Verification

What is a catch-all email address?

A catch-all email address belongs to a domain that is set up to accept mail for every possible address, whether or not a real mailbox sits behind it. That one setting changes what any verification tool can honestly promise, because the usual check that confirms an ordinary address cannot confirm an individual mailbox on a catch-all domain. This guide explains what a catch-all is, why that limit exists, how Sends Verified handles it, and whether a catch-all is worth emailing.

What a catch-all email address is

A catch-all, sometimes called an accept-all domain, is a mail server configured to say yes to any address at that domain. Mail to jane@example.com, sales@example.com, and this-name-does-not-exist@example.com all get accepted, then routed to a single inbox, forwarded, or in some cases quietly discarded.

Owners turn this on for ordinary reasons. A small business may want every message to land in one shared mailbox. An agency may forward everything to a central address. Some teams enable it so a customer who mistypes a name still reaches someone instead of bouncing. Whatever the reason, the effect for anyone verifying a list is the same: the domain will confirm an address that does not actually have a mailbox, so acceptance alone tells you very little.

Why SMTP alone cannot confirm the mailbox

Email verification works without sending a message. The verifier looks up the domain's mail servers (its MX records), opens an SMTP conversation with the right one, asks whether it would accept mail for the address, and hangs up before anything is delivered. Nobody on the list is emailed. If you want the full mechanics, see how email verification works.

On a normal domain this is decisive. The server replies with a positive code for an address that exists and a rejection for one that does not, so the mailbox signal is real. On a catch-all domain the server replies positively to everything. The mailbox-level answer you would normally rely on is gone, because the domain is designed to never say no. SMTP, on its own, simply cannot separate a real mailbox from an invented one when the domain accepts both.

This is why a careful verifier does not report every catch-all as Safe. Doing so would hand you a list that looks clean but hides unknown risk, since some of those accepted addresses have no mailbox at all. The honest move is to say exactly what the check could and could not prove, and let you decide from there.

How Sends Verified detects a catch-all email

Sends Verified scores eight signals for every address: syntax, domain, mail server (MX), mailbox, catch-all, disposable, role, and spam traps. The catch-all check is the one that guards against the trap above.

Before trusting a positive SMTP response, Sends Verified tests the domain with a made-up address that could not plausibly exist. If the server accepts that invented address too, the domain is accepting everything, and the result is flagged as Catch-all rather than passed off as Safe. You get an honest label that says the domain confirmed acceptance but the individual mailbox could not be proven by SMTP alone. A result of Safe, by contrast, means the mail server accepted the real address and rejected the test address, so the mailbox genuinely exists.

Domain typeWhat SMTP returnsSends Verified result
Normal domain, real mailboxAccepts the real address, rejects a made-up oneSafe
Normal domain, no mailboxRejects the addressInvalid
Catch-all domainAccepts every address, including a made-up oneCatch-all
Catch-all on Microsoft 365, mailbox in directoryAccepts everything over SMTPDeliverable, with a confidence score

Going further for Microsoft 365 catch-all domains

Many business domains run their mail on Microsoft 365, and plenty of them are catch-alls. For those domains, Sends Verified goes beyond the SMTP conversation. It confirms the specific mailbox against the provider's own directory and, when the mailbox is really there, promotes the address from Catch-all to Deliverable with a confidence score. That turns a result you could not act on into one you can.

This extra step is only possible where the provider exposes a reliable way to confirm the mailbox. Catch-all domains on providers without that kind of lookup stay labelled Catch-all, because there is no honest way to prove the individual mailbox exists. Sends Verified would rather tell you it cannot confirm than guess and inflate your list quality.

Is a catch-all email worth emailing?

A Catch-all result is not a verdict of invalid. The mailbox may well exist, and in many cases it does. The domain just refuses to confirm it one way or the other. That puts a catch-all in a middle zone: lower risk than an address a server has rejected, higher risk than a mailbox you have confirmed. Treating the whole group as either all good or all bad is where senders tend to get burned, so it helps to think of catch-alls as their own tier with their own rules.

Whether you send comes down to your list and your tolerance for bounces. A catch-all that accepts at verification time can still bounce later, or route to an address nobody reads, so sending to a large block of them can quietly drag your bounce rate up and put real pressure on deliverability. If you are weighing a cold campaign in particular, where every bounce costs you more, read our take on whether to send to catch-alls in cold outreach for the full picture.

A few practical habits keep catch-alls from hurting you. Segment them out so they do not sit next to confirmed addresses in the same send, and watch how they perform before trusting them at scale. Keep an eye on the metrics that matter for sender reputation, covered in how to reduce your email bounce rate. And remember that any verification is a snapshot: a mailbox can close, a domain can change hands, and roughly a few percent of a business list goes stale every month, which is why email lists decay and lists older than about three months are worth re-verifying.

How Sends Verified charges for a catch-all result

A Catch-all is a definite answer, so it is treated like any other confirmed result for billing. The only category that is always free is Unknown, where a server would not give a clear answer in time or refused the outside check; in that case the credit returns automatically when the task finishes. Sends Verified uses daily credits first on a monthly plan, then one-off instant credits that never expire, and duplicate addresses in a task are checked and charged only once.

FAQ

Is a catch-all email address valid?

A catch-all domain is valid and reachable, but that does not mean every address on it has a real mailbox. The domain accepts all mail by design, so an address labelled Catch-all might reach a person or might reach nothing. It is best read as "unconfirmed" rather than "good" or "bad".

Can any tool confirm the mailbox on a catch-all domain?

Not through SMTP alone, because the server answers yes to everything and never reveals which addresses are real. The one exception is where the provider exposes a directory to check against. Sends Verified uses that for Microsoft 365 catch-all domains to confirm the specific mailbox and promote it to Deliverable, while catch-alls on other providers remain Catch-all.

Will I be charged for a catch-all result?

Yes. A Catch-all is a clear outcome, so it uses a credit like a Safe or Invalid result does. Only Unknown results are free, and that credit is refunded automatically when the task finishes.

How often should I re-verify catch-all addresses?

Treat any verification as a snapshot in time. Mailboxes close, domains change configuration, and a Safe or Catch-all result can drift as a list ages. Re-verifying lists older than about three months keeps your data current and protects your bounce rate before a big send.

Clean your next list before you hit send.

Unknown results are always free. Create an account and verify your first addresses in minutes.

Start free