Catch-All Domains Are Sabotaging Your Email Deliverability
Your campaign dashboard shows 98% delivery. Your reply rate is near zero. Something doesn't add up.
The culprit is likely catch-all domains — mail servers configured to accept every email sent to them, regardless of whether the specific mailbox exists. Your ESP marks these as "delivered," but the emails may never reach a real inbox. No opens. No clicks. No bounces. Just silent failure.
Detect catch-all domains before you send → Get 100 free MailValid credits
For cold email teams, newsletter operators, and SaaS companies, catch-all domains represent one of the biggest hidden threats to sender reputation. This guide explains exactly how catch-all servers work, why standard verification misses them, and how MailValid's email verification API detects them.
What Is a Catch-All Domain?
A catch-all domain is configured to accept email for any address at that domain, even if the specific mailbox doesn't exist. When an email arrives, the server accepts it during the SMTP handshake — then either drops it silently, forwards it to a central mailbox, or generates an auto-reply.
Real-World Examples
| Domain Type | Catch-All Behavior | Common At |
|---|---|---|
| Large enterprises | Accept all, route to admin | Fortune 500, banks |
| Universities | Accept all, forward to IT | .edu domains |
| Government | Accept all, filter centrally | .gov domains |
| Small businesses | Accept all, owner checks periodically | Family-owned companies |
| Defunct companies | Accept all, no one reads | Acquired/shutdown firms |
Why ESPs Care About Catch-Alls
Email service providers (Gmail, Outlook, Yahoo) use engagement signals to rank sender quality. When you send to catch-all domains:
- The email is "delivered" — so your bounce rate looks healthy
- No human may ever open it — so engagement can be zero
- ESPs can interpret sustained zero engagement as low-quality sending
- Your future emails to real addresses may start landing in spam
Why Standard Email Verification Fails on Catch-Alls
Most basic verification tools use one of three methods. Only the third catches catch-alls.
Method 1: Syntax Validation (Worthless for Catch-Alls)
Regex checks whether the email looks valid. user@company.com passes. But on a catch-all domain, every syntactically valid address passes — even fakeuser123@company.com.
Method 2: MX Record Lookup (Also Worthless)
MX checks confirm the domain has a mail server. Catch-all domains have perfectly valid MX records. This test tells you the domain accepts mail — which is true, but useless for mailbox-specific verification.
Method 3: SMTP Handshake with Randomized Probing (The Only Fix)
True catch-all detection requires an extra step during SMTP verification:
- Connect to the mail server
- Attempt delivery to the target address
- Also attempt delivery to a guaranteed-nonexistent address at the same domain
- If the server accepts both, the domain is catch-all
- If the server rejects the random address but accepts the target, the target is likely real
This randomized probing is the detection method MailValid's verification API uses.
How MailValid Detects Catch-All Domains
Here's the actual documented request and response shape.
import requests
API_KEY = "your_mailvalid_api_key"
def check_catch_all(email):
resp = requests.post(
"https://mailvalid.io/api/v1/verify/single",
headers={"X-API-Key": API_KEY, "Content-Type": "application/json"},
json={"email": email}
)
result = resp.json()["result"]
if result["is_catch_all"]:
return {
"safe_to_send": False,
"reason": "Catch-all domain detected",
"risk": "HIGH",
"details": result
}
if result["is_valid"] and not result["is_disposable"]:
return {
"safe_to_send": True,
"reason": "Verified real mailbox",
"risk": "LOW",
"details": result
}
return {
"safe_to_send": False,
"reason": result["status_reason"],
"risk": "HIGH",
"details": result
}
# Test addresses
test_emails = [
"ceo@real-startup.com",
"fake123@enterprise-catchall.com",
"admin@university.edu"
]
for email in test_emails:
result = check_catch_all(email)
print(f"{email}: {result['risk']} — {result['reason']}")
Documented API Response
{
"success": true,
"credits_used": 1,
"result": {
"email": "user@enterprise.com",
"status": "catch_all",
"is_valid": false,
"domain": "enterprise.com",
"has_mx": true,
"mx_records": [{"priority": 10, "host": "mx.enterprise.com"}],
"smtp_checked": true,
"is_disposable": false,
"is_role_based": false,
"is_catch_all": true,
"confidence_score": 40,
"status_reason": "catch_all_domain"
}
}
Notice: status: "catch_all" and is_catch_all: true together. A naive tool that only checks syntax and MX would incorrectly tell you to send. MailValid tells you the domain accepts everything, so a specific mailbox can't be confirmed.
