US dental offices from the CMS NPPES register: fields, method and prices, nationwide or by state.
What is a catch-all email?
A catch-all email is an address at a domain whose mail server accepts messages for every address at that domain, including addresses that don't exist. You may also see it called an accept-all domain. If a dental practice's domain is catch-all, mail to info@, office@ and a misspelled ofice@ is taken in, and the server doesn't tell the sender which of those mailboxes is real.
That is why a verification check can't confirm the mailbox. The server says yes to any address, so a yes tells you nothing about the one you asked about. In a nodilist file, such an email will be labelled catch-all, kept apart from valid, and left out of the bounce refund.
How does email verification work?
An email check talks to the recipient's mail server the same way a real sender would, then stops before sending a message. There are two steps.
- Find the mail server. The checker looks up the domain's MX (mail exchanger) records in DNS. SMTP, the standard that mail servers use, requires this lookup before delivery. If the domain doesn't exist, the address fails here (RFC 5321, section 5.1).
- Ask about the mailbox. The checker opens an SMTP connection and names the address in a
RCPT TOcommand. Under the standard, the server replies "250 OK" if it accepts the recipient and returns a 550 reply "if the recipient is known not to be a deliverable address" (RFC 5321, section 3.3). The checker then ends the session without sending any message text.
Replies starting with 5 are permanent failures. Replies starting with 4 are temporary, meaning the same request might succeed later (RFC 5321, section 4.2.1). One common source of 4xx replies is greylisting: some servers turn away a first attempt from an unfamiliar sender on purpose and accept it only on a retry (RFC 6647).
Why the check fails on a catch-all domain
A catch-all server answers "250 OK" to every RCPT TO for its domain, so the probe gets the same reply for a real mailbox and an invented one. A checker detects this by also asking about an address that almost certainly doesn't exist. If the server accepts that too, the domain is marked catch-all. A 2026 study of Fortune 500 domains used the same test and also counted as catch-all any server that "accepted the message and bounced it afterward" (Allegrow, June 2026).
The standard allows that second behaviour. RFC 5321 notes that "some servers do not perform recipient verification until after the message text is received" and then send the failure back as a bounce message instead of rejecting the address during the session (section 3.3). Whatever the setup, the result is the same for you. The only way to learn whether a catch-all address reaches a person is to send to it.
Why do businesses set up a catch-all?
Most set it up so that mail to a mistyped or retired address still arrives. Google Workspace describes the feature as a way to collect "messages sent to non-existent or incorrect email addresses in your domain" in a single mailbox (Google Workspace Admin Help).
How it's configured depends on the mail host:
- Google Workspace. An administrator adds a routing rule that sends mail for "All inactive and unrecognized accounts" to a chosen mailbox (Google Workspace Admin Help).
- Microsoft 365. An Exchange Online domain set to "Authoritative" rejects mail for unknown recipients: "Emails for unknown recipients are rejected". An "Internal relay" domain passes mail for unknown recipients on to the organization's own mail server, which then decides what to do with it (Microsoft Learn). Microsoft doesn't offer a single catch-all switch. Administrators build one from these routing settings.
- cPanel web hosting. Shared hosting plans that use cPanel have a Default Address setting, described as "a catch-all address that receives any mail for an invalid email address for the domain" (cPanel documentation). Namecheap's help pages, for example, walk customers through turning it on (Namecheap).
A small practice whose website and email came bundled in one hosting plan may have a catch-all without knowing it. cPanel's own documentation warns about the cost: "If spammers target your domain and you forward mail to a default address, that address may receive a large amount of spam" (cPanel documentation).
How common are catch-all domains?
Published figures vary widely because studies measure different things, and we found no neutral industry-wide count. Two recent vendor studies show the range:
- Across all addresses one verification company checked: more than 9% of over 11 billion email addresses it processed in 2025 came back catch-all. That figure counts addresses, and it mixes business and consumer mail (ZeroBounce, Email List Decay Report for 2026).
- Among very large companies: 235 of the 500 Fortune 500 primary domains (47%) behaved as catch-all in a test run in late June 2026. The authors call the figure conservative because 53 inconclusive domains were counted as not catch-all (Allegrow).
