You verify a list, and a chunk of it comes back neither valid nor invalid: catch-all, accept-all or risky. Most tools then leave the decision to you. This article explains what a catch-all actually is, why those addresses cause bounces after they "passed", and how to decide what to do with them.
How email verification normally works
A verifier talks to the recipient's mail server the same way a sending server would, then stops before sending anything:
> EHLO verifier.example
> MAIL FROM:<check@verifier.example>
> RCPT TO:<jane@acme.com>
< 250 OK <- mailbox exists
> QUIT
If the server answers 550 No such user, the mailbox doesn't exist. If it answers 250 OK, it does. That's the whole trick.
What a catch-all server does
A catch-all (or accept-all) server answers 250 OK to every recipient on the domain, whether the mailbox exists or not:
> RCPT TO:<jane@acme.com> < 250 OK
> RCPT TO:<zz-not-a-person@acme.com> < 250 OK
A good verifier notices this by also testing a random address that can't exist. If that's accepted too, the domain is catch-all, and the answer for Jane is: unknown.
Companies run catch-all for a few reasons:
- To avoid missing mail sent to misspelled names.
- Because a security gateway (Mimecast, Proofpoint, Barracuda) accepts everything first and filters later.
- To make it harder for spammers to discover real addresses.
Why catch-all addresses bounce later
Accepting at the SMTP stage isn't the same as delivering. With many catch-all setups, the message is accepted, the internal system then finds no such mailbox, and one of three things happens:
- A bounce arrives minutes or hours later (a non-delivery report). It counts against you just like an immediate bounce.
- The message is silently dropped. No bounce, but also no human ever reads it, and your campaign data is wrong.
- It lands in a shared inbox that nobody monitors.
That's why lists with many catch-all addresses show "valid" rates of 95% and real bounce rates of 5% or more. For cold email, a bounce rate above roughly 2% is where mailbox providers start to push you towards spam.
"Risky" is a decision you're being asked to make
Different tools label catch-alls differently: catch-all, accept_all, risky or unknown. They all mean the same thing: the mailbox could not be confirmed. Returning "risky" moves the decision into your code, and often nobody ever makes it, so risky addresses get sent to.
MailRambo takes a strict position instead: deliverable is true only when the mailbox is confirmed, so a catch-all returns:
{ "email": "jane@acme.com", "deliverable": false, "reason": "catch_all" }
Your code gets a clear default, and the reason lets you override it deliberately when you want to.
So what should you do with catch-alls?
It depends on what you're sending:
| Use case | Recommended handling | Why |
|---|---|---|
| Cold outreach | Exclude, or send in a small separate batch | Hidden bounces hurt the whole domain |
| Newsletter to opted-in subscribers | Keep | They gave you the address themselves |
| Signup form | Allow | Many real companies run catch-all servers |
| Transactional (receipts, resets) | Allow | The user expects the email |
For outreach, a practical middle ground is to send catch-all contacts separately, at low volume, and remove anything that bounces. Grading helps too: an address at a domain with strong DMARC, a real MX and a well-known provider is a better bet than one at a parked domain. The domain health checker shows those signals, and the API returns them with ?detail=full.
Can catch-alls be "resolved"?
Some vendors sell a second, paid pass that tries to resolve catch-all addresses using sending history or other signals. It can improve the odds, but no SMTP-level check can confirm a mailbox on a server that accepts everything. Treat any "resolved" catch-all as a probability, not a fact.
Summary
- A catch-all server says yes to every address, so verification can't confirm the mailbox.
- Those addresses often bounce later or disappear silently, and that raises real bounce rates.
- Decide per use case: exclude them from cold outreach, allow them at signup.
Check whether a domain is catch-all with the free email verifier, or verify a whole list with the API.