JustEmails
PricingSign inStart free trialStart free
Tutorials··15 min read

Fix Inbound Spam on a Custom Domain (2026)

Stop spam on your custom domain: how Rspamd scoring and greylisting work, and the controls you actually get on a managed host.

By JustEmails Platform Team
Contents
  1. Why Custom Domains Attract Spam
  2. How Rspamd Actually Filters Mail
  3. Step 1: Know Which Dials Are Actually Yours
  4. Step 2: Tighten the Catch-All (Or Kill It)
  5. Step 3: Use Sender Rules Instead of Thresholds
  6. Step 4: Greylisting, and Why First Contact Is Slow
  7. Step 5: The Rules You Set Yourself
  8. Common Mistakes That Make Spam Worse
  9. The First 30 Days
  10. Frequently Asked Questions
  11. Why does my custom domain get more spam than Gmail?
  12. Can I change the spam score thresholds on my JustEmails domain?
  13. Why did mail from a new sender arrive ten minutes late?
  14. How do I stop the same spam reaching a new domain?
  15. Try JustEmails

Last Tuesday, I opened my inbox to 47 unread messages. Eleven were legitimate. The rest: crypto investment pitches, fake invoice PDFs, three offers to sell me my own domain back, and one creative attempt at a Nigerian prince scam updated for 2026 (they're doing AI assistants now, apparently).

Forty-seven messages. Eleven real.

This was a custom domain I'd set up two months ago. Clean WHOIS privacy. No public contact form. I did everything "right." Still got hammered. (I'll admit I spent an embarrassing amount of time wondering if I'd somehow signed up for spam newsletters in my sleep.)

Here's the thing — switching to custom domain email trades Gmail's 15-year spam-filter advantage for control over your own mail. That control comes with work. And honestly? Most tutorials gloss over this part because it's tedious. If you're seeing more spam than you did on a @gmail.com address, it's not because your provider is broken. It's because your domain is new, the filters that would auto-junk a known-bad sender are still giving yours the benefit of the doubt, and spammers have ways of finding you that have nothing to do with how careful you were.

We're the JustEmails team — JustEmails is built by Velocity Digital Labs, and we run Rspamd + ClamAV as the filtering stack across every mailbox. This is what we tell anyone whose inbox is drowning: what the filtering stack does on your behalf, which controls are actually yours, and which habits move the number. If you're still evaluating email hosts, our Google Workspace alternatives comparison covers the full landscape.

Why Custom Domains Attract Spam

Before you change anything, understand the attack surface.

WHOIS records. Even with privacy protection, domain registrations create a paper trail. Registrars get breached. Privacy services have gaps. The moment you register a domain, it's in databases that spammers scrape daily. This isn't paranoia — it's the business model.

Catch-all addresses. If you configured *@yourdomain.com to route to your inbox, congratulations: you're accepting mail to every address spammers can guess. sales@, info@, admin@, and 10,000 variations generated by dictionary attacks. Catch-alls are convenient. They're also a spam magnet. I've made this mistake more times than I'd like to admit — set up a catch-all "just in case," then wondered why I'm drowning a month later. (More on this below.)

Scraped websites. If your email address is anywhere on the public web — contact page, footer, GitHub profile, LinkedIn — bots have it. The scraping-to-spam pipeline runs in hours, not days. A fresh domain with a contact form can start receiving junk within 48 hours of launch.

New domain reputation. Gmail, Outlook, and Yahoo have sender reputation systems that track billions of addresses. Your brand-new domain has no reputation. Filters that would auto-junk something on a known-bad domain give yours the benefit of the doubt. That doubt gets exploited. Understanding how email authentication works helps here — SPF, DKIM, and DMARC won't stop inbound spam, but they're foundational to overall mail hygiene.

None of this means custom domain email is a mistake. It means general-purpose filtering is calibrated for mature domains with established traffic patterns, and a new domain sits outside that calibration for a while. New domains need patience and a few deliberate decisions about how mail reaches you at all.

And yes, that's annoying. Nobody tells you this upfront.

