in my experience that sort of "send some spam to addresses we have no reason to believe exist" behavior takes the form of sending stuff to $commonfirstname@domain not $service@domain
nobody is sending email to alsdkjfadf@domain
nobody is sending email to alsdkjfadf@domain
That’s actually the kind of spam I used to receive on a very short domain with a catch-all.
I guess they loop through short domain names and then try to brute-force the local part.