What is a catch-all domain?

Catch-all domain, defined
A catch-all domain accepts mail for every address at that domain, whether or not the mailbox exists, which makes mailbox-level verification impossible there.

Ask a normal server about an address that does not exist and it says 550. Ask a catch-all server the same question and it says 250, because it is configured to take everything and sort it out later.

That behavior removes the only signal SMTP verification has. The test for it is simple: ask about a random address nobody could have registered. If that is accepted too, the domain takes anything.

Around 28% of addresses on a typical B2B list sit on catch-all domains, so how a verifier reports them changes the headline accuracy figure far more than the quality of its engine does.

Some of those addresses are real and some are not. A catch-all verdict means unproven, not bad, and the useful next step is engagement data rather than another verification pass.

How ZapBounce reports it

Catch-all domains come back as catch_all with the reason accept_all_domain, never folded into valid. It is a result and costs a credit like any other, because it took a second probe to establish and it tells you something true about the whole domain. The mx_host field shows whether it is a Google, Microsoft or self-hosted domain, which changes what you can infer.

Ten thousand addresses, two honest numbers

Suppose you run a 10,000-address B2B list through a verifier and 2,800 of those addresses sit on catch-all domains, which is close to the usual share. Of the remaining 7,200, say 6,300 return a clear 250 after the control probe was refused, and 900 return a clear 550.

An honest report says coverage was 72%, because that's the share of the list that got a real verdict. Accuracy is then measured inside that 72%. A vendor who quotes you 99% is nearly always describing this inner group and staying quiet about the 2,800. With us those 2,800 cost a credit each like any other result, and the label is what you're buying: proof that the domain accepts everything, so a valid on those rows from anyone else is a guess.

Now watch what happens if those 2,800 get stamped valid instead. Your report shows 9,100 good addresses, the summary looks wonderful, and the first campaign decides how many were real. If a fifth of them are dead, that's 560 hard bounces from addresses you were told were fine.

Mailing the unproven group without betting the domain

Keep the catch-all segment out of your main send. Start with a batch of a few hundred, from the same domain and with the same content, and read the bounces over the next three days. Some accept-all servers reject unknown users only after the handshake, so the failure arrives later as a bounce message instead of a refusal on the wire.

If that first batch bounces under 2%, widen it. At 10%, you've learned something about where the data came from, and it cost you a few dozen bounces to find out.

Age matters more here than anywhere else on your list. A catch-all address you collected last month from a signed-up customer is probably fine. One that came from a purchased file three years ago has nothing vouching for it at all, because the single check that could have caught it doesn't work on that domain.

Catch-all domain: common questions

Can any verifier check a catch-all address?

Not over SMTP. Some vendors add guesses from other data and present the result as a verdict. The protocol itself has no answer left to give.

Should I delete catch-all addresses?

Usually not. Many are real mailboxes at companies that configured the domain this way. Send to them separately and let engagement decide.

Why are so many B2B addresses catch-all?

It is a common corporate mail configuration, so it clusters on exactly the domains B2B lists target. Around 28% of a typical B2B list.

See this on your own list

100 free checks a month, and the unknowns come back labeled.