Catch-All Emails: What They Are and Whether to Send to Them
A catch-all domain accepts mail for any address, so no check can confirm the mailbox. Learn what that means for bounces and when sending is worth it.
By the Glintscout team8 min read
On this page
A catch-all email address belongs to a domain whose mail server accepts messages for every address, whether or not a mailbox by that name exists. Because the server says yes to everything, no verification check can tell you whether your specific address is real. Treat catch-all addresses as unconfirmed: keep them out of your main campaign, and send to them only in a small, separate batch that you watch for bounces.
What a catch-all email address is
An email address has two parts: the mailbox name before the @ and the domain after it. Normally, a domain's mail server knows which mailboxes exist and refuses mail for the rest, so a message to a name that doesn't exist bounces.
A catch-all domain (also called accept-all) is set up differently. Its server accepts mail for any name at the domain. The message then goes to the matching mailbox if there is one, to a shared catch-all inbox if there isn't, or wherever else the owner decided.
For example, picture a fictional dental practice on the domain harbordental.example with a catch-all. Mail to frontdesk@, to dr.lee@ and to a typo like fronddesk@ is accepted in exactly the same way. From the outside, you can't tell which of the three is a real mailbox.
Why businesses set up catch-all domains
A catch-all is usually a convenience for the business, not a trap for senders:
- Misspelled addresses still arrive. A customer who gets the name wrong still reaches the business.
- Mail to former staff isn't lost. When someone leaves, messages to their old address keep coming in.
- One inbox runs everything. Small businesses often route every address to the owner or the front desk.
- The mail provider offers it. Google Workspace, for example, can deliver mail for unrecognized recipients to a chosen mailbox (Google's setup guide), and web hosting control panels commonly have a similar "default address" setting.
Some domains behave like catch-alls for technical reasons. Certain email security gateways accept every recipient at the edge and sort out the real ones later, which also stops outsiders from testing which addresses exist. And in Microsoft 365, only domains set as authoritative reject unknown recipients at the door; a domain set to internal relay, common during migrations and in hybrid setups, passes mail for addresses it doesn't know on to another server (Microsoft's documentation).
For you as a sender, the reason doesn't change the outcome: the server's answer tells you nothing about your address.
How verification spots a catch-all domain
Verifying an address without sending an email means starting the conversation that would deliver a message and stopping before anything is sent. The checker looks up the domain's mail servers (its MX records), connects to one, names a sender and then names the recipient. A server that knows the mailbox doesn't exist refuses the recipient right there, typically with a 550 reply (RFC 5321, section 3.3). That refusal is what makes an address invalid.
To spot a catch-all, a careful checker first asks about an address that can't exist, such as a long random string at the same domain. If the server accepts that too, it accepts everything, and its yes for your real address proves nothing. The address gets a catch-all verdict instead of valid. The SMTP standard itself notes that when a server defers checking recipients until after the message arrives, the recipient step "may return no information at all" (RFC 5321, section 7.3).
Our guide to verifying an email address without sending walks through the whole check and what each verdict means.
Glintscout reports catch-all as a verdict of its own, next to valid, invalid and unknown. When you build a list with its Google Maps search, only addresses verified as valid reach the CSV export, so catch-alls can't slip into a campaign unnoticed.
What happens when you send to a catch-all address
If you send anyway, one of four things happens, and from your side most of them look the same:
- The mailbox exists and your email arrives. The best case, and the likeliest one when the business published the address itself.
- It lands in a shared catch-all inbox. Someone may read it, forward it or ignore it. At a small business, that inbox is often the owner's.
- It's accepted, then bounced. Some servers accept first and check recipients later. The standard requires a server that can't deliver a message it already accepted to send a failure notice back to the sender (RFC 5321, section 6.1), so the bounce can arrive minutes or hours after your tool marked the email as sent.
- It's silently dropped. Some systems discard mail for unknown recipients without telling anyone. No bounce, no reply, and no way to tell it apart from being ignored.
The third outcome is the one that hurts. A late bounce counts against your bounce rate like any other, and it's how a campaign with a clean send log can still collect bounces the next day. Our guide to email bounce rates covers what level is safe and how to stay under it.
Key takeaway: a catch-all verdict doesn't mean "probably valid". It means the check learned nothing about that address, so its real risk depends on where the address came from.
Should you send to catch-all addresses?
