When a breach disclosure or paste site lists many email addresses at your custom domain, it can feel like your whole online identity is on display. The right response is different from a normal “one-account” breach: this situation can point to domain-wide exposure, password reuse risks, and a spike in phishing, spoofing, and account takeover attempts. Use this guide to confirm what actually leaked, contain immediate risks, and harden your domain and accounts for the long term.
First, Understand What “Multiple Addresses” Really Means
Seeing dozens of addresses at your domain does not necessarily mean dozens of accounts were compromised. Breach corpuses often include:
- Real inboxes and aliases that you created (e.g., jane@yourdomain.com, billing@yourdomain.com).
- Role addresses that are common guesses (info@, admin@, support@) added by attackers or mailing lists.
- Old or decommissioned aliases that still forward somewhere.
- Nonexistent addresses created by guesswork, typo harvesting, or dictionary attacks.
Your goal is to separate active, owned mailboxes and aliases from noise, then match any compromised addresses to the services they access.
Verify the Leak and Scope the Impact
- Collect the address list. Copy the full set of leaked addresses and deduplicate it. Keep a private working file with a timestamp.
- Mark each address as real, alias, role, or unknown. Use your domain admin console, email provider settings, and DNS/provider records to confirm which addresses actually exist or forward.
- Check if passwords or data accompany the emails. If the breach includes password hashes or plaintext credentials, treat it as critical for any address you control. If it’s emails only, expect targeted spam and phishing but not necessarily account takeovers.
- Map addresses to services. For each address you own, list the services where it’s used for login or recovery. Prioritize financial, shopping, cloud storage, and social accounts.
- Look for reuse patterns. If multiple leaked addresses were used with the same or similar passwords, raise the urgency level.
Containment: Actions to Take in the First 24–48 Hours
- Disable or remove unneeded aliases. Immediately delete forwarding rules and catch-all behaviors for any addresses you don’t use. This cuts off a major phishing and spam vector.
- Turn off catch-all mailboxes. If your domain accepts mail to any address, disable the catch-all. Attackers abuse this to test and deliver phishing to arbitrary names.
- Reset passwords on high-risk accounts. For any leaked address you actually use, change the password on the service account itself. Use unique, long passphrases generated by a manager. Do not reuse passwords across services.
- Enable strong multi-factor authentication (MFA). Turn on app-based or hardware key MFA for logins tied to exposed addresses. Avoid SMS MFA when possible; use authenticator apps or security keys.
- Update recovery channels. Replace recovery emails and phone numbers that point to leaked addresses, weak mailboxes, or shared team inboxes.
- Monitor domain email flow. Review inbound logs or your provider’s analytics for surges in bounces, forwards, or phishing indicators.
- Alert your household or team. If multiple people use the domain, explain the risk and share a short checklist: don’t click links in unexpected emails, verify senders out-of-band, and report suspicious messages.
Harden Your Domain Configuration
A strong domain posture reduces spoofing, phishing success, and delivery of unwanted messages.
- SPF: Publish an Sender Policy Framework (SPF) record that authorizes only the services you actually use to send mail. Remove legacy or unknown senders.
- DKIM: Enable DomainKeys Identified Mail (DKIM) signing for all real sending services (e.g., your mail host, newsletter platform). Rotate keys if you’ve migrated providers.
- DMARC: Deploy DMARC in monitoring mode (p=none) first, then move to enforcement (p=quarantine or p=reject) once you understand legitimate senders. Use rua/ruf addresses dedicated to reports.
- Disable directory-style address discovery: If your provider supports it, block SMTP VRFY/EXPN equivalents and disable features that auto-create aliases or accept mail to non-existent users.
- Audit third-party senders: Remove old marketing or CRM tools that still appear in DNS. Each extra sender increases misconfiguration and spoofing risk.
- No catch-all policy: Keep catch-all disabled long term. Create unique, purpose-built aliases instead.
Clean Up and Rationalize Your Address Inventory
Leaked address sprawl often reveals how many aliases have accumulated over the years. Make them work for you:
- Maintain a master inventory. Track each address, its owner, purpose, and connected services.
- Use per-site aliases with a naming scheme. For example, store purchases as store-amazon@yourdomain.com. If an alias leaks, you instantly know the source and can deactivate it.
- Tie risky activities to hardened mailboxes. Use separate, well-protected addresses for banking, tax, and healthcare.
- Decommission stale aliases. Forward temporarily for 30–60 days, then remove. Update services with current addresses before deletion.
- Standardize role accounts. If you must keep info@, support@, or billing@, protect them with MFA, restricted access, logging, and clear ownership.
Protect Accounts Linked to Exposed Addresses
Even if passwords weren’t included, exposed addresses attract credential-stuffing and social engineering. Reduce your attack surface:
- Password manager and unique passwords: Store strong, unique passwords for every account. Replace any reused or weak credentials.
