Catch-all addresses
A catch-all (or accept-all) domain tells every sender “yes, that mailbox exists” — for every address, real or not. Some companies set it up so they never lose mail sent to a typo; many security gateways (Proofpoint, Mimecast and similar) behave the same way in front of the real mailbox.
For you, it means the mail server’s “yes” proves nothing. jane@acme.com and zzz-made-up@acme.com get the same answer.
How EmailShield detects it
Section titled “How EmailShield detects it”Catch-all is a property of the domain, so it’s tested once per domain, not once per address. EmailShield asks the domain’s mail server about an address that is realistic but made up. If the server says that one exists too, the domain is catch-all.
While that test runs, addresses on the domain show as Still resolving. They become Valid (the domain isn’t catch-all, so its “yes” is real) or Catch-All before the job finishes.
Getting past the gateway
Section titled “Getting past the gateway”When a catch-all answer comes from a security gateway, EmailShield tries to ask the email platform behind it. If that platform confirms the mailbox, the address is upgraded to Valid with the reason Mailbox confirmed at the mail platform behind the gateway. That check can only ever move an address up — a “no” from behind the gateway never makes an address invalid.
The send-risk rating
Section titled “The send-risk rating”Every catch-all address also gets a rating, shown in the results and in the export’s safe_to_send_tier column (with a 0–100 safe_to_send_score):
| Rating | What it means |
|---|---|
| likely | The address follows the same pattern as the domain’s other addresses (for example first.last@) and reads like a real person’s name. |
| uncertain | Some signals point each way. |
| risky | Doesn’t match the domain’s pattern, looks generated, or looks like a spam trap. |
The rating is worked out from your list itself — no third-party data is involved — and it’s a judgement, not a confirmation. It never changes the category: a likely catch-all is still a catch-all.
Should you send to catch-alls?
Section titled “Should you send to catch-alls?”It depends on how much risk your domains can take. Common approaches:
- Leave them out. The safest choice, especially for new domains.
- Send only to likely. Turn on Count good catch-all addresses as safe to send under Views & Export, and the likely ones join your Safe to send export.
- Send to them separately. Put catch-alls in their own campaign, at a lower daily volume, and pause it if bounces rise.