Somewhere in every list there is a company whose addresses all come back clean and none of them work. The tool said valid. The send went out. Nothing bounced, nothing replied, and three weeks later somebody noticed that a whole account had gone quiet at once. That company has a catch-all domain, and the tool was telling the truth about the wrong thing.
The server accepts everything, and it does so deliberately
When a verifier says an address is valid, it has usually held a short conversation with the receiving mail server: it opens a connection, names a sender, names the recipient, and reads the answer. A server that keeps a list of its mailboxes answers honestly. Ask it about somebody who left in 2019 and it refuses the recipient. Ask it about a person who works there and it accepts.
A catch-all domain accepts all of it. Every recipient, every spelling, every
string of nonsense in front of the at sign. An address like
qx7hd@theircompany.com is taken exactly as readily as the chief executive’s,
because the server is not consulting a list. It has been configured to take
delivery first and work out where the message goes afterwards.
Nobody sets this up to make prospecting harder. There are three ordinary reasons for it:
- A security gateway sits in front of the real mail server. It accepts the message, scans it, and only then passes it on. It cannot refuse an unknown recipient at the door, because the recipient list lives behind it.
- Somebody decided a typo should never bounce. A company that has changed its name twice, or that would rather read a misaddressed enquiry than lose it, turns the catch-all on and points the leftovers at one inbox.
- The domain was set up on a hosting package where catch-all is the default and nobody ever turned it off.
None of those is unusual and none is a warning sign about the company. Catch-all is a configuration, not a character trait. It is common at large organisations with a filtering gateway and common at very small ones on shared hosting, which happens to be both ends of most B2B lists.
So “valid” is an answer to a question you did not ask
Two different questions get collapsed into one word here.
The question the verifier asked: will this server accept mail addressed to this string? The question you wanted answered: is there a person on the other end of this mailbox who will read what I send?
On a normal domain the first is decent evidence for the second. On a catch-all
the first is evidence of nothing at all, because the answer was fixed before
your address was written. Some tools report this honestly and return
accept_all, catch-all or unknown. Others fold it into valid, because valid
is the result people buy. Both are looking at the same transcript.
The test that takes one minute and costs nothing
Take the domain and put a name in front of it that nobody could possibly have.
Something like zz-not-a-real-person@theircompany.com. Run it through whichever
verifier you use — there is no paste-one-address box on this site, but what a
check can prove sets out how to read the answer you get
back.
If the invented address comes back deliverable, the domain is a catch-all, and every other clean result you hold for that domain means the same thing as this one: nothing. If it is refused, the server is answering properly and your other results are worth what they say.
Do this once per suspicious domain before you send several hundred people at it. It buys nothing from anybody and it is the single most useful minute in list cleaning.
Three things quietly stop working
Pattern guessing starts to look like proof. Generate first.last@,
f.last@ and first@ for the same person, verify all three, and on a catch-all
all three come back valid. You now hold three confirmed addresses for one human
being, at most one of which is read. A tool that scores confidence from
acceptance will rate them equally, which is the most misleading output in this
whole category.
The bounce never arrives. Delivery was accepted, so nothing is returned to you. The message is filed in an unread catch-all mailbox, or dropped after the gateway fails to route it. Your usual feedback loop — send, read the bounce, delete the row — is gone. What you get instead is silence, and silence looks exactly like a prospect who was not interested.
Your bounce rate starts lying to you. This is the expensive one. Because the mail was accepted, your bounce statistics stay healthy while your reply rate falls, so the number you monitor gives you no reason to stop. Meanwhile the receiving side is learning that mail from your domain arrives for people who do not exist, and that judgement gets applied to the colleagues of theirs who are real. You pay for the guess in reputation rather than in bounces, and the invoice arrives late and lands on the wrong list.
Ask who has seen the address, not whether the server nodded
Once acceptance stops being evidence, there is only one useful question left: how many independent places has this address been seen in?
An independent source is a sighting that did not come from the same place as the others — a published page, a signature in a public archive, a corpus record gathered from somewhere else entirely, a previous confirmation from you. Two independent sources that agree on the same string is a fact, because the odds of two unrelated sources inventing the same mistake are small. One sighting is a claim. It might be a perfectly good claim, and it is still one person’s word.
That is what our two labels mean, and neither is a price tier. Verified means two independent sources agreed, or a verifier reached the mailbox itself. Risky means one sighting, shown to you with the sighting attached, so you can see what it rests on. On a catch-all domain the verifier route is closed by definition, so anything verified there got that way by corroboration.
Sending to a single-source address on a catch-all
It is a judgement call. The variables that should move it:
- How many at once. One address at a catch-all domain is a small bet. Three hundred people at the same parent domain, all built from the same guessed pattern, is one bet repeated three hundred times, and it settles all at once.
- Whether the pattern is corroborated elsewhere. If two colleagues at that
company are confirmed at
first.last@, a third at the same format is a better bet than a fourth format nobody has ever seen. It raises the odds on the format; it still proves nothing about whether that particular mailbox exists. - What the sending domain can afford. A domain that has been warming for three weeks has no reputation to spend. An established one can absorb a few mistakes.
- Whether there is another route. If the person is reachable on LinkedIn, an unproven address is not worth spending a first impression on.
If you do send, keep those rows in their own campaign, and watch silence rather than bounces — a segment where nobody at all replies is telling you something a bounce report will not.
What Cuvy does with them
Catch-all domains are resolved rather than guessed at, and the result keeps its label: a single sighting is presented as a single sighting, with the source, and never promoted to confirmed because a server said yes. Confirmed and single-source addresses come out of a run in separate files, so nothing unproven reaches your sequencer unless you move it there on purpose.
Two honest notes on that. A role mailbox is free and a miss is free, but an address handed to you costs one credit whether it is confirmed or single-source — which is exactly why the label stays visible rather than being smoothed away. And on a typical B2B search around 74% of people come back with an address at all, a figure that moves a long way with the sort of companies on your list. Working out your own takes an afternoon, and is the subject of another post.