- MFA everywhere feasible: Prioritize app-based or hardware key MFA for critical accounts.
- Review and limit API tokens and app passwords: Revoke unused API keys, OAuth grants, and app-specific passwords tied to leaked addresses.
- Rotate IMAP/SMTP app passwords: If you use app passwords on desktop or mobile clients, regenerate them and remove old devices.
- Check forwarding and filtering rules: Attackers often add hidden forwarding rules. Inspect and remove any rules you didn’t create.
- Update security questions and recovery options: Replace guessable answers with random passphrases stored in your manager.
Detect and Respond to Phishing and Spoofing
Expect a spike in messages that look like they are from you or to you:
- Verify unexpected requests by contacting the sender through a known channel before acting.
- Hover before you click: Inspect URLs; prefer direct navigation to known sites instead of clicking links in messages.
- Attachment discipline: Treat unsolicited attachments as suspicious, especially from role accounts.
- Report and block: Use your provider’s spam/phishing reporting. Consider quarantine policies combined with DMARC enforcement.
- Educate collaborators: Vendors and family using your domain should know how to spot spoofed messages and when to escalate.
When the Leak Includes Passwords
If the dataset includes passwords (plaintext or cracked hashes) for any of your domain addresses:
- Immediate password resets: Change the password on the affected service and any other account where that password might have been reused.
- Session invalidation: Sign out of all sessions for the affected accounts and revoke API tokens.
- MFA upgrade: Move to app-based or hardware-key MFA if you rely on SMS.
- Check for changes and transactions: Review recent logins, forwarding rules, recovery changes, and financial transactions.
- Audit email filters: Remove any rules that hide attacker replies or confirmations.
Consider Credit and Identity Monitoring
Large breaches can correlate exposed addresses with your name, phone, and other identifiers across multiple datasets. Monitoring can help you spot credit pulls, new accounts, and suspicious activity tied to your financial identity. If you want a single place to track credit changes and identity-related alerts while you lock down your domain, consider using a dedicated monitoring service such as SmartCredit for privacy, credit monitoring, and identity protection.
Communicate With Affected Contacts
If clients, family members, or teammates regularly email role accounts or aliases that now attract spam:
- Send a short notice from your primary domain mailbox explaining that you’re tightening security and that unexpected messages may be malicious.
- Publish contact changes on your website if role addresses are changing. Avoid listing full addresses in plain text; use contact forms or obfuscation to reduce harvesting.
- Set temporary auto-replies to deprecated aliases that direct people to updated addresses or your contact page.
Legal and Operational Considerations
- Business domains: If you operate as a business, check any contractual or regulatory duties to notify customers when emails may be abused for phishing.
- Log retention and evidence: Preserve relevant logs (email headers, access logs) for potential reporting, especially if fraud occurred.
- Report criminal activity: If you experience account takeover or financial loss, file reports with your bank and appropriate authorities.
Build a Sustainable, Low-Maintenance Setup
After immediate cleanup, design your domain and email use to be resilient:
- Minimal trusted senders: Keep DNS authorizations lean; remove old services promptly.
- Per-service aliases with lifecycle rules: Create aliases on demand, document where they’re used, and retire them on schedule.
- Quarterly reviews: Reconcile your alias inventory, check DMARC reports, and rotate keys if needed.
- Separation of concerns: Use distinct addresses for high-value services, newsletters, and testing. Don’t mix work and personal recovery channels.
- Backup and incident plan: Document steps to disable catch-all, reset credentials, and notify stakeholders so you can execute quickly next time.
Quick Checklist
- Disable catch-all and remove unused aliases.
- Reset passwords and enable MFA on accounts linked to exposed addresses.
- Lock down domain: SPF, DKIM, DMARC (monitor, then enforce).
- Review forwarding rules, API tokens, and app passwords.
- Inventory aliases and decommission stale ones.
- Watch for phishing and spoofing; educate your contacts.
- Consider identity and credit monitoring to detect downstream fraud.
Conclusion
When a breach names multiple addresses at your custom domain, treat it as a domain-level security event. Confirm what is real, cut off unnecessary mailflows like catch-all boxes, harden DNS and authentication, and reset credentials with MFA on the accounts that matter. Use per-site aliases and a living inventory to keep future exposure contained, and keep an eye on downstream risks such as phishing and financial identity misuse. With a structured response and a cleaner domain setup, you can reduce the immediate noise and make your inbox—and your online identity—much harder to exploit next time.
Good to Know
A single compromised service that had your domain on file can expose dozens of role and alias addresses at once, even if those mailboxes never existed; many breach lists are compiled from guessable or past aliases.