Deliverability

Catch-All Domains: Why Verification Sometimes Says Maybe

A catch-all server accepts every address on its domain, including the ones that do not exist. It is the main reason a verification result sometimes says "we cannot be sure".

Table of contents

What a catch-all is

A domain configured as catch-all accepts mail for any address ending in that domain. Write to a colleague, or to a name invented on the spot, and the server says yes to both. What happens next is internal: the message may be routed to a shared mailbox, filed, or silently discarded.

Administrators enable this for practical reasons: not losing messages sent to a misspelled address, supporting many aliases without declaring each one, or simply because it was the default.

Why it defeats verification

Verifying an address means asking the receiving server whether it will accept mail for that specific mailbox. On a normal server, the answer distinguishes real addresses from invented ones. On a catch-all, every answer is yes.

The correct conclusion is not "the address is valid" and not "the address is invalid". It is "the domain accepts everything, so this test tells us nothing about this mailbox".

Any tool that reports catch-all addresses as simply valid is telling you something it cannot know. Any tool that reports them as invalid is discarding contacts who very likely exist.

How common they are

Catch-all configurations are common in business domains, and much rarer among consumer providers. This means a B2B list will contain a meaningful share of addresses you cannot verify with certainty, and a consumer list almost none.

This is worth knowing before you judge a verification tool by the share of results it declares certain. On a B2B list, a tool reporting one hundred per cent certainty is not more accurate, it is less honest.

What to do with them

Treat catch-all addresses as a separate segment rather than folding them into valid or invalid:

  • Judge them by other signals. An address in a plausible format, on an active domain, belonging to a person you found through a professional source, is probably real.
  • Send to them separately. Keep them out of your main send, so their bounces do not contaminate the reputation signal of your clean batch.
  • Watch what happens. A catch-all that accepts and never bounces still tells you nothing, but replies and opens do.
  • Deprioritise, do not delete. Removing every catch-all address from a B2B list can mean throwing away a large share of your real contacts.

How a verification tool detects one

The test is simple and slightly impolite. The tool opens an SMTP conversation with the domain's mail server and asks about two addresses: the one you want to check, and one that certainly does not exist, generated at random.

If the server rejects the invented address and accepts yours, the answer is meaningful: this specific mailbox exists. If it accepts both, the domain is catch-all and the test has told you nothing about your address in particular.

This is why a serious verifier is slower than a tool that only checks DNS records. A DNS lookup confirms that a domain exists and has mail servers, which takes milliseconds and proves very little. A real conversation with the receiving server takes a second or two and produces an answer worth having.

Some servers complicate matters further. A few accept every address during the conversation and decide later, generating a bounce hours after the fact. Others rate-limit or temporarily refuse an unfamiliar sender, which produces an ambiguous result that should be reported as risky rather than guessed either way.

Catch-all is not the same as accept-all spam trapping

Two situations are easy to confuse. A catch-all is a normal administrative choice: the domain accepts everything so that misspelled addresses still reach someone.

A spam trap is different. It is an address deliberately kept alive, or recycled from an abandoned mailbox, specifically to catch senders who mail people who never asked. Writing to one damages your reputation directly, and no verification tool can reliably flag them, because from the outside they look exactly like ordinary addresses.

The practical link between the two: lists that contain many unverifiable catch-all addresses are often lists built by scraping, and scraped lists are where traps live. The catch-all rate of a list is therefore a decent proxy for how it was assembled, even though catch-all itself is harmless.

A decision framework for B2B lists

Rather than a binary keep or delete, sort catch-all addresses by the surrounding evidence:

  • Format. firstname.lastname on a company domain is far more likely to be real than a generic string.
  • Source. An address someone gave you, or that appears on a professional profile, is worth more than one inferred from a naming pattern.
  • Domain activity. A domain with a live website, recent DNS changes and a working mail server is a going concern.
  • Age. An address collected two years ago on a catch-all domain is the weakest combination in the list.

Then send to them as a separate batch, after your clean batch, and watch what happens. Bounces from a catch-all domain often arrive late, which is precisely why you do not want them mixed into the send that carries your important messages.

Conclusion

Catch-all is not a defect in your list and not a failure of the verification tool. It is a server configuration that makes one specific question unanswerable. The right response is to say so plainly, segment those addresses, and decide about them with information that comes from somewhere else.

Frequently asked questions

Should I delete catch-all addresses from my list?

No. On a business list they often represent a large share of your real contacts. Keep them in a separate segment, judge them on format, source and domain activity, and send to them after your verified batch rather than alongside it.

Can any tool verify a catch-all address with certainty?

No tool can, and any that claims to is guessing. The server accepts every address by design, so the question cannot be answered from outside. What a good tool can do is say so plainly instead of reporting a false positive.

Are catch-all domains a sign of a bad list?

Not in themselves, since it is a normal administrative choice. But a list with an unusually high catch-all rate is often a scraped one, and scraped lists are where spam traps live. Treat the rate as a clue about how the list was built.

Track the emails that matter

Install mailcheck for free and track up to 10 emails per month in Gmail and Zoho Mail.

Add to Chrome, free

No credit card. Unlimited tracking from 9 EUR per month.

All articles →