Bounce Address

Email & Security
The return address used for non-delivery reports (bounces) when email cannot be delivered.
← Back to Glossary

What is a Bounce Address?

A bounce address, also called the return path or envelope sender, is the email address that receives non-delivery reports (NDRs) when an email cannot be delivered. This address is separate from the "From" address visible to recipients and is used exclusively for automated delivery notifications.

How Bounce Addresses Work

Email transmission uses two sets of addresses:

Header From (visible to recipient):
From: John Doe <[email protected]>
Envelope From (SMTP-level, used for bounces):
MAIL FROM: <[email protected]>

When delivery fails, the receiving server sends the bounce to the envelope sender, not the header From address.

SMTP Conversation Example

Client: MAIL FROM: <[email protected]>

Server: 250 OK

Client: RCPT TO: <[email protected]>

Server: 550 No such user here

Client: QUIT

# Later, server sends bounce to [email protected]

Types of Email Bounces

Hard Bounces

Permanent delivery failures:

Action: Remove address from mailing list immediately.

Soft Bounces

Temporary failures:

Action: Retry delivery, remove after multiple soft bounces.

Block Bounces

Deliverability issues:

Action: Investigate sender reputation and authentication.

Bounce Address Configuration

Setting Return Path in Email Headers

PHP (mail function):
$to = "[email protected]";

$subject = "Test Email";

$message = "Email body";

$headers = "From: [email protected]\r\n";

$headers .= "Return-Path: [email protected]\r\n";

mail($to, $subject, $message, $headers, "-f [email protected]");

PHPMailer:
$mail = new PHPMailer();

$mail->From = "[email protected]";

$mail->Sender = "[email protected]"; // Return path

$mail->addAddress("[email protected]");

$mail->Subject = "Test Email";

$mail->send();

Postfix (SMTP):
# /etc/postfix/main.cf

sender_canonical_maps = hash:/etc/postfix/sender_canonical

# /etc/postfix/sender_canonical

@example.com [email protected]

# Apply changes

postmap /etc/postfix/sender_canonical

systemctl reload postfix

Dedicated Bounce Handling Services

Most email service providers offer bounce management:

Amazon SES:
{

"Message": {

"Subject": "Test",

"From": "[email protected]",

"ReturnPath": "[email protected]"

}

}

SendGrid:
const msg = {

to: '[email protected]',

from: '[email protected]',

replyTo: '[email protected]',

return_path: '[email protected]',

subject: 'Test Email',

text: 'Email body'

};

Bounce Address Naming Conventions

Subdomain Approach

[email protected]           # General bounces

[email protected] # No-reply emails

[email protected] # Returns/receipts

Campaign-Specific

Track bounces per campaign:

[email protected]

[email protected]

[email protected]

Variable Envelope Return Path (VERP)

Encode recipient in bounce address:

Sending to: [email protected]

Return path: [email protected]

When bounce arrives at bounces+*, parse to identify failed recipient

Processing Bounce Messages

Automated Bounce Parsing

Python Example:
import email

from email import policy

def parse_bounce(raw_email):

msg = email.message_from_string(raw_email, policy=policy.default)

# Extract bounce type

if "550" in msg.get_payload():

return "hard_bounce"

elif "452" in msg.get_payload():

return "soft_bounce"

# Extract failed recipient

for part in msg.walk():

if part.get_content_type() == "message/delivery-status":

# Parse delivery status

pass

return bounce_info

# Integrate with mailing list to remove hard bounces

Webhook-Based Bounce Handling

Modern ESPs provide webhooks:

SendGrid Webhook:
POST /bounce-webhook

{

"email": "[email protected]",

"event": "bounce",

"reason": "550 5.1.1 User unknown",

"type": "blocked",

"status": "5.0.0"

}

Action: Update database to mark email as bounced.

SPF and Bounce Addresses

SPF checks the envelope sender (bounce address), not the From header:

Message:

From: [email protected] (header)

Return-Path: [email protected] (envelope)

SPF Check:

Queries: mail-server.com TXT record (not example.com)

Must include sending IP in mail-server.com's SPF

Bounce Domain SPF Configuration

bounces.example.com.    IN    TXT    "v=spf1 include:_spf.sendgrid.net ~all"

Ensure your bounce subdomain has appropriate SPF records for your sending infrastructure.

Bounce Address Best Practices

Use a Dedicated Bounce Address

Never use your primary email for bounces:

# Bad

Return-Path: [email protected]

# Good

Return-Path: [email protected]

Monitor Bounce Rates

Bounce RateAssessmentAction
< 2%HealthyContinue monitoring
2-5%ConcerningAudit email list quality
5-10%PoorImmediate list cleaning needed
> 10%CriticalDeliverability at risk

Implement Bounce Processing

Automate removal of hard bounces:

-- Mark emails with hard bounces

UPDATE mailing_list

SET status = 'bounced', bounce_count = bounce_count + 1

WHERE email IN (SELECT email FROM recent_hard_bounces);

-- Remove after 3 hard bounces

DELETE FROM mailing_list

WHERE bounce_count >= 3;

Separate Transactional and Marketing Bounces

[email protected]  # Order confirmations, receipts

[email protected] # Newsletters, campaigns

Different bounce rates are expected for each type.

Set Up Bounce Processing Automation

Cron Job Example:
#!/bin/bash

# Process bounces every hour

# Fetch bounces from IMAP

fetchmail -c /etc/fetchmailrc

# Parse and update database

/usr/local/bin/process-bounces.py

# Clean up processed bounces older than 30 days

find /var/mail/bounces -mtime +30 -delete

Backscatter and Bounce Security

Backscatter Problem

When your server accepts spam and then bounces it, you're sending to forged addresses:

1. Spammer sends email with forged From

2. Your server accepts it

3. Your server realizes it's spam/invalid

4. Your server bounces to forged From address

5. Innocent party receives bounce (backscatter)

Solution: Reject at SMTP time, don't accept then bounce:
# Postfix: Reject unknown users at SMTP time

smtpd_recipient_restrictions = reject_unauth_destination

local_recipient_maps = hash:/etc/postfix/local_recipients

Bounce Forgery

Attackers can forge bounce messages to:

Validation:

Common Bounce Scenarios

Scenario 1: All Emails Bouncing

Cause: SPF failure, IP blacklist, or server reputation Check: SPF records, sender IP reputation, DMARC reports

Scenario 2: Bounces Not Being Received

Cause: Bounce address misconfigured or doesn't exist Check: MX records for bounce domain, mailbox exists

Scenario 3: High Soft Bounce Rate

Cause: Recipient servers overloaded, rate limiting, large messages Check: Sending rate, message size, recipient server errors

Scenario 4: Bounce Loops

Cause: Bounce address triggers auto-reply, which triggers another bounce Check: Disable auto-responders on bounce addresses

Testing Bounce Handling

Send test email with invalid recipient:
# Test bounce to invalid address

swaks --to [email protected] \

--from [email protected] \

--server mx.test-domain.com

# Check if bounce arrives at [email protected]

Verify SPF for bounce domain:
dig bounces.example.com TXT

# Should show SPF record with authorized senders

Proper bounce address management is critical for maintaining sender reputation, list hygiene, and deliverability.

Put This Knowledge to Work

Use DomScan's API to check domain availability, health, and more.