How Rspamd Actually Filters Mail

Most custom domain hosts use Rspamd (open-source, fast, actively maintained) or SpamAssassin (older, slower, still works). JustEmails uses Rspamd with ClamAV for malware scanning. Understanding how scoring works lets you read what is happening to your mail instead of guessing at it.

Rspamd assigns every message a spam score. Higher score = more spam-like. Simple enough. The score comes from hundreds of rules, each contributing positive or negative points:

  • Header analysis. Malformed headers, missing Message-ID, weird character encoding. Legitimate mail rarely has these issues. Spam constantly does.
  • Content rules. Known spam phrases, suspicious URLs, obfuscated text, excessive caps and punctuation. "URGENT: Your account has been compromised!!!" scores high.
  • RBL checks. Real-time blocklists like Spamhaus, Barracuda, SORBS. If the sending IP is on a blocklist, the score goes up. A lot.
  • SPF/DKIM/DMARC results. Failing authentication adds points. Passing doesn't remove points — it just avoids the penalty.
  • Bayesian filtering. Trained on your specific corpus of spam and ham. This is where user feedback actually matters.
  • Greylisting. Not a score — a delay tactic. Rspamd can defer mail from unknown senders temporarily. Legitimate servers retry. Botnets often don't.

Rspamd's stock action bands, for orientation:

ScoreTypical action
0-4Delivered to inbox
4-6Greylisted
6-15Delivered with spam header, client moves to junk
15+Rejected at SMTP level, sender gets bounce

Those are Rspamd's out-of-the-box bands, and they are what most documentation you find online is describing. Every managed host runs its own tuned values and does not necessarily publish them, JustEmails included. Knowing the shape is still worth something: it tells you that "went to junk" and "never arrived at all" are two different events with two different causes, and only one of them leaves you anything to look at.

Step 1: Know Which Dials Are Actually Yours

Before changing anything, find out what you can change. On a managed host, most of the filtering isn't yours to touch — which is mostly good news, because the scoring model is the part that takes continuous work to keep current.

On JustEmails, the spam screen sits under Settings and gives you two things:

  • Quarantine review — the messages filtering held back, there to look through rather than lost silently
  • Sender allow and block rules — per-sender overrides that beat the general scoring in both directions

There is no threshold box, no greylisting toggle and no RBL checklist. Rspamd scoring, the blocklists it consults and the deferral behaviour are all maintained server-side. If you want that level of control, self-hosting Rspamd is the honest answer, and it is a standing commitment rather than an afternoon.

One outbound number belongs alongside all this: the daily send allowance, which runs 20/day for a domain's first week after verification, 200/day for the second, and 500/day from day 15 onward. It's counted per account rather than per mailbox, and it earns a place in a spam-filtering post because replies and auto-responders come out of it — pointing a vacation autoresponder at a catch-all that receives a hundred junk messages a day spends the allowance on spammers.

Then spend ten minutes in the quarantine. You're looking for:

  • Is legitimate mail being held, and from which senders?
  • Is the same junk arriving repeatedly from one domain?
  • Which of your addresses is taking the volume — a named mailbox, or the catch-all?

Step 2: Tighten the Catch-All (Or Kill It)

Look, I get it. Catch-alls are convenient. You can give out invoices@, billing@, whatever, without creating mailboxes. But if you're drowning in spam, the catch-all is usually why.

I'm biased here — I think catch-alls are overrated for 90% of use cases.

Option A: Kill it entirely. Only mail to addresses you've explicitly created gets delivered. Everything else bounces. Most aggressive, most effective. If you don't need info@ to work, delete the catch-all route.

Option B: Route to a spam-tolerant mailbox. Keep the catch-all but send it to a separate mailbox you check weekly for lost mail, not your primary inbox. Treat it as a spam trap with occasional signal.

Option C: Per-address scoring, if your stack offers it. Some self-hosted setups let you hold catch-all matches to a stricter spam score than real mailboxes, discarding anything borderline that was addressed to a name nobody ever created. It works, but it is a self-hosting feature — JustEmails doesn't expose per-address scoring, so on a managed host the real choice is between A and B.

