You are absolutely correct…
I used to have ‘catch-all’ addresses on my web sites so that if anybody misspelt ‘[email protected]’ as ‘slaes’ it still got through.
The results were millions and millions of spam e-mails sent to random e-mail addresses at the domain.