where.
2) A spammer harvested the domain name from the public place.
3) The spammer probed the domain looking for a catch-all account using: thisisjusttestmessageatall@<my domain>.com.
4) When the emails did not bounce after about 5 days (the probe requires the delay due to the way mailers work), the spammer had a domain with a catch-all account.
5) Spam was generated with doctored headers to appear to come from my domain.
What did I do?
1) I changed my catch-all account to :fail: to deny future probes and to end the bounce flood.
2) I changed part of my email strategy to include forwarders.
3) I started using SpamAssassin (probably won't help in this case)
Is this chance or did I cause an issue for LP? A couple days after I made my changes, I get a notice from LP that they are moving my account to another server.
Kudos to:
I didn't see "don't use catch-all addresses".
I theorize that catch-all accounts are valuable to spammers because it is more difficult to verify if an email account exists or not. This allows spammers to evade filter services that check for the validity of the return address (Comments? Is this premise reasonable?).
Kudos to:
oh bye the way. the setting on the default address should be set to :fail: not :blackhole: blackhole can cause problems. jmho

(I assume “default” was intended to be “catch-all”)
and lemons to
One more word of advice. If you have set your Default Address to :fail: change it to :blackhole:
From the probe’s point of view, a catch-all blackhole is the same as email received.
Does any of this make sense?