We recommend Option A for most people. Full stop. If you've published 30 different addresses across the web over the years, Option B is the pragmatic middle ground — but you'll probably regret not cleaning that up sooner.

Step 3: Use Sender Rules Instead of Thresholds

On a self-hosted stack this is the point where you'd lower the reject threshold and watch what happened. On a managed host you get something blunter and considerably safer: per-sender rules.

Block the domains that keep arriving despite everything — the marketing outfit that ignores unsubscribes, the outfit that bought your address from whoever scraped it. Block the domain rather than the address: spammers rotate the part before the @ constantly and keep the part after it for as long as it still works.

Allow the senders you cannot afford to have filtered. Your bank, your payment processor, your accountant, the tools that mail you login codes. An allow rule is the one thing that reliably beats a general model having an off day, and it is also what stops a greylisting delay biting the same sender twice.

Both live under Settings → Spam on JustEmails, and both take effect on the next message rather than after a propagation wait.

What you shouldn't do is go hunting for a reject threshold to lower. The reason it isn't exposed is the reason you'd regret it: mail rejected at SMTP level is gone. The sender gets a bounce, you never see it, and a client who assumed you were ignoring them doesn't usually write again to check.

Step 4: Greylisting, and Why First Contact Is Slow

Greylisting works. It's simple: when an unknown sender connects, return a "try again later" response. Real mail servers retry automatically (usually within 5-15 minutes). Spam botnets are stateless — they fire once and move on. No retry, no delivery.

The trade-off: time-sensitive mail from new senders arrives late on first contact. Password resets, order confirmations, authentication codes from new services. If you're waiting on one of those from a vendor you've never dealt with, the delay is maddening precisely because nothing looks broken.

What to do about it:

  1. Recognise the symptom — one late message from a sender you've never heard from, then normal delivery from that sender forever after
  2. Allow-list the senders where even ten minutes is too long: banks, payment processors, anything that mails you a code with an expiry on it
  3. Don't chase a delay that only happens once per sender; that's the mechanism working

On JustEmails, greylisting is part of the managed stack rather than a per-domain switch, so the allow list under Settings → Spam is the lever you have — and it's per-sender, which is the granularity you actually want.

Step 5: The Rules You Set Yourself

Server-side filtering catches the bulk. User-level rules finish the job.

Block, don't just delete. Most people delete junk and move on. (Guilty.) Deleting teaches nothing to anything. Blocking the sending domain is the correction that carries weight, because it is a rule rather than a signal — it applies to the next message from that domain whatever the scoring makes of it.

Rescue the false positives properly. When legitimate mail gets held — and it will, especially in the first weeks — get it out of the quarantine and add an allow rule for that sender in the same sitting. Skip the second half and the same sender gets held again next month, and you find out about it on a phone call.

Subject-line filters for repeat offenders. If you're seeing the same patterns repeatedly (subject lines with "URGENT" and cryptocurrency, From addresses with random character strings), set up user-level rules. In most mail clients: Settings > Filters > New Rule > If Subject contains X, move to Trash.

Sender blocklists. Direct blocking by From address is less useful than it sounds — spammers rotate addresses constantly. But if you're getting mail from a specific persistent domain (marketing spam from a company that won't honor unsubscribe), blocking the domain works. For the alias vs. forwarding distinction when setting up these rules, see our alias vs. forwarding explainer.

Common Mistakes That Make Spam Worse

I've made most of these. Sharing so you don't have to.

Responding to spam. Even to "unsubscribe." This confirms your address is active. Real companies honor unsubscribe. Spam operations sell your confirmed-active address to the next buyer.

Publishing your real address everywhere. If you need a contact form, use a role address (contact@) that you can abandon if it gets burnt. Keep your personal address off the public web.

Not enabling DMARC. Wait — DMARC is outbound, not inbound. True. But here's the trick: if you're receiving spoofed mail that claims to be from your own domain, your DMARC policy helps recipients reject it. And if senders you receive mail from have good DMARC policies, your filters can weight that positively. Our DMARC enforcement guide covers ramping from p=none to p=reject safely.

