Prices increase in 00D : 00H : 00M Upgrade now Pay less later.

Blog / Technical Guide

Catch-All Domain Detection: MailValid API vs ZeroBounce vs NeverBounce (2026)

Catch-All Domain Detection: MailValid API vs ZeroBounce vs NeverBounce (2026)

Catch-All Domains Are Sabotaging Your Email Deliverability

Your campaign dashboard shows 98% delivery. Your reply rate is near zero. Something doesn't add up.

The culprit is likely catch-all domains — mail servers configured to accept every email sent to them, regardless of whether the specific mailbox exists. Your ESP marks these as "delivered," but the emails may never reach a real inbox. No opens. No clicks. No bounces. Just silent failure.

Detect catch-all domains before you send → Get 100 free MailValid credits

For cold email teams, newsletter operators, and SaaS companies, catch-all domains represent one of the biggest hidden threats to sender reputation. This guide explains exactly how catch-all servers work, why standard verification misses them, and how MailValid's email verification API detects them.

What Is a Catch-All Domain?

A catch-all domain is configured to accept email for any address at that domain, even if the specific mailbox doesn't exist. When an email arrives, the server accepts it during the SMTP handshake — then either drops it silently, forwards it to a central mailbox, or generates an auto-reply.

Real-World Examples

Domain Type Catch-All Behavior Common At
Large enterprises Accept all, route to admin Fortune 500, banks
Universities Accept all, forward to IT .edu domains
Government Accept all, filter centrally .gov domains
Small businesses Accept all, owner checks periodically Family-owned companies
Defunct companies Accept all, no one reads Acquired/shutdown firms

Why ESPs Care About Catch-Alls

Email service providers (Gmail, Outlook, Yahoo) use engagement signals to rank sender quality. When you send to catch-all domains:

  1. The email is "delivered" — so your bounce rate looks healthy
  2. No human may ever open it — so engagement can be zero
  3. ESPs can interpret sustained zero engagement as low-quality sending
  4. Your future emails to real addresses may start landing in spam

Why Standard Email Verification Fails on Catch-Alls

Most basic verification tools use one of three methods. Only the third catches catch-alls.

Method 1: Syntax Validation (Worthless for Catch-Alls)

Regex checks whether the email looks valid. user@company.com passes. But on a catch-all domain, every syntactically valid address passes — even fakeuser123@company.com.

Method 2: MX Record Lookup (Also Worthless)

MX checks confirm the domain has a mail server. Catch-all domains have perfectly valid MX records. This test tells you the domain accepts mail — which is true, but useless for mailbox-specific verification.

Method 3: SMTP Handshake with Randomized Probing (The Only Fix)

True catch-all detection requires an extra step during SMTP verification:

  1. Connect to the mail server
  2. Attempt delivery to the target address
  3. Also attempt delivery to a guaranteed-nonexistent address at the same domain
  4. If the server accepts both, the domain is catch-all
  5. If the server rejects the random address but accepts the target, the target is likely real

This randomized probing is the detection method MailValid's verification API uses.

How MailValid Detects Catch-All Domains

Here's the actual documented request and response shape.

import requests

API_KEY = "your_mailvalid_api_key"

def check_catch_all(email):
    resp = requests.post(
        "https://mailvalid.io/api/v1/verify/single",
        headers={"X-API-Key": API_KEY, "Content-Type": "application/json"},
        json={"email": email}
    )
    result = resp.json()["result"]

    if result["is_catch_all"]:
        return {
            "safe_to_send": False,
            "reason": "Catch-all domain detected",
            "risk": "HIGH",
            "details": result
        }

    if result["is_valid"] and not result["is_disposable"]:
        return {
            "safe_to_send": True,
            "reason": "Verified real mailbox",
            "risk": "LOW",
            "details": result
        }

    return {
        "safe_to_send": False,
        "reason": result["status_reason"],
        "risk": "HIGH",
        "details": result
    }

# Test addresses
test_emails = [
    "ceo@real-startup.com",
    "fake123@enterprise-catchall.com",
    "admin@university.edu"
]

for email in test_emails:
    result = check_catch_all(email)
    print(f"{email}: {result['risk']} — {result['reason']}")

Documented API Response

{
  "success": true,
  "credits_used": 1,
  "result": {
    "email": "user@enterprise.com",
    "status": "catch_all",
    "is_valid": false,
    "domain": "enterprise.com",
    "has_mx": true,
    "mx_records": [{"priority": 10, "host": "mx.enterprise.com"}],
    "smtp_checked": true,
    "is_disposable": false,
    "is_role_based": false,
    "is_catch_all": true,
    "confidence_score": 40,
    "status_reason": "catch_all_domain"
  }
}

Notice: status: "catch_all" and is_catch_all: true together. A naive tool that only checks syntax and MX would incorrectly tell you to send. MailValid tells you the domain accepts everything, so a specific mailbox can't be confirmed.

