OS Tools

Catch-All Email Verification: How to Actually Resolve Accept-All Domains

Catch-all domains are usually 20–40% of a B2B list, and most verifiers hand them back as 'unknown' — charged, and no more useful than before. Here's what can be done about them.

Short answer

A catch-all (accept-all) domain accepts mail to any address, so an SMTP check can't prove a specific mailbox exists. The only reliable resolutions are a second-pass deliverability engine that tests behaviour beyond the accept, or corroborating the address from an independent source. OS Tools runs a second-pass on risky and catch-all results and refunds the credit when the result is still uncertain — so you never pay for "unknown".

  • Never bulk-send to unresolved catch-alls — they're the main hidden source of hard bounces.
  • Don't delete them either — a large share are real mailboxes at real companies.
  • Do resolve what you can, then send the remainder on a separate warmed domain at low volume.

Why catch-all exists

An administrator configures the domain to accept mail to any local part so that misaddressed mail isn't lost. Microsoft 365 and Google Workspace both make this a one-click setting, and many managed IT providers turn it on by default. The result: anything@company.com gets a 250 OK at the SMTP layer, whether or not a mailbox exists behind it.

That's fatal for standard verification, which relies on the receiving server rejecting unknown recipients. No rejection means no signal.

What each approach can and can't do

ApproachWhat it doesResolves catch-all?
Syntax + MX checkValidates format and that the domain accepts mailNo
Standard SMTP RCPT checkAsks the server if the mailbox existsNo — server accepts everything
Database/cache lookupReturns a previously observed verdictOnly if the address was seen before
Second-pass deliverability engineTests behaviour beyond the accept to separate real mailboxes from accepted-then-discardedOften, but not always
Independent corroborationConfirms the person and pattern from another sourcePartially — raises confidence, not proof
Send-and-observeLow-volume send on an isolated domain, watch bouncesDefinitively — but at reputation risk

The commercial problem: paying for non-answers

Most verifiers bill per address submitted, including addresses returned as unknown, risky or accept-all. If 30% of a 10,000-row list is catch-all, you have paid for 3,000 rows and learned nothing about them. Your effective cost per actionable verdict is 1.4x the headline rate.

Two things fix this: a vendor that attempts a genuine second pass, and a vendor that refunds when it still can't decide. OS Tools does both — risky and catch-all results go to a second engine, and anything still unresolved is refunded automatically rather than sold to you as "unknown".

A practical playbook

  1. Segment. Split the verified file into valid, invalid, and catch-all/unknown. Never merge them back into one send.
  2. Second-pass the catch-alls. Whatever resolves, moves to the valid segment.
  3. Prioritise by pattern confidence. An address matching the domain's observed pattern (first.last@) at a company where you have other confirmed contacts is far safer than a guessed pattern.
  4. Isolate the send. Remaining catch-alls go out from a separate warmed domain, 20–30 per day, so bounces can't damage your primary sending reputation.
  5. Watch the bounce rate per segment. If the catch-all segment bounces above 5%, stop and re-source rather than pushing volume.

Keep overall hard bounces under 2%, and ideally under 1%. Mailbox providers read bounce rate as a spam signal, and reputation damage from a single bad send can take months to recover.

What not to do

  • Don't treat accept-all as valid. It's the single most common cause of a "verified" list bouncing.
  • Don't discard them wholesale unless deliverability risk outweighs the pipeline — plenty of good accounts run catch-all.
  • Don't re-verify the same address across three vendors hoping one says valid. They're all guessing at the same missing signal; you're just paying three times.

Frequently asked questions

What is a catch-all email address?

A catch-all (or accept-all) domain is configured to accept mail sent to any address at that domain, whether or not the mailbox exists. Standard verification can't tell a real mailbox from a typo on such a domain, so most tools return 'unknown'.

Is it safe to email catch-all addresses?

Only with care. Unresolved catch-alls are the main hidden source of hard bounces on 'verified' lists. Send them from a separate warmed domain at low daily volume, monitor bounces per segment, and stop if the segment exceeds about 5%.

Can catch-all emails be verified at all?

Some can. A second-pass deliverability engine tests behaviour beyond the initial accept and resolves a meaningful share of them. The rest are genuinely undecidable without sending, which is why a vendor that refunds unresolved results is worth more than one claiming to verify everything.

What percentage of a B2B list is catch-all?

Typically 20–40%, higher in markets dominated by managed IT providers who enable accept-all by default. It is normal and does not mean your list is bad.

Should I pay for unknown or risky results?

No. An unknown result gives you nothing to act on. OS Tools refunds the credit for any result it can't settle confidently, so the effective cost per actionable verdict stays close to the headline rate.

Try it

OS Tools is pay-as-you-go, no subscription, and every new account starts with 200 free credits. Upload a CSV, get the cleaned file back with your original columns preserved.

Start free with 200 credits