You verify a list, and a chunk of it comes back neither "valid" nor "invalid" but catch-all (some tools say accept-all). These addresses are not wrong, and they are not confirmed either. Handled carelessly, they are where many of the bounces in an otherwise clean list come from.
This article explains what a catch-all domain is, why no verification tool can see inside one, and how to decide which of those addresses to email.
What a catch-all domain is
Normally, a mail server knows which mailboxes exist. When another server tries to deliver to nobody@company.com, it answers "user unknown" (550 5.1.1) and the message bounces.
A catch-all (or accept-all) domain is configured differently: its mail server accepts messages for every address on the domain, whether the mailbox exists or not. Mail to non-existent addresses is then delivered to a shared inbox, forwarded somewhere, silently deleted, or bounced later.
Companies set it up for understandable reasons:
- They do not want to lose mail because a sender misspelled a name (
jon@instead ofjohn@). - Former employees still receive mail that someone can pick up.
- Some email security gateways can accept mail first and filter it afterwards, which looks the same from the outside.
Why verification cannot confirm a catch-all address
An email verifier checks a mailbox by starting an SMTP conversation with the domain's mail server and asking whether it would accept a message for the address. It then disconnects before anything is sent (see how bounce codes work).
On a catch-all domain, the server says "yes" to every address. john.smith@company.com gets a yes, and so does zq8x7k2@company.com. The answer carries no information about whether John actually has a mailbox.
That is also how catch-all domains are detected: the verifier asks about a random address that cannot exist. If the server accepts it, the domain accepts everything, and any "yes" for your real address has to be treated as unconfirmed.
In MailQuell, this extra probe is what Power mode does. It costs 2 credits per address instead of 1 and marks addresses on accept-all domains as catch-all rather than reporting them as valid.
Why catch-all addresses are risky
- Delayed bounces. Some catch-all servers accept the message during the SMTP conversation, then check the recipient and send a bounce back hours later. Your sending tool still counts them as bounces.
- Nobody reads it. Mail to a non-existent person may land in a shared inbox nobody watches, or be deleted. You get no bounce, but you get no reply either, and low engagement also hurts deliverability over time.
- Spam traps are harder to spot. An address that looks plausible on an accept-all domain gives no signal at all.
None of this means catch-all addresses are bad. Many are real people at real companies, often exactly the decision-makers you want to reach in B2B. They simply need more care.
How to decide which catch-all addresses to email
Use what you know about each address in addition to the verification result:
| Signal | Lower risk | Higher risk |
|---|---|---|
| Where the address came from | The person gave it to you, or it is on their company website | Guessed from a pattern, bought or scraped |
| The name part | Matches a real person you can find (maria.lopez@) |
Generic or odd (sales2@, x.y@) |
| Past engagement | They opened, clicked or replied before | Never contacted |
| Company size | Small company where naming is simple | Large company with many formats |
A practical approach used by many cold email senders:
- Separate catch-all addresses from valid ones. Never mix them into your first sends from a new domain.
- Send to valid addresses first, and let your mailbox build a good track record.
- Send catch-all addresses in small batches (for example 10 to 20% of a day's volume) and watch your bounce rate after each batch.
- Stop and review if bounces rise. If a particular domain produces bounces, drop its remaining addresses.
- Remove non-responders after your sequence ends. An address on an accept-all domain that never engages is not worth keeping.
Frequently asked questions
Is "accept-all" the same as "catch-all"?
Yes. Different verification tools use different labels for the same thing: a domain whose mail server accepts every address.
Can any tool really verify catch-all emails?
Not through SMTP, because the server gives the same answer for every address. Some tools estimate the probability that an address is real from other data. Treat those scores as estimates, not confirmations.
Is my own domain catch-all?
You can find out by sending a test message to a random address on your domain, such as test-8k2j9q@yourdomain.com. If it arrives somewhere instead of bouncing, the domain is catch-all. In Google Workspace, for example, this is a routing rule in the admin console (Gmail > Routing) that redirects mail for unrecognized addresses to a mailbox.
Should I switch catch-all off on my company domain?
If you do not need it, yes. It attracts spam sent to made-up addresses and makes your own domain harder for others to verify. If you keep it, make sure someone actually reads the inbox it delivers to.
Check it yourself
- See which mail servers a domain uses with the MX lookup.
- Check a single address with the free email checker.
- To separate catch-all addresses from valid ones across a whole list, verify it in Power mode: start free with 200 checks every month.