JavaScript: Real-Time Catch-All Detection

async function verifyBeforeSend(email) {
  const response = await fetch('https://mailvalid.io/api/v1/verify/single', {
    method: 'POST',
    headers: {
      'X-API-Key': 'YOUR_API_KEY',
      'Content-Type': 'application/json'
    },
    body: JSON.stringify({ email })
  });
  const { result } = await response.json();

  if (result.is_catch_all) {
    return {
      send: false,
      reason: 'Catch-all domain — cannot confirm mailbox exists',
      flag: 'catch_all'
    };
  }

  if (!result.is_valid || result.is_disposable) {
    return { send: false, reason: result.status_reason, flag: 'invalid' };
  }

  return { send: true, flag: 'verified' };
}

const check = await verifyBeforeSend('prospect@company.com');
console.log(check.send ? 'Safe to send' : `Blocked: ${check.reason}`);

The Business Impact of Catch-All Domains

Wasted Send Volume

B2B lists commonly contain a meaningful share of catch-all domains (enterprises, .edu, .gov). Flagging and separating these before a send protects your budget and your reputation.

Inflated Metrics

Catch-alls can make a campaign look healthier than it is: delivery rate looks fine, but open and reply rates on those addresses are often near zero since you can't confirm a human received the message.

Reputation Risk

ESPs track engagement per domain over time. Sending large volumes to catch-alls with zero engagement can signal low-quality sending, which risks legitimate emails to real mailboxes also landing in spam.

How to Handle Catch-All Domains in Your Workflow

For cold outreach, the safest approach is removing catch-all domains entirely. You lose some potential real addresses at those domains, but you protect your domain reputation.

Option 2: Separate Low-Volume Sequence

For newsletter or transactional senders, create a separate sequence for catch-all domains: send at lower volume, monitor engagement aggressively, and suppress the domain if engagement stays at zero.

Option 3: Domain-Level Targeting

Use MailValid's API to build a "safe domain" list based on verified real mailboxes:

safe_domains = set()
risky_domains = set()

for email in email_list:
    result = check_catch_all(email)["details"]
    domain = email.split('@')[1]

    if result["is_valid"] and not result["is_catch_all"]:
        safe_domains.add(domain)
    elif result["is_catch_all"]:
        risky_domains.add(domain)

print(f"Safe domains: {len(safe_domains)}")
print(f"Catch-all domains flagged: {len(risky_domains)}")

MailValid Pricing

Plan Monthly Price Credits Per-Email Cost
Free $0 100 (one-time) —
Starter $15/mo 10,000 $0.0015
Growth $50/mo 50,000 $0.001
Scale $75/mo 100,000+ $0.00075

Catch-all detection is included in every verification at no extra charge.

FAQ: Catch-All Domain Detection

Are catch-all domains always bad?

Not always. For transactional emails (receipts, password resets), catch-alls still ensure delivery even if the user typo'd their address. For marketing and cold email, they're riskier because you can't confirm a human received the message.

Can I detect catch-alls without an API?

Technically yes, but it's unreliable. You'd need to script SMTP connections, generate randomized addresses, and interpret server responses — all while managing rate limits and blocklisting risks.

Does MailValid charge extra for catch-all detection?

No. It's included in the standard per-verification price on every plan.

Can I try MailValid for free?

Yes — 100 free verification credits. Sign up here →

Don't Let Catch-Alls Hide Your Real Performance

Catch-all domains can make campaigns look more successful than they are while quietly risking your sender reputation. The only solution is detection at the point of verification, before the email ever leaves your server.

Get 100 free credits and audit your list for catch-alls today →

See MailValid's pricing →

Last Updated - 21 September 2026

M

MailValid Team

Email verification experts

Share:

Join teams that verify before they send

Stop letting bad emails hurt your deliverability

100 free credits. From $0.0008/email after. Credits never expire. No credit card required.

More from MailValid

Verify 100 emails free Start Free