Skip to content

Forwarders and parked domains

A forwarder is an address on your free subdomain or one of your verified domains — support@acme.singlesign.com or support@acme.com, sales@, dmca@, billing@ — with no mailbox behind it. Mail sent to it is delivered to one or more destinations you choose: company mailboxes, members' personal mailboxes, or addresses outside SingleSign. A parked domain is an extra domain whose addresses mirror one of your primary domains, so ana@acme.co reaches the same mailbox as ana@acme.com. Both are run from the organization console — forwarders in the Forwarders section, parking from Domains — and both need the Manage domains permission (Owners, Admins and the Domains admin role); seeing them needs View domains, which an Auditor has too. See Admin roles and permissions.

Two things a forwarder is not. It isn't a shared inbox: every destination gets its own copy of each message, and nobody sees whether a colleague replied. And it isn't the Forward action on a company mailbox, which sends one person's mail on to a colleague while they're away or after they leave — that lives in Company mailboxes.

Forwarders

The Forwarders section sits after Domains in the console: "support@, dmca@, billing@ and other addresses with no mailbox behind them — each delivers to one or many people, or to an outside address that confirms first." Its header counts them against your plan ("2 of 3 forwarders" on the free tier). Forwarders live on a verified domain — until you have one, the button is off with "Verify a domain first — forwarders live on it." — and the organization's checklist card offers "Set up support@ and other role addresses" as soon as a domain is verified and no forwarder exists yet.

Adding one

"Add forwarder" opens the "Add a forwarder" dialog — "An address with no mailbox behind it. Mail sent to it fans out to every destination you pick — a person, a few people, or an outside address."

  • Address @ Domain — "Just the part before the @ — lowercase letters, numbers, dots, hyphens." The domain list holds your verified domains; a parked domain isn't offered ("acme.co is a parked domain — a forwarder on the primary domain also answers there, so it is not listed."). Once the name is valid the hint reads "Mail to support@acme.com will be forwarded."
  • Common role addresses — one-click chips for support@, sales@, info@, dmca@, security@, legal@, privacy@ and billing@, each with its purpose on hover. The same chips greet you while the section is empty ("No forwarders yet — the usual role addresses are one click away.").
  • Delivers to — the destinations, explained next.
  • Screener — Inbox or Screen like personal mail, below.
  • Outside delivery — Automatic, Keep the original sender or Send as the forwarder, below.

Names follow the same rules as addresses, and a name belongs to one thing on a domain. A forwarder can't take a name a company mailbox or alias already holds ("That address already belongs to a company mailbox or one of its aliases — a forwarder cannot take it."), and while a forwarder holds a name — paused or not — it can't be given as an address either ("That address is already in use."); deleting the forwarder frees it. The system addresses every domain gets are ours ("That name is reserved for the system (postmaster, abuse, bounces and friends) — pick another."); support@, sales@, admin@ and the other role names on your own domain are exactly what forwarders are for. One forwarder per address: "A forwarder with that address already exists — edit it instead."

Delivers to

The "Delivers to" picker ("Pick a mailbox or type an address") lists the organization's company mailboxes and the members' personal mailboxes as soon as it has focus, and turns anything else you type into an outside address — "Send to sam@example.com · Outside address — it gets a confirmation e-mail and receives nothing until it says yes." The line under the field is the whole rule: "Company mailboxes and members' personal mailboxes receive right away. Any other address gets a confirmation e-mail first and receives nothing until it says yes."

A destination can never be another forwarder ("A forwarder cannot deliver to another forwarder — pick a mailbox or an outside address."), a suspended mailbox isn't offered, a SingleSign mailbox that is neither a company mailbox of this organization nor an active member's personal one can't be picked, and the same mailbox counts once however you name it ("That destination is already on this forwarder.").

Every destination has a state — a dot on its chip, with the detail on hover:

StateWhat it means
ActiveReceiving mail directly (a mailbox) or Confirmed — receiving forwarded mail (an outside address).
ConfirmingWaiting for this address to confirm by e-mail — nothing is forwarded there until it does.
BouncingBounced 3 times in 7 days — paused. The destination's mail server refused our messages three times in seven days; we stopped sending there and told the admins.
DisabledSwitched off — nothing is forwarded here. The address declined the confirmation.

Outside addresses confirm first

An outside address receives nothing until the person behind it says yes — the same rule Google applies to its forwarding, and the thing that stops a forwarder being used to flood someone. Add one and the forwarder is created right away with that destination reading Confirming ("support@acme.com set up — one outside address confirms by e-mail before receiving anything"). The address gets an e-mail with the subject "Deliver mail for support@acme.com to you?": "Acme Inc. wants to deliver mail sent to support@acme.com to this address (sam@example.com). If that's fine with you, confirm here (the link works for 7 days)" — and, for anyone who doesn't know you: "open the same link and choose Decline — nothing will be sent to you, and the organization is told."

