Catch-All Email Verifier: How to Check Catch-All Addresses
By Aria Pramesi, founder of InboxPolicy · Updated July 9, 2026
Looking for a catchall email verifier or a quick catch all email checker? Catch-all domains, also called accept-all domains, accept mail sent to any address, so no verifier can confirm a specific mailbox by SMTP response alone. An accept-all domain is functionally the same problem under a different name. About 30-40% of B2B email addresses sit on catch-all domains. Use the free check below to validate catch-all emails at the format and MX level, then get an honest send / review / avoid decision, InboxPolicy never guesses a catch-all address is safe.
Check an email address
Free format + MX check, runs in your browser. No signup.
Why can't SMTP verify a catch-all address?
A catch-all domain is configured to accept mail sent to any address at that domain, whether or not a specific mailbox exists behind it. When a verification engine opens an SMTP session to check a mailbox on a catch-all domain, the mail server accepts the recipient regardless of whether the exact address is real, made up, or mistyped.
That means the one signal most verification tools rely on, an SMTP accept or reject response, doesn't distinguish a real mailbox from a nonexistent one on these domains. InboxPolicy's engine still runs the full sequence, syntax, MX, and live SMTP, but on a catch-all domain the SMTP step returns evidence that can't confirm the specific mailbox either way.
How common is catch-all in B2B email lists?
Roughly 30-40% of B2B addresses sit on catch-all domains, based on InboxPolicy's verification data. That's not a fringe case. On a typical outbound or cold-email list, a third or more of contacts can come back with an unresolved mailbox status, which makes how a verification tool handles catch-all results one of the bigger factors in overall list quality.
What action does InboxPolicy return for a catch-all result?
InboxPolicy tags the normalized signals with catch_all and, by default, maps that evidence to the action review, not send. Under a more aggressive policy configuration, the same evidence can map to send_with_caution instead. Either way, InboxPolicy never returns send for an address it cannot confirm exists.
The decide_send response includes a confidence score and normalized signals for catch-all, disposable, free, and role-account status. The verify_email tool and /v1/verify endpoint provide the full verification detail.
Should you ever send to a catch-all address anyway?
A review or send_with_caution result isn't a rejection, it's an honest admission that SMTP alone can't resolve the mailbox. If you have other signals, a prior reply, a form-submitted address, known engagement history, those can inform the send decision alongside InboxPolicy's evidence.
What InboxPolicy won't do is guess. Unknown results route to review. Catch-all results route to review by default or send_with_caution under aggressive strictness; neither is silently marked safe. That's a deliberate tradeoff between coverage and false confidence.
How do other verification tools handle catch-all addresses?
Most verification tools return a status field rather than a send decision, so catch-all handling comes down to how aggressively they try to resolve the unknown versus how clearly they flag it. See the comparison below for what's publicly documented about each.
- MillionVerifier resolves unknowns aggressively and runs $3.90/1k at entry down to $0.45/1k at 1M volume; InboxPolicy Growth is $79 for 25,000 ($3.16/1k), while MillionVerifier's entry is $39 for 10,000 ($3.90/1k), a lower total purchase; MillionVerifier also wins on unit price at 1M ($0.45/1k) for one-shot bulk list cleaning.
- ZeroBounce and Kickbox report catch-all and other results through status fields (Kickbox adds a Sendex quality score), aimed at a dashboard workflow rather than a real-time send decision.
- Emailable is a dashboard-first verification suite built around bulk uploads and integrations.
| Tool | Entry price | Catch-all handling | Free tier |
|---|---|---|---|
| InboxPolicy | $0.01 per fresh verification (pay-per-call, x402), or credit packs from $5.00/1k down to $3.16/1k at Growth volume | Tags catch_all evidence, returns review by default or send_with_caution under an aggressive policy, never guessed safe | None; cache re-verification (72 hrs), malformed rejection instead |
| ZeroBounce | ~$9.90/1k sub | Reports via status field; also maintains a spam-trap/abuse address database | 100 emails/month |
| Kickbox | ~$10.00 per 1,000 | Reports via status field plus a Sendex quality score | One-time free credits |
| MillionVerifier | $3.90–0.45/1k | Resolves unknowns aggressively; positioned for one-shot bulk list cleaning | Yes, free tier available |
| Emailable | ~$6.46/1k sub | Dashboard-first suite with bulk uploads and integrations; catch-all handling not detailed publicly | 250 signup credits (live pricing reviewed 2026-07-20) |
Catch-all guides
Dig into specific tools and scenarios: Apollo's catch-all domain flag explains what it means and what to do next; catch-all flags in Instantly, Smartlead, and Clay covers how the major cold-email platforms surface catch-all results; are catch-all emails safe to send to weighs the risk of sending anyway; and catch-all vs accept-all settles the terminology question once and for all.