Wishing for a lower reject threshold. Rejected mail is invisible. You don't get a copy. You don't know you missed it. If a client sends you a legitimate message and it bounces, they probably won't tell you — they'll assume you're ignoring them. A quarantine you can actually read through is worth more than an aggressive bounce you can't, which is why the managed default leans the way it does.

The First 30 Days

Don't add rules daily. Check weekly, change one thing, wait another week.

Week 1: Baseline. Note how many spam messages land in inbox vs. spam folder vs. rejected.

Week 2: Block the repeat offenders by domain. Rescue anything the quarantine held wrongly and allow that sender while you're there.

Week 3: Read the quarantine again with the catch-all in mind. If most of what's being held was addressed to a name you never created, Step 2 is the fix, not another rule.

Week 4: Stabilise. If false positives are rare and the volume is manageable, stop adding rules. A short, deliberate allow list ages better than a long one.

After 30 days your domain has some reputation behind it, your allow list covers the senders that matter, and the general filtering starts working better on its own.

The first month is the hard part. It gets better. Promise.

For background on the DNS setup that feeds into all this, our custom domain email setup guide covers the MX, SPF, DKIM, and DMARC records that make filtering work. If you're migrating from a per-seat provider, our Microsoft 365 migration guide walks through the mailbox export process. For teams weighing cost trade-offs, the flat-fee vs. per-mailbox pricing breakdown shows where each model wins.

Frequently Asked Questions

Why does my custom domain get more spam than Gmail?

Gmail has 15+ years of sender reputation data, billions of training examples, and aggressive pre-filtering at the network edge. Your custom domain is new to spam filters — it doesn't have that reputation history, so borderline mail gets through. Add public WHOIS records, scraped contact pages, and catch-all addresses, and spammers have a verified target list. The fix isn't switching back to Gmail — it's shrinking what you expose, using the sender rules you do have, and letting reputation build over 2-3 months of consistent usage.

Can I change the spam score thresholds on my JustEmails domain?

No. Rspamd scoring runs server-side on JustEmails and there are no threshold, greylisting or RBL settings to edit. The spam screen under Settings gives you two controls instead: a quarantine you can review, and sender allow and block rules. If legitimate mail keeps getting held, allow that sender. If the same junk keeps arriving, block the domain. Per-domain threshold tuning is a self-hosted Rspamd job, with the maintenance that implies.

Why did mail from a new sender arrive ten minutes late?

Greylisting. A receiving server can defer the first message from an unknown sender and ask it to try again. Legitimate mail servers retry within about 5 to 15 minutes; a lot of spam machinery never does. The cost is a one-off delay on first contact, which stings when you are waiting on a password reset or an order confirmation from a vendor you have never dealt with. On JustEmails this is part of the managed filtering stack rather than a switch in your dashboard, so the lever is the allow list under Settings → Spam.

How do I stop the same spam reaching a new domain?

Work the controls that are yours rather than waiting for a model to come round to your point of view. On JustEmails that means the quarantine and the sender rules under Settings → Spam: block the domains that keep arriving, allow the senders whose mail must never be held, and review what the quarantine caught before it ages out. Per-sender rules take effect immediately and beat the general scoring both ways, which is exactly what you want in the first weeks of a domain's life.


Try JustEmails

Unlimited custom domain email hosting for $49/year flat — unlimited domains, unlimited mailboxes, 10 GB storage, full IMAP/SMTP. Built for agencies, freelancers, and anyone managing email across more than one domain.

Start your 7-day free trial → · How it compares

spam-filteringrspamdcustom-domain-emailemail-securityinbound-emailbuildinpublicsaasstudioaiworkforcebuildwithclaude

Related posts

Guides
A Professional Email Address: What It Actually Costs and Why It Matters
11 min read
Guides
How to Set Up Squarespace Domain Email (Without Google Workspace)
14 min read
Tutorials
Migrate from SparkPost to JustEmails Without Losing Deliverability
11 min read