The link opens a page on email.singlesign.com — no sign-in needed — headed "Forward mail to you?", naming the organization, the forwarder and the address, with the promise spelled out: "Nothing is forwarded until you confirm. Spam and mail that fails authentication are never forwarded; if your mail server refuses messages three times in a week, forwarding pauses and the organization is told." "Confirm forwarding" turns it to "Forwarding confirmed" — "Mail sent to support@acme.com now reaches sam@example.com. Acme Inc. can stop it at any time, and you can ask them to." — and the destination becomes Active. "Decline" gives "Forwarding declined" ("Acme Inc. was told."): the destination becomes Disabled and the admins get a notification. A link is good for 7 days and one answer; afterwards the page says "This link has expired", and an admin can send a fresh one with "Resend" in the forwarder's Edit dialog — once every ten minutes ("A confirmation e-mail went out to that address recently — try again in ten minutes.").

The Screener

Every forwarder decides how the Screener treats strangers writing to it; its row shows Inbox or Screened.

  • Inbox (the default) — "Strangers are expected here — first-time senders skip the Screener and land in the inbox; spam and mail that fails authentication are still filtered, and blocked senders stay blocked." Nobody who writes to support@ is added to anyone's contacts, and each recipient's own decisions still hold: a sender you've blocked is still discarded, one you've screened out stays out.
  • Screen like personal mail — "First-time senders wait in each recipient's Screener until that person lets them in, exactly as mail to their own address would."

Colleagues are colleagues either way — mail between members skips the Screener as usual. More in The Screener for businesses.

Outside delivery — what the sender line becomes

When a destination is outside SingleSign, we hand the message on from our servers on behalf of your domain, and it has to pass the destination's own SPF and DMARC checks — which is why your domain's records matter here (see Domains and DNS records). Outside delivery decides what the destination sees as the sender — "How mail is handed to destinations outside SingleSign. Spam and mail that fails DMARC are never forwarded outside."

  • Automatic (the default) — "Keeps the original sender when their message arrived with a valid, aligned DKIM signature, otherwise sends as the forwarder — the safest choice for delivery."
  • Keep the original sender — "The message goes out untouched under the original From; it passes DMARC at the destination only when the sender signed it with DKIM, so unsigned mail can land in spam or be refused."
  • Send as the forwarder — "From becomes "Name via support@acme.com" with Reply-To set to the original sender, signed with your domain — always authenticated, but the sender shows as the forwarder."

In plain words: a message that arrived from the internet with a valid DKIM signature matching its sender's domain can go on exactly as it came, and the destination sees the original sender. Everything else — an unsigned message, a signature for some other domain, and always mail sent by SingleSign users, colleagues included, because it reaches the forwarder through our own relay rather than from the internet — goes out as the forwarder: From becomes "Sam Jones via support@acme.com" <support@acme.com>, Reply-To is the original sender (unless they set a Reply-To of their own), the original From is kept in an X-Original-From header, and the message is signed with your domain's DKIM key. Replying still reaches the person who wrote. In either mode two trace headers are added (X-SingleSign-Forwarded-For, X-SingleSign-Forward-Hops) and nothing else in the message is touched.

What is never forwarded outside, in any mode:

  • Spam and mail that fails authentication. A message our checks judged spam, or that failed DMARC, stays inside — destinations in SingleSign still get it in their Spam folder — and never leaves for an outside address. Your domain's reputation is worth more than one message.
  • Beyond the daily budget. An organization may forward 200 messages a day outside on the free tier and 5,000 a day on SingleSign Business. Past that, outside copies are dropped for the rest of the day — mailboxes in the organization still receive — and the admins are told once, under the bell and by e-mail.
  • To a bouncing address. A destination whose mail server refuses our messages three times in seven days is paused: it reads Bouncing, and the admins are notified. Once the problem at the other end is fixed, remove the destination and add it again (an outside address confirms again).
  • A second hop. Mail that already went through a forwarder is never forwarded outside again, so two forwarders can't loop.

Outside copies go through SingleSign's own sending path and never count against any member's sending limits. A forwarder that delivers only to outside addresses stores none of its mail in SingleSign — each message is passed on and the copy discarded.

Pause, edit, delete

Each row shows the address, its destinations, the Screener and Outside delivery settings, and Active or Paused, with the last 24 hours under the address — "12 delivered · 3 forwarded outside · 1 bounced", or "Quiet — nothing in the last 24 h".

  • "Pause" — "support@acme.com paused — mail to it is held, nothing bounces." Mail sent to it while paused is held on our side — never bounced back to the sender — and reaches no destination; "Resume" lets new mail flow again.
  • "Edit" — the "Edit support@acme.com" dialog: "Destinations change right away. An outside address you add gets a confirmation e-mail and receives nothing until it says yes." Add a destination, Remove one (a forwarder keeps at least one — "delete the forwarder instead"), "Resend" a pending confirmation, or switch the Screener and Outside delivery settings; every change is saved as you make it. The address itself can't be renamed — delete the forwarder and add a new one.
  • "Delete" — "Delete support@acme.com?": "Mail sent to support@acme.com is no longer delivered anywhere — senders are not told. The destinations keep their own mail." The name is free again for a mailbox, an alias or a new forwarder.

