> ## Documentation Index
> Fetch the complete documentation index at: https://docs.maski.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Subdomains

> Claim a subdomain of a Maski domain, like mycompany.alias4me.in, and receive mail on it with no DNS setup at all.

A subdomain gives you your own slice of a Maski-owned domain — for example
`mycompany.alias4me.in` — and every address beneath it is yours. Unlike a
[custom domain](/custom-domains), there is nothing to configure: no DNS records,
no verification, no waiting. You claim the name and it starts receiving mail
within a second.

<Info>
  Subdomains are a Pro feature. Pro includes 5 subdomains. They are counted
  separately from custom domains, so having one does not use up the other.
</Info>

## Subdomain or custom domain?

Both give you a namespace you control. They differ in what they cost you to run.

|                                                              | Subdomain                   | Custom domain                        |
| ------------------------------------------------------------ | --------------------------- | ------------------------------------ |
| Address looks like                                           | `you@mycompany.alias4me.in` | `you@yourcompany.com`                |
| DNS setup                                                    | None                        | Several records to publish           |
| Ready in                                                     | About a second              | Minutes to hours, after verification |
| You must own a domain                                        | No                          | Yes                                  |
| Replying to forwarded mail                                   | Yes                         | Yes                                  |
| Starting a new message ([send from alias](/send-from-alias)) | No                          | Yes, once verified                   |
| [Brand logo](/bimi)                                          | No                          | Yes, with a VMC                      |

Pick a subdomain when you want a tidy, branded-ish namespace today without
buying or configuring anything. Pick a custom domain when the address needs to
be on a domain you own — for a business, or to start new conversations as well
as receive and reply.

## Claiming one

Go to **Subdomains** in the dashboard and choose a label. The label is the part
you pick; the rest is the Maski domain it sits under, chosen from a list. Today
that list holds one domain, `alias4me.in`.

Labels are checked as you type. Some are unavailable:

* Anything already claimed, by you or anyone else.
* Infrastructure names — `mx`, `mail`, `smtp`, `www`, `bounces`, and similar.
* Brand and role names, for the same reason Maski restricts them on shared
  addresses: `paypal.alias4me.in` would be a convincing thing to pretend with.
* Punycode (`xn--`) labels, and anything outside letters, digits and hyphens.

The check tells you the truth about a name without holding it. Two people typing
the same label are both told it is free, and whoever presses Claim first gets
it.

## Choosing what arrives

A subdomain has an inbound mode, which decides what happens to mail for an
address you have not explicitly created. You pick one when you claim, and you
can change it at any time — a change takes effect on the next message, with
nothing in flight to migrate.

<AccordionGroup>
  <Accordion title="Manual — only addresses you create">
    Mail to any other address on the subdomain is discarded, and the sender is
    not told. The tidiest option, and the default.
  </Accordion>

  <Accordion title="Catch-all — one address absorbs everything">
    A single `*` address receives all mail for the subdomain, wherever it was
    sent, and forwards it to one destination.
  </Accordion>

  <Accordion title="Auto-create — a real alias per address">
    The `*` address acts as a template. The first time mail arrives for a new
    address, Maski creates a real alias from that template. From then on the
    address has its own settings, its own counters, and its own pause and
    sender rules — you can manage it like any other alias.
  </Accordion>
</AccordionGroup>

## The `*` address

Catch-all and auto-create both deliver **through a `*` address**. A subdomain
in one of those modes with no `*` address yet delivers nothing, and, as with
manual mode, the senders are not told. Maski never guesses a destination on your
behalf, and it never leaves you in that state without saying so:

* **When you claim** into catch-all or auto-create, the dialog offers to create
  the `*` address for you, ticked by default, and names the destination it will
  forward to. Untick it if you would rather set it up yourself.
* **On the subdomain's page**, if a delivering mode has no `*` address, the page
  says so and gives you **Add catch-all** — one click, no dialog.
* **Add address** on the same page creates a named address like
  `work@mycompany.alias4me.in`, with the subdomain already selected.

The destination is your account's default destination, falling back to your
login address. That matters most under auto-create, where the `*` address is the
template every auto-created address inherits its destination from.

