What Is a Catch-All Email Address (and Why "Risky" Results Cause Bounces)

You verify a list, and a chunk of it comes back neither valid nor invalid: catch-all, accept-all or risky. Most tools then leave the decision to you. This article explains what a catch-all actually is, why those addresses cause bounces after they "passed", and how to decide what to do with them.

How email verification normally works

A verifier talks to the recipient's mail server the same way a sending server would, then stops before sending anything:

> EHLO verifier.example
> MAIL FROM:<check@verifier.example>
> RCPT TO:<jane@acme.com>
< 250 OK                 <- mailbox exists
> QUIT

If the server answers 550 No such user, the mailbox doesn't exist. If it answers 250 OK, it does. That's the whole trick.

What a catch-all server does

A catch-all (or accept-all) server answers 250 OK to every recipient on the domain, whether the mailbox exists or not:

> RCPT TO:<jane@acme.com>             < 250 OK
> RCPT TO:<zz-not-a-person@acme.com>  < 250 OK

A good verifier notices this by also testing a random address that can't exist. If that's accepted too, the domain is catch-all, and the answer for Jane is: unknown.

Companies run catch-all for a few reasons:

  • To avoid missing mail sent to misspelled names.
  • Because a security gateway (Mimecast, Proofpoint, Barracuda) accepts everything first and filters later.
  • To make it harder for spammers to discover real addresses.

Why catch-all addresses bounce later

Accepting at the SMTP stage isn't the same as delivering. With many catch-all setups, the message is accepted, the internal system then finds no such mailbox, and one of three things happens:

  1. A bounce arrives minutes or hours later (a non-delivery report). It counts against you just like an immediate bounce.
  2. The message is silently dropped. No bounce, but also no human ever reads it, and your campaign data is wrong.
  3. It lands in a shared inbox that nobody monitors.

That's why lists with many catch-all addresses show "valid" rates of 95% and real bounce rates of 5% or more. For cold email, a bounce rate above roughly 2% is where mailbox providers start to push you towards spam.

"Risky" is a decision you're being asked to make

Different tools label catch-alls differently: catch-all, accept_all, risky or unknown. They all mean the same thing: the mailbox could not be confirmed. Returning "risky" moves the decision into your code, and often nobody ever makes it, so risky addresses get sent to.

MailRambo takes a strict position instead: deliverable is true only when the mailbox is confirmed, so a catch-all returns:

{ "email": "jane@acme.com", "deliverable": false, "reason": "catch_all" }

Your code gets a clear default, and the reason lets you override it deliberately when you want to.

So what should you do with catch-alls?

It depends on what you're sending:

Use case Recommended handling Why
Cold outreach Exclude, or send in a small separate batch Hidden bounces hurt the whole domain
Newsletter to opted-in subscribers Keep They gave you the address themselves
Signup form Allow Many real companies run catch-all servers
Transactional (receipts, resets) Allow The user expects the email

For outreach, a practical middle ground is to send catch-all contacts separately, at low volume, and remove anything that bounces. Grading helps too: an address at a domain with strong DMARC, a real MX and a well-known provider is a better bet than one at a parked domain. The domain health checker shows those signals, and the API returns them with ?detail=full.

Can catch-alls be "resolved"?

Some vendors sell a second, paid pass that tries to resolve catch-all addresses using sending history or other signals. It can improve the odds, but no SMTP-level check can confirm a mailbox on a server that accepts everything. Treat any "resolved" catch-all as a probability, not a fact.

Summary

  • A catch-all server says yes to every address, so verification can't confirm the mailbox.
  • Those addresses often bounce later or disappear silently, and that raises real bounce rates.
  • Decide per use case: exclude them from cold outreach, allow them at signup.

Check whether a domain is catch-all with the free email verifier, or verify a whole list with the API.

Run these checks from your code

Verify addresses at signup, clean lists and read SPF/DKIM/DMARC with one API call. 100 free verifications a month, test keys that cost nothing, and the API on every plan.