Every change — and every destination confirmed, declined or paused — is written to the organization's audit log. Removing a domain removes its forwarders with it, and so does deleting the organization.

The catch-all — SingleSign Business only

Below the table, a Catch-all row per domain reads "Anything else @acme.com goes to …" the destinations you chose — or "is not delivered anywhere" while it's off — with the rule underneath: "Only when no mailbox, alias or forwarder owns the name — named addresses always win." Switch it on and the "Catch-all for acme.com" dialog says what it does — "Everything sent to a name @acme.com that nobody owns — no mailbox, alias or forwarder — goes to the destinations below. Named addresses always win." — then takes the destinations and the two settings like any forwarder, and "Set up catch-all". It appears in the table as Anything else @acme.com; switching it off deletes it ("Mail to unknown names @acme.com is no longer delivered anywhere. Named addresses are not affected."). Without a catch-all, mail to a name nobody owns isn't delivered — and the sender isn't bounced.

One catch-all per domain, and it's part of SingleSign Business: on the free tier the row says so — "The catch-all is part of SingleSign Business — the free plan forwards named addresses only." — with a link to the pricing table. A catch-all on the primary domain answers for its parked domains too.

Plan limits

Free tier (every organization today)SingleSign Business
Forwarders3No limit
Outside destinations per forwarder110
Catch-all—Included
Outside forwards a day2005,000

Mailbox destinations don't count towards these — a forwarder can deliver to as many company and personal mailboxes as you like. When an allowance is used up the console says so before you try: "Your plan includes 3 forwarders and every one is in use — SingleSign Business has no limit.", "Your plan allows 1 outside destination per forwarder — SingleSign Business allows 10." Until billing opens every organization is on the free tier; see Plans and pricing.

What recipients see

A message that arrived through a forwarder carries a "to support@acme.com" chip on its row and in the conversation header ("Arrived through support@acme.com — click to see everything sent to it"), so someone who receives both support@ and billing@ can tell them apart. Clicking the chip searches to:support@acme.com — the search box understands the to: token and narrows the list to what arrived through that address; the rest of the query stays free text. Aliases and parked-domain mirrors get the same chip; a message sent to your own address shows none.

Replies go out from your own address — a forwarder has no mailbox and can't be sent from. If someone needs to answer as support@, make it an alias on their company mailbox instead (a name can't be both — see Company mailboxes).

Every member sees which forwarders point at them under Settings → Mail → "Addresses that reach you" — in every mailbox of theirs, the personal one included: "Forwarders an organization pointed at this mailbox. Mail sent to them lands here; the organization's admins set them up and can stop them — ask them if one should not reach you." Each row names the forwarder (or Anything else @acme.com), the organization, and how it's screened — Straight to inbox or Screened like your mail. Nothing here changes a forwarder; that's the admins' job.

Parked domains

A parked domain mirrors a primary domain: every active address of the primary — company mailbox addresses, aliases, forwarders, the catch-all and the system addresses — also receives mail as @acme.co. The parked domain has no addresses of its own, and mail is always sent from the primary: nothing ever goes out as @acme.co. It's the right tool for the .co you bought beside the .com, the old company name, or the misspelling customers keep typing.

Parking one

Add and verify the extra domain like any other — see Domains and DNS records. Once it's verified, carries no addresses, and there's another verified domain to park it onto, its card in Domains offers "Park onto…". The "Park acme.co" dialog has a "Park onto" picker of your primary domains and the plain terms: "Every address of acme.com — company mailboxes, aliases, forwarders and the system addresses — also receives mail as @acme.co. Mail still goes out from acme.com; nothing is sent as @acme.co. The MX, SPF, DKIM and DMARC records for acme.co stay required, so inbound mail and bounces keep working." A domain that still carries addresses can't be parked — "acme.co still has 2 addresses of its own. A parked domain carries none — move or remove them first, then park it."

Once parked, the card wears a "Parked on acme.com" chip and reads mirrors acme.com; the primary's card reads mirrored by acme.co. Neither the address forms nor the forwarder dialog offer a parked domain — its names are the primary's. "Unpark" reverses it: "Mail to @acme.co stops mirroring acme.com — names that only existed as mirrors are no longer delivered. The domain keeps its records and can carry addresses of its own again."

The rules

  • Both domains must be verified, and the parked domain still needs its MX, SPF, DKIM and DMARC records — MX so mail for it reaches us, the rest so bounces and reports for it authenticate. Its checklist and its own DKIM key stay as they are, and the usual checks and notices apply.
  • No chains. A domain can't be parked onto a parked domain ("That domain is itself parked on another one — park onto the primary domain instead."), a domain with domains parked on it can't itself be parked, and a domain is parked on one primary at a time ("That domain is already parked on another domain — unpark it first.").
  • Suspending the primary silences its parked domains too; removing the primary unparks them — they become domains of their own again, with no addresses.
  • What recipients see: a message that arrived as ana@acme.co shows "to ana@acme.co" on its row; replies and automatic away replies go out from the mailbox's own address on the primary.
  • No limit on parked domains, on any plan.

Last updated: 2026-09-11