Neither figure tells you much about dental practices or any other small-business niche. For that reason we publish the share for each list from our own checks.
How many catch-all emails are in the dentist list?
The dentist list isn't open yet. When it opens, the dentist email list page will show how many of its emails are valid, catch-all and unknown, from our own checks.
What do valid, catch-all, unknown and invalid mean in a nodilist file?
Every email in a nodilist file will have an email_status and a last-verified date. The date is when we last ran the check, which is separate from the date the source was updated and the date your file was exported.
| Status | What it means | In your file? | Counts toward the bounce refund? |
|---|---|---|---|
| valid | The mail server confirmed the mailbox exists. | Yes | Yes |
| catch-all | The domain accepts every address, so the mailbox can't be confirmed. | Yes, labelled | No |
| unknown | The server didn't give a clear answer, for example because of timeouts or greylisting. | Yes, labelled | No |
| invalid | The server rejected the mailbox. | No, removed | Not applicable |
A valid result shows what the server said on the last-verified date. A mailbox can be closed after that date, which is why the refund below exists. Every email in the file will be one the business published in a public source, and the row will carry that source. We don't generate addresses from name patterns, so a catch-all status never means we guessed the address.
What bounce rate should you expect from catch-all emails?
Expect more bounces from catch-all and unknown emails than from valid ones, but no checker can predict how many for a given list. A hard bounce is a permanent failure such as "address does not exist" (Amazon SES). On a catch-all domain it can arrive as a bounce message after the server first accepted the mail, as described in RFC 5321, section 3.3. Some catch-all domains deliver everything to a shared inbox and never bounce anything. Others accept at first and reject later.
A soft bounce, such as a full mailbox, is temporary and is handled differently from a hard bounce by sending platforms (Amazon SES).
What is a good bounce rate?
Under 2% is the usual target. Amazon SES, for example, tells senders to keep their bounce rate below 2%, places accounts under review at 5% and may pause sending at 10%. SES counts only hard bounces (Amazon SES). Published averages by industry, and why older lists bounce more, are in our guide to email bounce rate benchmarks.
How do you send to catch-all emails safely?
Send to valid emails first and treat catch-all and unknown emails as a separate, smaller test.
- Split the file by
email_status. Load valid, catch-all and unknown as separate segments in your sending tool so each one gets its own bounce and complaint numbers. - Send to valid emails first. They're the part of the file a server confirmed.
- Send catch-all emails in small batches. Amazon SES advises that addresses you can't be confident about should be only "a small portion of your overall sending" (Amazon SES). Start with a few dozen, check the result, then continue.
- Watch bounces after every batch, and remove hard bounces at once. SES tells senders to "remove bounced addresses from your mailing list and stop sending mail to them immediately" (Amazon SES). If a batch bounces well above your valid segment, pause the catch-all segment.
- Authenticate your sending domain. Since 1 February 2024 Gmail has required SPF or DKIM from every sender to personal Gmail accounts, and SPF, DKIM and DMARC from senders of close to 5,000 or more messages a day. Bulk senders also need one-click unsubscribe and a visible unsubscribe link (Gmail Help; Gmail sender FAQ). Yahoo requires SPF, DKIM and a DMARC policy of at least
p=nonefrom bulk senders and began enforcing in February 2024 (Yahoo sender best practices, Yahoo FAQs). - Keep spam complaints low. Gmail asks senders to keep the spam rate in Postmaster Tools below 0.10% "and avoid ever reaching a spam rate of 0.30% or higher" (Gmail Help). Yahoo's limit is 0.3% (Yahoo).
The Gmail and Yahoo rules are written for mail to their own consumer accounts. Most practices use their own domain, so these rules may not apply to them directly. We still treat them as the baseline, because SPF, DKIM and DMARC are open standards that any receiving server can check.
Check your sending platform's rules first. Some platforms don't allow purchased lists at all. Amazon SES's guidance, for example, says "Don't buy, rent, or share email addresses" (Amazon SES). Read your platform's acceptable use policy before you import any list. For the law on cold B2B email in the US, see is buying an email list legal?
How does the nodilist bounce refund treat catch-all emails?
