Back to blog
Cold Email August 23, 2026 9 min read Jorge Lewis

Catch-All Emails in Cold Outreach: Send or Skip?

Should you email catch-all addresses? Get the verdict: why verifiers flag them risky, when to send, when to skip, and how to cap the bounce risk.

Run any B2B list through a verifier and a chunk of it comes back tagged catch-all, accept-all, or just risky. Catch-all emails in cold outreach force an awkward choice: send them and accept bounce risk you cannot fully measure, or skip them and write off a meaningful slice of your addressable market. The honest verdict is neither extreme. You send a triaged subset under strict caps, and you skip the rest without regret. This guide covers what a catch-all actually is, why verifiers refuse to bless it, and the exact triage rules for deciding which side of the line each address falls on.

This is not a theoretical question for us. Our parent agency, Referral Program Pros, has booked more than 7,000 meetings across 4,000+ outbound campaigns, and GTM Bud was built on the playbook that agency runs daily. GTM Bud also carries a reply-rate guarantee, 5 percent positive replies on LinkedIn or 1.5 percent on email, with a full refund if a campaign misses it. When you guarantee outcomes, every hard bounce is volume the guarantee depends on, burned. That forces a working policy on catch-alls rather than a shrug, and the policy below is the one we run.

What is a catch-all email address?

A catch-all email address is an address on a domain whose mail server accepts every message sent to it, whether or not the specific mailbox exists. Verifiers also call these accept-all domains. During verification, a tool asks the server whether a mailbox is real, and a catch-all server answers yes to everything, so the check learns nothing. The address might reach a named person, or it might dissolve into a monitored bucket, or bounce later in delivery. How common this is depends on who you ask: the estimates that verification providers commonly publish put catch-all configurations at 12 to 20 percent of B2B domains, while Findymail’s catch-all guide puts the figure around 30 percent of business domains. Either way, it is far too large a slice of the B2B universe to discard without a second look, and far too uncertain to mail blindly.

Why do verifiers flag catch-all emails as risky?

Because the one test that verification relies on is useless against them. A standard verifier confirms an address by probing the mail server over SMTP and reading whether the server accepts or rejects that specific mailbox. A catch-all server accepts every probe, so the verifier can only report the domain’s behavior, not the mailbox’s existence. That is what the risky, accept-all, or unknown label actually means: not “this address is bad” but “we cannot know.”

The bounce data explains the caution. Hunter’s email verification guide reports that in its tests, accept-all addresses were 27 times more likely to bounce than standard addresses, while addresses verified as valid typically bounce at under 1 percent. Some verifiers now go further than the binary label and score catch-alls probabilistically using additional signals. How each major tool labels and handles these results, and where each one is honest about its limits, is covered in our roundup of the best email verification tools, so we will not repeat the tool-by-tool detail here.

Should you send cold emails to catch-all addresses?

Yes, but only a triaged subset, and never from infrastructure you cannot afford to burn. Send the catch-alls that a specialized verifier scores as deliverable, that belong to accounts you genuinely want, and only from warmed secondary domains with live bounce monitoring. Skip unverified catch-alls in bulk, especially from purchased or scraped lists, and skip all of them while a domain is new or recovering. The math behind this verdict is simple: with catch-all configurations covering somewhere between 12 and 30 percent of B2B domains depending on whose estimate you use, skipping every catch-all silently deletes a large share of your total market, and Findymail argues that verifying rather than skipping them lets senders reach 20 to 30 percent more of their market. Deleting that much pipeline to avoid a manageable risk is not caution. It is a targeting error dressed up as one.

Here is the thing: the senders who get burned by catch-alls are almost never the ones who sent to them deliberately. They are the ones who never segmented them at all, mailed a raw list, and discovered the catch-all share of it through their bounce report.

When to send to a catch-all address

Send when the evidence outside the SMTP check points to a real person:

  • A specialized verifier scores it deliverable. Tools that model catch-alls probabilistically give you a risk score instead of a shrug. Hunter’s rule of thumb in its verification guide is to filter at a minimum 85 percent confidence score and loosen gradually based on the bounce rate you observe.
  • The person is verifiably active. A live LinkedIn profile at that company, a byline, a conference bio, or a quoted press mention makes a fabricated address unlikely. Identity evidence substitutes for mailbox evidence.
  • The account is worth the risk. A catch-all at a named target account in your ICP justifies a careful send. A catch-all on a row your data vendor threw in for volume does not.
  • Your sending domain can absorb a miss. Warmed, established, currently showing healthy bounce and spam metrics, and separate from your primary company domain.

When to skip a catch-all address

Skip when the address is unsupported, the source is dirty, or your infrastructure is fragile:

  • It came from a purchased or scraped list. These lists concentrate stale addresses, spam traps, and unverifiable catch-alls in one place, which is a core reason our answer to should you buy email lists is no.
  • No specialized verification is available. If your only signal is a generic accept-all label and you have no identity evidence, the address is a lottery ticket priced in reputation.
  • The sending domain is new, warming, or recovering. A young domain has no reputation buffer. Bounces that an established domain shrugs off can push a new one straight into the spam folder.
  • Catch-alls would dominate the campaign. When the risky segment stops being a bounded experiment and becomes the campaign itself, one bad domain batch can spike your bounce rate past the thresholds mailbox providers punish.

