A catch all email is an address on a domain whose mail server accepts mail for any name before the @. jane@acme.com and zzzz1234@acme.com both get a yes, so a probe cannot tell a real mailbox from a made-up one.
Key takeaways
- A catch all domain accepts every recipient. The verdict is "cannot confirm", not "bad address".
- Catch all addresses are riskier than verified ones and safer than invalid ones. Send to them in a separate, smaller batch.
- Bounces from unconfirmed addresses hurt your sending domain. Read the status before you send.
- On LeadOcean the filter is
emailStatus. The valuecatch_allis free to count and the status is on every search row.
What it is
A catch all email is an address on a domain configured to accept mail for every possible recipient, so no check at the mail server can prove the specific mailbox exists.
It is a server setting, not an address type. The SMTP standard (RFC 5321) defines how a server answers the RCPT TO command with a 250 (accepted) or a 550 (mailbox unavailable) (RFC 5321, September 2026). It does not define a catch all. An admin chooses to answer 250 for everything.
Admins do it so no customer mail gets lost to a typo. The cost lands on senders, who lose their cheapest signal.
How it works
A verifier asks the mail server whether a recipient exists, then disconnects without sending a message. A normal domain answers honestly. A catch all domain does not.
- The verifier connects to the domain's mail server and sends
RCPT TOfor the address you want to check. - A normal server replies 250 for a real mailbox and 550 for an unknown one.
- The verifier sends a second
RCPT TOfor a random name that cannot exist. - If that random name also gets a 250, the domain accepts everything. Every address there is labelled catch all.
- The mailbox may be real or not. If a message goes out and the mailbox is missing, the bounce comes later, after you sent.
Worked example, with placeholders:
RCPT TO:<jane.doe@acme.com> -> 250 OK
RCPT TO:<zq81xk-probe@acme.com> -> 250 OKBoth lines say yes, so Acme is a catch all domain. jane.doe@acme.com is unconfirmed even though it looks like a good address.
Catch all vs verified vs invalid
Teams confuse "catch all" with "invalid" because both stop a clean pass. They are different outcomes with different send rules.
| Verified | Catch all | Invalid | |
|---|---|---|---|
| What the server said | 250 for this address, 550 for a random one | 250 for every address | 550 for this address |
| Mailbox known to exist | Yes | No | No |
| Bounce risk | Low | Unknown, higher than verified | Near certain |
| Send? | Yes | Separate small batch, watch bounces | Never |
LeadOcean emailStatus | verified | catch_all (and catch_all_valid) | invalid |
A fourth value matters here. LeadOcean's catch_all_valid marks a mailbox on a catch all domain whose existence was confirmed through the provider's identity check. That covers Microsoft 365 managed tenants and Google Workspace only (LeadOcean API enums, September 2026). Everything else on a catch all domain stays catch_all.
When it matters
Cold outbound to a small domain
Small companies are often your best fit, and some of them run catch all domains. Check the catch all share of the list before you send. Do not drop it. Split it out and send it at a lower volume.
Protecting your sending domain
Bounces damage reputation faster than they cost you leads. A mailbox that does not exist bounces after you sent, and mailbox providers count it. LeadOcean does not refund or credit bounced emails, so the status check is your only protection.
Sizing a list before you pay for it
A list that is 90% verified and a list that is 90% catch all look the same until you read the status. Count by status first. On 2026-10-01, leadocean_count_leads returned 92,392,601 people with emailStatus set to catch_all (worldwide, no other filters). That filter also matches catch_all_valid. It is a count of people by email status, not a mailable count.
Paying twice for the same check
Running a catch all address through a second verifier rarely changes the answer. The domain still says yes to everything, so a second probe has the same blind spot. Spend verification on the unknown and risky groups instead.
How LeadOcean handles it
Every people search row publishes email_status, email_type and has_email as flags, so you see the status before you buy the address. The emailStatus filter takes the values from GET /v1/enums/email_status. Sizing is free: send count=true as a query parameter with limit=1 (LeadOcean OpenAPI, September 2026).
Passing emailStatus replaces the default mailable filter (verified, catch_all_valid and catch_all). So you choose what to send. The first call below sizes catch all VPs in the US and spends no records. The second pulls the verified group, and each person returned counts one record.
curl -X POST "https://api.leadocean.io/v1/people/search?count=true&limit=1" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"emailStatus": ["catch_all"], "jobLevel": ["VP"], "country": ["US"]}'
curl -X POST "https://api.leadocean.io/v1/people/search" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"emailStatus": ["verified"], "jobLevel": ["VP"], "country": ["US"], "limit": 25}'Pull verified first and catch_all second, then send them as two campaigns. The same filter works in the MCP server through leadocean_count_leads and leadocean_search_leads, and in the Exports page of the app (app.leadocean.io), which shows the record price before you start.
Pricing is two plans: Free (1,000 records, one-off, no card) and Pro at $499 a month. See pricing.
FAQ
Should I email catch all addresses?
Yes, in a separate smaller batch, after your verified group. Watch the bounce rate on that batch and stop if it climbs. Never mix catch all and verified addresses in one send.
Can a verifier confirm a catch all email?
Not through the mail server, because it says yes to everything. Only an outside signal can confirm a mailbox, such as a provider identity check. That is what separates catch_all_valid from catch_all on LeadOcean.
Is catch all the same as accept all?
Yes. "Accept all" and "catch all" name the same server behavior. Tools differ in the label they print. See the guide to accept all domains.
Does a catch all address bounce more?
Often, yes, because nobody can confirm the mailbox ahead of time. We have not run a bounce test, so this page gives no rate. For the plain-language version see what is a catch all email.
Which verifier is best for catch all?
No verifier can promise a certain answer on a catch all domain. Compare how each one labels them in best catch all email verifiers. More on this topic is in the blog hub.
Size your catch all and verified lists before you send
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →