ValidMailbox

What is a catch-all email address?

A catch-all domain accepts mail addressed to every mailbox name, including ones that do not exist. Because the receiving server never rejects an unknown recipient, no external check can confirm whether a specific address at that domain is real. Validation tools report these as catch-all: plausible, but unproven.

Why domains are configured this way

A catch-all is usually a convenience, not a mistake. A small company sets one up so that mail to sales@, accounts@ and a misspelled jhon@ all land somewhere rather than bouncing. Microsoft 365 and Google Workspace both offer it, and many shared hosting plans enable it by default. Marketing teams also use catch-alls for per-vendor tagging, where every signup gets its own invented local part.

The side effect is that the domain loses the ability to say no. A recipient server normally rejects an unknown mailbox during the SMTP conversation, which is the signal every verification service depends on. A catch-all answers yes to everything, so that signal disappears.

Why a validator cannot see through it

Checking an address from outside has three layers. Syntax parsing confirms the address is well-formed under RFC 5322. An MX lookup confirms the domain publishes mail servers and can receive mail at all. Only the third layer, an SMTP conversation with the receiving server, can speak to whether one particular mailbox exists.

That third layer is where catch-alls defeat the check. You open a connection, name a recipient, and the server accepts. You name a recipient that could not possibly exist and the server accepts that too. The two answers are identical, so the test carries no information. Services that report a confident "valid" on a catch-all domain are reporting the server's politeness, not the mailbox.

This is also why our tools do not perform SMTP probing by default. Beyond being uninformative on catch-all domains, repeated probing from one source gets that source blocked, which degrades the check for everyone using it.

What a catch-all result actually tells you

More than it appears to. A catch-all verdict means the syntax is valid, the domain exists, and it publishes working mail servers. The address will not hard bounce for the common structural reasons. What remains unknown is one specific thing: whether a person is behind that particular local part.

Most business domains fall into this bucket. If a list of company contacts comes back largely catch-all, that is normal and not a sign of a bad list. A list that comes back largely invalid is the one to worry about.

How to handle catch-all addresses in a campaign

Treat them as a middle tier rather than discarding them. Send to confirmed-valid addresses first and let that traffic establish your sending reputation. Add catch-alls afterwards, in smaller batches, and watch the bounce rate as you go. If bounces stay low, the addresses were real; if they climb, you have learned something a validator could not have told you in advance.

Pay attention to the local part as well. A catch-all result on [email protected] is a reasonable bet, because it follows a pattern a real organisation uses. The same result on a guessed address is a guess either way. Where accuracy genuinely matters, a reply, a form submission or a LinkedIn confirmation tells you more than any check will.

Catch-all is not the same as disposable

The two are sometimes confused. A disposable provider such as Mailinator issues real, working mailboxes that expire within hours or days — those are reported invalid, because mailing them is pointless. A catch-all is an ordinary domain with a permissive configuration, and its addresses may well be long-lived. One is a throwaway, the other is simply unverifiable from outside.

How to check this

The email validator classifies every address as valid, invalid or catch-all, one at a time or in bulk from a CSV. The exported file carries a Validation_Status column plus a Validation_Reason explaining each verdict, so you can filter catch-alls into their own send. If you are weighing how many of them to include in a single batch, the warmup rate calculator helps you size it, and what bounce rate is too high covers the threshold to watch while you do.

Frequently asked questions

Is a catch-all address safe to email?

Usually, yes. A catch-all verdict means the syntax is valid and the domain publishes working mail servers, so the address will not hard bounce for structural reasons. What is unknown is whether a person is behind that specific local part. Send to confirmed addresses first, then add catch-alls in smaller batches while watching the bounce rate.

Why can't a validator tell if a catch-all address is real?

Because the receiving server accepts every recipient, including ones that cannot exist. The accept for a real mailbox and the accept for an invented one are identical, so the test carries no information. Any service reporting a confident verdict on a catch-all domain is reporting the server's politeness, not the mailbox.

Is catch-all the same as a disposable address?

No. A disposable provider issues real mailboxes that expire within hours or days, and those are reported invalid because mailing them is pointless. A catch-all is an ordinary domain with a permissive configuration, and its addresses are often long-lived.