The catch-all send-or-skip decision matrix

SituationVerdictWhy
Verifier with catch-all scoring marks it deliverableSendThe probabilistic evidence replaces the missing SMTP evidence
Named ICP contact with an active LinkedIn presenceSend, in the capped segmentIdentity evidence makes a fabricated address unlikely
Generic accept-all label, no identity evidence, established domainSend a small test batch onlyUnknown risk, but a warmed domain can absorb a bounded test
Address from a purchased or scraped listSkipCatch-alls from dirty sources carry the worst bounce odds
Sending domain is new, warming, or recovering from a deliverability dipSkip for nowNo reputation buffer to absorb the extra bounces
Catch-alls would exceed a small share of the campaignSplit into a separate campaignContains a bounce spike so it cannot poison the whole send

How to cap the risk on the catch-alls you do send

The cap tactic is the difference between a controlled experiment and a reputation incident: bound the share, isolate the infrastructure, and pre-commit to a stop rule. Published guidance is stricter than most senders expect. Bulk Email Checker’s cold outbound guide recommends keeping catch-all addresses to 2 to 5 percent of any individual campaign, starting with test batches of 50 to 100 addresses, scaling only while bounces stay under 2 percent, and suppressing the entire batch the moment they climb. Evaboot’s catch-all guide goes a step further on isolation, recommending that catch-alls run as a separate campaign from a secondary mailbox so any damage never touches your primary sending infrastructure; its own scoring data illustrates why, with safe-rated emails averaging 97 percent deliverability against roughly 83 percent for its riskier catch-all bucket.

In practice the cap tactic has four moving parts:

  1. Segment at verification time. Every list gets split into verified, catch-all, and invalid before anything sends. Invalid is deleted, not archived.
  2. Bound the catch-all share. Keep the segment a small minority of each campaign, or run it as its own campaign entirely. Both published approaches work; mixing catch-alls invisibly into your main send is the only wrong answer.
  3. Isolate the infrastructure. Send the catch-all segment from warmed secondary domains, never your primary. If you have not set up dedicated sending domains yet, our guide to how many domains and inboxes you need for cold email covers the architecture.
  4. Pre-commit to a stop rule. Decide the bounce threshold before you send, watch the segment daily, and suppress it the moment the trend turns. Hunter’s deliverability guidance treats a bounce rate above 3 percent as a stop-and-fix signal, and the broader hygiene that keeps you far below that line is laid out in our cold email deliverability guide.

A catch-all is not a bad address. It is an unknown address. Price the unknown accordingly: small batches, separate infrastructure, and a hard stop the moment bounces move.

Where this fits in a done-for-you system

Everything above is list operations: verify, segment, cap, isolate, monitor, suppress. It is not difficult, but it has to happen on every list, every time, and skipping it once is how a month of domain warming disappears in an afternoon. GTM Bud runs this triage as part of its done-for-you outbound pipeline, so leads are verified and risk-segmented before a campaign ever sends, and volume management keeps risky segments from concentrating on any single inbox. Pricing is a flat monthly rate per connected sending account, $150 per month per email account with 600 sends included, so there is no per-lead billing pushing anyone to mail unverifiable addresses just to hit a number.

Frequently asked questions about catch-all emails in cold outreach

Why do companies set up catch-all domains?

Mostly for coverage and defense. A catch-all configuration guarantees that mail sent to a misspelled or former address still reaches someone, which matters for sales and support inboxes. Increasingly it is also an anti-scraping defense, because a server that accepts everything denies list-building tools the ability to confirm which addresses exist. That defensive posture is why catch-all setups are common at larger and more technical companies, which are often exactly the accounts an outbound campaign wants to reach.

Can you verify a catch-all email address?

Partially. A standard SMTP check cannot confirm a catch-all mailbox, because the server accepts every address it is asked about. Specialized verifiers layer on additional signals to score deliverability probabilistically, and Findymail claims its catch-all verification lets senders safely reach 20 to 30 percent more of their market. Treat these scores as probabilities rather than guarantees, and keep monitoring bounces even on addresses a tool scored as deliverable.

Is a catch-all address the same as a spam trap?

No. A spam trap is an address planted specifically to catch senders who mail unverified lists, and hitting one damages your reputation even though it never bounces. A catch-all address is simply unverifiable: it belongs to a real company whose server accepts all mail, and it may well reach a real person. The two get conflated because purchased lists are dense with both, which is one more reason to build lists from live sources instead of buying them.

Do catch-all addresses reply at lower rates than verified ones?

There is no published evidence that deliverable catch-all addresses reply worse than verified ones. The risk concentrates in delivery, not response: a catch-all send either bounces or lands like any other cold email. The variables that move reply rate are targeting, offer, and copy quality, not the recipient server’s acceptance policy. Judge catch-alls on bounce behavior and keep the reply-rate analysis focused on your messaging.

Should agencies send to catch-all addresses on client campaigns?

Yes, but under stricter rules than on your own campaigns, because the domain reputation at risk belongs to a client. Verify with a tool that scores catch-alls, keep them to a small bounded share of each campaign, and send them only from the client’s secondary outbound domains, never from anything tied to their primary domain. Teams running cold email for agencies at volume usually automate this triage rather than hand-sorting every list.

Treat catch-alls as budgeted risk, not forbidden addresses

The verdict on catch-all emails in cold outreach is a policy, not a yes or no: verify what can be verified, send the scored and evidenced subset from isolated infrastructure under a hard cap, and skip everything that arrives unsupported from a dirty source or lands on a fragile domain. Do that and catch-alls stop being a threat and become what they actually are, the 12 to 30 percent of the market, per the estimates above, that most competitors are too nervous to mail. If you would rather have the triage, the caps, and the bounce monitoring run automatically, connect an inbox to our cold email automation tool and start with the 7-day trial; the risk rules in this article are already built in.

Jorge Lewis

Co-Founder & AI Lead

AI-SaaS builder and co-founder of Startino. Leads product and engineering at GTM Bud.

catch-all email cold outreachaccept-all domainsshould you email catch-all addressesemail verificationbounce rate

Ready to automate your outreach?

GTM Bud finds Leads, writes personalized messages, and sends them, all on autopilot.