Only emails marked valid count toward the refund. If more than 5% of the emails we mark valid hard-bounce within 30 days, we refund that share of your order.
Catch-all and unknown emails will be shown separately in your file and don't count toward the 5%, because we never told you those mailboxes were confirmed. To claim, you send us your bounce report for the valid emails. Card held at checkout, charged on delivery. The conditions are on the refunds and guarantee page.
What this guide can't tell you
- How many catch-all emails on a given list will bounce. Only sending tells you that.
- Whether a domain is still catch-all today. Owners can change the setting at any time.
- Whether your sending platform accepts purchased lists. Check its acceptable use policy.
This guide explains email delivery in general terms. It is not legal advice.
Frequently asked questions
Is a catch-all email the same as an invalid email?
No. An invalid email was rejected by the mail server, and we remove it. A catch-all email sits on a domain that accepts everything, so the mailbox may exist or may not.
Should I delete catch-all emails from my list?
That depends on how much bounce risk your sending setup can absorb. If your platform has strict bounce limits, send to valid emails only. Otherwise, test catch-all emails in small batches as described above and keep the addresses that don't bounce.
Can any tool verify a catch-all email for certain?
Not with an SMTP check, because the server gives the same answer for every address. Any score a tool gives for a catch-all address is an estimate, not a confirmation. Sending is the only test.
Why is an email marked unknown?
The server didn't answer clearly during our check, for example because it timed out or used greylisting, which turns away a first attempt on purpose (RFC 6647). A later check may give a clear answer. The last-verified date shows when we last tried.
Does a valid status guarantee delivery?
No. Valid means the server confirmed the mailbox on the last-verified date. Mailboxes close, and a spam filter can still stop a message that reaches a real mailbox. The bounce refund covers the first case.
Can a domain stop being catch-all?
Yes. The owner can change the setting at any time, in either direction. Our status reflects the domain's behaviour on the last-verified date.
Sources
- RFC 5321, Simple Mail Transfer Protocol (Oct 2008), sections 3.3, 4.2.1, 5.1: https://www.rfc-editor.org/rfc/rfc5321 (accessed 2026-09-29)
- RFC 6647, Email Greylisting: An Applicability Statement for SMTP (Jun 2012): https://www.rfc-editor.org/rfc/rfc6647 (accessed 2026-09-29)
- Google Workspace Admin Help, Get misaddressed email in a catch-all mailbox: https://support.google.com/a/answer/12943537 (accessed 2026-09-29)
- Microsoft Learn, Manage accepted domains in Exchange Online (ms.date 2024-05-19): https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/manage-accepted-domains/manage-accepted-domains (accessed 2026-09-29)
- cPanel & WHM Documentation (version 130), Default Address: https://docs.cpanel.net/cpanel/email/default-address/ (accessed 2026-09-29)
- Namecheap Knowledgebase, How to create a catch-all email address in cPanel: https://www.namecheap.com/support/knowledgebase/article.aspx/912/31/how-to-create-a-catchall-email-address-in-cpanel/ (accessed 2026-09-29)
- Gmail Help, Email sender guidelines (requirements from 1 Feb 2024): https://support.google.com/a/answer/81126 (accessed 2026-09-29)
- Google Workspace Admin Help, Email sender guidelines FAQ (bulk sender: close to 5,000 or more messages a day): https://support.google.com/a/answer/14229414 (accessed 2026-10-03)
- Yahoo Sender Hub, Sender best practices: https://senders.yahooinc.com/best-practices/ and FAQs: https://senders.yahooinc.com/faqs/ (accessed 2026-09-29)
- Amazon SES Developer Guide, Sending review process FAQs (bounce and complaint thresholds): https://docs.aws.amazon.com/ses/latest/dg/faqs-enforcement.html (accessed 2026-09-29)
- ZeroBounce, The Email List Decay Report for 2026 (2025 data, 11 billion+ addresses): https://www.zerobounce.net/email-list-decay (accessed 2026-09-29)
- Allegrow, Fortune 500 catch-all and gateway email study (late June 2026): https://www.allegrow.co/knowledge-base/fortune-500-catch-all-gateway-email-study (accessed 2026-09-29)