<Note>
  A `*` address you create counts as one of your plan's aliases, the same as a
  catch-all on a custom domain. At most one per subdomain, so a Pro account that
  gives all 5 subdomains a catch-all spends 5 of its 25 aliases. If you are
  already at the alias limit when you claim, the offer stands down and says so —
  the claim still goes through, and you can add the `*` address after freeing a
  slot.
</Note>

## Addresses created by inbound mail

Under auto-create, addresses appear because someone mailed them, not because you
made them. On the subdomain's page they are marked **Created by inbound mail** so
you can tell them apart from the ones you made.

They do not count against your plan's alias limit — you did not create them, and
a stranger mailing a hundred random addresses at your subdomain should not be
able to stop you making aliases by hand. They are limited separately, per
subdomain: up to 200 auto-created addresses each, and a cap on how many new ones
can appear in an hour so a burst cannot fill your list.

**Reaching either limit never costs you mail.** New addresses keep forwarding
through the `*` template, exactly as a plain catch-all would; you just stop
getting a separate row per address.

## Addresses beneath your subdomain

Every address under a subdomain you hold is yours alone, so the shared-domain
restrictions do not apply. `support@`, `hello@`, `careers@` and `billing@` are
all available to you, and short names of two characters are allowed.

## Replies and sending

You can **reply** to anything Maski forwards you from a subdomain address. Reply
as normal from your own mail client and Maski routes the message back out as the
subdomain address, so the other person never sees your real inbox. Setting a
[sender name](/send-from-alias#showing-your-name) on the alias works here too.

You cannot **start** a new conversation from a subdomain address —
[send-from-alias](/send-from-alias) needs a verified custom domain. Mail from
your subdomain is signed under the shared Maski domain, so allowing fresh
outbound would let one account's behaviour affect delivery for everyone else on
that domain. A subdomain is reply-only, the same as a shared Maski address.

## If your Pro plan ends

Subdomains are **disabled, not released**, when an account goes back to free.
The names stay yours and keep their addresses; mail stops arriving until you
upgrade again, at which point they come back as they were. Nothing is burned and
nothing is handed to anyone else.

While a subdomain is disabled you cannot add addresses to it — an address on a
name that routes no mail would be a dead end — and the page says so rather than
offering a button that does nothing.

## Releasing a subdomain

Releasing frees the slot against your plan limit. It does **not** free the name.

<Warning>
  **A released subdomain is burned permanently.** Nobody can claim it afterwards —
  including you.

  This is deliberate. People and services go on mailing a name long after you stop
  using it. If the name could be re-issued, whoever claimed it next would receive
  your password resets, your bank mail and your two-factor codes, for every
  address beneath it at once. The addresses you created are retired rather than
  deleted.
</Warning>

You confirm a release by typing the subdomain's label. If you only want to stop
paying, downgrading is the reversible option — see above.

## About DMARC checkers

If you run an external DMARC checker against your subdomain, some will report
"no DMARC record" or "invalid DMARC record". **This is a reporting artifact, not
a fault, and your mail is unaffected.**

The reason is a detail of how DNS wildcards work. Maski publishes one wildcard
record that covers every subdomain, and that wildcard also answers at the name
where a checker looks for a DMARC policy. Receivers follow the spec here: they
ignore anything that is not a DMARC policy and fall back to the policy on the
parent domain, which is published and correct. Strict checkers stop at the first
answer and report it as broken.

Mail from your subdomain is signed and aligned on both SPF and DKIM, and passes
DMARC. If you want to confirm it yourself, check the policy on the parent domain
rather than on your subdomain, or send a message to a mailbox that shows
authentication results.

## Limits

* Pro includes 5 subdomains. Free includes none.
* A `*` address you create counts as one of your plan's aliases. Addresses
  created by inbound mail do not.
* Auto-created addresses are capped at 200 per subdomain and rate-limited.
  Reaching a limit degrades to forwarding through the `*` address; mail is never
  dropped for it.
* Starting a new message from a subdomain address is not supported. Replies
  are. Use a [custom domain](/custom-domains) if you need to send first.
* Brand logos ([BIMI](/bimi)) are not available on a subdomain. Publishing the
  record a logo needs would stop the wildcard answering for your name, and your
  mail would stop with it.
