Skip to content
DefinitionUpdated 2 min read

What is a catch-all email domain?

A catch-all (or accept-all) domain is one whose mail server accepts mail for any address at that domain, whether or not the mailbox exists. Because the server says yes to everything, a verifier cannot tell whether a particular address is real, so catch-all addresses are marked risky rather than valid.

Why verification cannot see through it

Email verification works by asking the receiving server, during the SMTP conversation, whether it will accept mail for a given address. A normal server answers with a 2xx code for real mailboxes and a 5xx code for ones that do not exist. A catch-all server answers 2xx for everything.

Verifiers detect this by testing an address that cannot exist, something like zq81xk-test@company.com. If the server accepts that too, the domain is catch-all, and the result for the real address is "accepted, unproven".

How common is it, and who uses it?

It varies by market and there is no reliable public figure, so measure your own lists. Catch-all set-ups tend to show up at companies that run their own mail servers or have security gateways in front of their mailboxes, which often means larger or more regulated organisations. That is awkward, because those can be exactly the accounts you most want to reach.

A worked way to estimate the risk

Say you have 200 catch-all addresses for a campaign. Instead of sending all 200:

  1. Pick 20 at random and send the first email.
  2. Wait 48 hours for delayed bounces.
  3. If 1 of 20 bounced (5%), expect around 10 bounces across the 200. If 6 of 20 bounced (30%), stop: the remaining 180 would likely add dozens of failures.
  4. Send the rest in batches mixed with verified addresses, so catch-alls never dominate a day's sending.

The sample is small, so treat the estimate as a rough guide, not a guarantee.

Raising your confidence

  • Confirm the pattern. If you have a verified address at the same company from another source, and it follows first.last@, an address built the same way is more likely real.
  • Look for the address in public. An email in a conference bio, a press release or a GitHub commit is evidence.
  • Check the person still works there. A catch-all will happily accept mail for someone who left two years ago.

Common mistakes

  • Counting catch-all as valid in reports. It inflates your found rate and then your bounce rate.
  • Paying full price for them as verified. Check how your supplier bills catch-all results.
  • Blasting a whole catch-all list on a new domain. New domains have the least reputation to spare; see email deliverability.

Where Sluice fits

Sluice bills only addresses that pass its independent verification, and refunds a bounce exactly what the lookup cost. Sequences stop for anyone whose email bounces, so a catch-all that turns out to be dead does not keep getting follow-ups. For more on cleaning lists before you send, see how to verify email addresses.

Questions people ask

Should I send to catch-all email addresses?
Carefully. Send a small batch first, keep it a minority of any campaign, and remove addresses that bounce. Prefer addresses built from a confirmed pattern at that company.
Why do companies set up catch-all domains?
So mail with a typo in the name, or sent to a former employee, still arrives somewhere rather than bouncing. Some also do it to hide which addresses exist from people probing their server.
Can a catch-all address still bounce?
Yes. Some servers accept the message during the SMTP conversation and then bounce it later, or the domain policy changes. That delayed bounce counts against you like any other.

Sources

  1. RFC 5321: Simple Mail Transfer Protocol

Try it on your own market

Sluice quotes the worst-case price before anything runs and charges only for lookups that found something, so finding out costs close to nothing.

Get started