JavaScript: Real-Time Catch-All Detection
async function verifyBeforeSend(email) {
const response = await fetch('https://mailvalid.io/api/v1/verify/single', {
method: 'POST',
headers: {
'X-API-Key': 'YOUR_API_KEY',
'Content-Type': 'application/json'
},
body: JSON.stringify({ email })
});
const { result } = await response.json();
if (result.is_catch_all) {
return {
send: false,
reason: 'Catch-all domain — cannot confirm mailbox exists',
flag: 'catch_all'
};
}
if (!result.is_valid || result.is_disposable) {
return { send: false, reason: result.status_reason, flag: 'invalid' };
}
return { send: true, flag: 'verified' };
}
const check = await verifyBeforeSend('prospect@company.com');
console.log(check.send ? 'Safe to send' : `Blocked: ${check.reason}`);
The Business Impact of Catch-All Domains
Wasted Send Volume
B2B lists commonly contain a meaningful share of catch-all domains (enterprises, .edu, .gov). Flagging and separating these before a send protects your budget and your reputation.
Inflated Metrics
Catch-alls can make a campaign look healthier than it is: delivery rate looks fine, but open and reply rates on those addresses are often near zero since you can't confirm a human received the message.
Reputation Risk
ESPs track engagement per domain over time. Sending large volumes to catch-alls with zero engagement can signal low-quality sending, which risks legitimate emails to real mailboxes also landing in spam.
How to Handle Catch-All Domains in Your Workflow
Option 1: Exclude Entirely (Recommended for Cold Email)
For cold outreach, the safest approach is removing catch-all domains entirely. You lose some potential real addresses at those domains, but you protect your domain reputation.
Option 2: Separate Low-Volume Sequence
For newsletter or transactional senders, create a separate sequence for catch-all domains: send at lower volume, monitor engagement aggressively, and suppress the domain if engagement stays at zero.
Option 3: Domain-Level Targeting
Use MailValid's API to build a "safe domain" list based on verified real mailboxes:
safe_domains = set()
risky_domains = set()
for email in email_list:
result = check_catch_all(email)["details"]
domain = email.split('@')[1]
if result["is_valid"] and not result["is_catch_all"]:
safe_domains.add(domain)
elif result["is_catch_all"]:
risky_domains.add(domain)
print(f"Safe domains: {len(safe_domains)}")
print(f"Catch-all domains flagged: {len(risky_domains)}")
MailValid Pricing
| Plan | Monthly Price | Credits | Per-Email Cost |
|---|---|---|---|
| Free | $0 | 100 (one-time) | — |
| Starter | $15/mo | 10,000 | $0.0015 |
| Growth | $50/mo | 50,000 | $0.001 |
| Scale | $75/mo | 100,000+ | $0.00075 |
Catch-all detection is included in every verification at no extra charge.
FAQ: Catch-All Domain Detection
Are catch-all domains always bad?
Not always. For transactional emails (receipts, password resets), catch-alls still ensure delivery even if the user typo'd their address. For marketing and cold email, they're riskier because you can't confirm a human received the message.
Can I detect catch-alls without an API?
Technically yes, but it's unreliable. You'd need to script SMTP connections, generate randomized addresses, and interpret server responses — all while managing rate limits and blocklisting risks.
Does MailValid charge extra for catch-all detection?
No. It's included in the standard per-verification price on every plan.
Can I try MailValid for free?
Yes — 100 free verification credits. Sign up here →
Don't Let Catch-Alls Hide Your Real Performance
Catch-all domains can make campaigns look more successful than they are while quietly risking your sender reputation. The only solution is detection at the point of verification, before the email ever leaves your server.
Get 100 free credits and audit your list for catch-alls today →
Last Updated - 21 September 2026
MailValid Team
Email verification experts
Join teams that verify before they send
Stop letting bad emails hurt your deliverability
100 free credits. From $0.0008/email after. Credits never expire. No credit card required.