Frequently asked questions
What is a catch-all email domain?
A catch-all domain is configured to accept mail sent to any address at that domain, whether or not a real mailbox exists. Because the mail server won't reject invalid addresses at the SMTP level, verification tools can't confirm a specific mailbox by SMTP response alone. This makes catch-all domains a blind spot for any tool that only reports mailbox status.
What percentage of B2B emails are catch-all?
Roughly 30-40% of B2B email addresses sit on catch-all domains, based on InboxPolicy's verification data. That means catch-all handling isn't an edge case, it affects a third or more of typical business-to-business contact lists, so how a tool treats catch-all results has a real impact on list quality and sender reputation.
Does InboxPolicy ever mark a catch-all address as safe to send?
No. InboxPolicy tags catch-all evidence with catch_all and returns the action review by default, never guessing the mailbox is valid. Under a more aggressive policy configuration it can return send_with_caution instead, but it will not silently return send for an address it cannot confirm exists.
Is a catch-all result the same as an invalid email?
No. Catch-all means the verification engine could not confirm or deny the mailbox exists because the domain accepts all mail. It is not a bounce prediction. InboxPolicy separates this from malformed or clearly invalid addresses, which are rejected before any SMTP check runs and never billed.
Which tool should I use for a catch-all-heavy list I just want to clean once?
For one-shot cleaning of a large scraped list at the lowest cost, MillionVerifier runs $3.90/1k at entry down to $0.45/1k at 1M volume; InboxPolicy Growth is $79 for 25,000 ($3.16/1k), while MillionVerifier's entry is $39 for 10,000 ($3.90/1k), a lower total purchase; MillionVerifier also wins on unit price at 1M ($0.45/1k). InboxPolicy is built for per-send decisions in live agent workflows, not one-time bulk list cleaning, so pricing and workflow fit differ.
How does InboxPolicy price catch-all verifications?
The same as any other verification, $0.01 per fresh check via pay-per-call x402, or from a prepaid credit pack such as Starter ($5 for 1,000 credits) or Growth ($79 for 25,000 credits). A cache hit within 72 hours returns from_cache and costs 0 credits, even for a previously seen catch-all result.
What is the best catch-all email verifier?
The best catch-all email verifier for your case depends on the job. For one-shot bulk list cleaning, a resolver like MillionVerifier is priced for that workflow. For live, per-send decisions inside an agent or outbound tool, InboxPolicy is built for that: it runs syntax, MX, and SMTP checks, tags catch-all evidence honestly, and returns a send / send_with_caution / review / retry_later / avoid decision for $0.01 per check instead of a bare status label.
How do you verify a catch-all email without sending?
You can't fully verify a specific mailbox on a catch-all domain without sending, because the SMTP server accepts RCPT TO for any address. What you can do without sending is confirm the address is well-formed and that the domain has valid MX records, then treat the mailbox itself as unresolved. InboxPolicy runs this full check and returns review by default, or send_with_caution under aggressive strictness, with the catch_all evidence tag rather than guessing the mailbox is safe.
Can you check if a catch-all domain will bounce?
You can check whether the domain itself is reachable, has valid MX records, and accepts mail, which rules out hard bounces from a dead or misconfigured domain. What you can't determine from SMTP alone is whether a specific mailbox on a catch-all domain exists, since the server accepts everything. InboxPolicy reports both: domain-level deliverability evidence and an honest review flag for the unresolved mailbox.
What does it mean when Apollo flags a domain as catch-all?
When Apollo flags a domain as catch-all, it means Apollo's own verification couldn't confirm the specific mailbox exists because the domain accepts mail for any address at that domain. It does not mean the address is invalid. See our guide on Apollo's catch-all domain flag for how to handle those contacts before sending.