It depends on three things: how the address was found, how healthy your sending domain is and how much the prospect matters. Use this table for each address or segment:
| Factor | Leans toward sending | Leans toward skipping |
|---|---|---|
| Where the address came from | Published on the business's own website | Guessed from a name pattern |
| Type of address | Role address at a small business (info@, office@) | A named person at a larger company |
| Your sending domain | Warmed up, with a clean bounce history | New, or already bouncing |
| Share of your list | A small slice you can send separately | Most of the list |
| Value of the prospect | Moderate: worth one test email | High: worth a call or another channel |
The source matters most. An address the business published on its own website is one it expects to receive mail at. A pattern guess such as jane.smith@ on a catch-all domain has nothing behind it: the server would have accepted it whether Jane works there or not. Named people at larger companies carry an extra risk, because a catch-all keeps accepting mail for staff who left years ago.
A practical rule: send to catch-all addresses only when you could live with some of them bouncing, and never in the same batch as your verified addresses.
How to send to catch-all addresses with less risk
If you decide to send, do it deliberately:
- Keep them in their own segment. Tag or export catch-alls separately so their results can't hide inside your main campaign's numbers.
- Send to verified addresses first. If the main campaign is already near your bounce limit, fix that before adding risk.
- Start small. Send a batch you could afford to lose, from a warmed-up mailbox, at your normal daily pace.
- Wait for late bounces. A common rule of thumb is to give each batch a day or two before sending the next, since accept-then-bounce servers report late.
- Suppress every bounce at once. An address that hard-bounced should never be emailed again, from any of your mailboxes.
- Stop at your threshold. If the segment's hard bounces pass the limit you set for the whole campaign (a common rule of thumb is 2%), stop sending to catch-alls from that source.
- Skip pattern guesses. On a catch-all domain, a guessed address is exactly that: a guess nobody can check.
Better routes to prospects who matter
For a prospect you really want, an unconfirmed address is the weakest way in. Better options:
- The address the business publishes. Check the contact page, the footer and the about page. Our guide to finding a company's email address covers where to look.
- The contact form. It goes wherever the business wants inquiries to go. Keep your message as short as a cold email.
- A phone call. For a local business, a short call asking who handles, say, the website can get you a name and a confirmed address in under a minute.
- A two-line email to the general inbox. Asking a published info@ address who handles marketing is low-risk, and a reply confirms the address you actually need.
FAQ
Is a catch-all email address valid?
It might be. The address may belong to a real mailbox, or it may exist only because the domain accepts everything. A catch-all verdict means the check can't tell, which is why it's reported separately from valid and invalid.
What's the difference between catch-all and unknown?
Catch-all means the server answered and accepted a made-up address, so its answers can't be trusted. Unknown means the server gave no usable answer: it timed out, blocked the check or deferred it, as servers using greylisting do with unfamiliar senders. An unknown address can come back valid or invalid on a later check (Glintscout offers an optional second verification for these, listed on the pricing page), while a catch-all domain keeps accepting everything.
Why do verification tools disagree about catch-all addresses?
Some servers answer differently from one check to the next, and some tools go beyond the mail server check, labeling catch-all addresses "likely valid" based on other signals. Treat those labels as estimates, not confirmations.
Does sending to catch-all emails hurt deliverability?
Not by itself: mail that is accepted and delivered doesn't count against you. The risk is in the addresses that bounce later, which count toward your bounce rate like any other. Keep catch-alls a small, separate share of your sending and the risk stays manageable.
Should my own domain have a catch-all?
It's a trade-off. A catch-all makes sure misaddressed mail reaches you, but it also collects spam sent to invented addresses, and it makes every address at your domain impossible for others to verify. If you use one, route it to a mailbox someone checks, and filter it.
Keep reading
All articlesEmail verification
How to Verify an Email Address Without Sending an Email
Verify an email address without sending one: syntax, domain and MX checks, the SMTP handshake, catch-all and greylisting, and what each verdict means.
10 min read
Email verification
What Is a Good Email Bounce Rate (and How to Lower It)
What a good email bounce rate is, hard vs soft bounces with real error codes, and a checklist to keep bounces low before they hurt your domain.
9 min read
Outreach
10 Cold Email Templates for Selling to Local Businesses
10 cold email templates for web design, SEO, booking software, reviews and ads offers to local businesses, with why each line works and a follow-up.
13 min read