Lazure
ExplainerDeliverability6 min read

Why do “verified” emails still bounce?

Because catch-all domains accept every address at the door, including the ones that never existed. Most verifiers cannot tell the difference, so they guess, and your sending reputation pays for the guess.

Email verification usually works by asking. A verifier opens a conversation with the receiving mail server and, in effect, asks whether a mailbox exists. Most servers answer honestly: yes, or no such user.

A catch-all domain answers yes to everything. Real mailbox, misspelled mailbox, an address someone invented, all accepted at the door, then sorted out later or silently discarded. The server is configured that way on purpose, usually so that mail to a mistyped address is not lost.

The verifier asked a question the server was configured never to answer honestly.

What that does to your list

Verification tools have to decide what to report for those domains, and the choice is unattractive either way. Mark them invalid and you discard a large number of perfectly real addresses, because catch-all is common at exactly the mid-market and enterprise companies you want to reach. Mark them valid and you have quietly promoted a guess to a fact.

Most tools take the second option, sometimes labelling it “accept-all” or “risky” in a column nobody reads before importing. Which is how a list that reports 98% deliverable produces a bounce rate that gets your domain throttled.

What a bounce actually costs

Optimises forNothing. There is no upside to a hard bounce.
Quietly penalisesYour sending domain first, then every campaign that runs after it. Mailbox providers read bounce rate as a signal of list quality, and the reputation damage outlasts the campaign that caused it by weeks.
Use it whenWorth knowing that the usual tolerance is low, a couple of percent is where problems start, and a list full of unresolved catch-alls will clear that on its own.

How to actually resolve them

Since the server will not answer, the resolution has to come from somewhere other than the server. That means corroboration: does this address pattern match others confirmed at the same company, has this specific address been observed as active elsewhere, does a second independent source hold the same mailbox.

None of that is a single request, which is why plenty of tools do not do it. It is also why a second verification layer is the difference between a domain marked accept-all and an address you can actually send to.

A practical test when evaluating any data vendor: take twenty contacts you know are real at catch-all domains, and twenty addresses you have invented at the same domains. A verifier doing real work will separate them. One that returns “valid” for all forty is telling you it asked the door and believed the answer.

What to do with the ones that stay unresolved

Some will not resolve, and the honest answer is to treat them differently rather than pretend. Send them in a separate batch, on a lower volume, away from your primary sending domain, so if the bounce rate on that batch is bad, it damages a segment rather than your whole programme.

The rule of thumb worth keeping: never let unresolved addresses ride along in the same send as your verified ones. That is how one bad segment takes a good campaign down with it.

Lazure verifies catch-all domains before returning an address

Dual verification resolves the addresses that a single server check cannot, so accept-all domains do not arrive in your list quietly labelled valid.

See Lazure enrichment