Email verification usually works by asking. A verifier opens a conversation with the receiving mail server and, in effect, asks whether a mailbox exists. Most servers answer honestly: yes, or no such user.
A catch-all domain answers yes to everything. Real mailbox, misspelled mailbox, an address someone invented, all accepted at the door, then sorted out later or silently discarded. The server is configured that way on purpose, usually so that mail to a mistyped address is not lost.
The verifier asked a question the server was configured never to answer honestly.
What that does to your list
Verification tools have to decide what to report for those domains, and the choice is unattractive either way. Mark them invalid and you discard a large number of perfectly real addresses, because catch-all is common at exactly the mid-market and enterprise companies you want to reach. Mark them valid and you have quietly promoted a guess to a fact.
Most tools take the second option, sometimes labelling it “accept-all” or “risky” in a column nobody reads before importing. Which is how a list that reports 98% deliverable produces a bounce rate that gets your domain throttled.
What a bounce actually costs
How to actually resolve them
Since the server will not answer, the resolution has to come from somewhere other than the server. That means corroboration: does this address pattern match others confirmed at the same company, has this specific address been observed as active elsewhere, does a second independent source hold the same mailbox.
None of that is a single request, which is why plenty of tools do not do it. It is also why a second verification layer is the difference between a domain marked accept-all and an address you can actually send to.
A practical test when evaluating any data vendor: take twenty contacts you know are real at catch-all domains, and twenty addresses you have invented at the same domains. A verifier doing real work will separate them. One that returns “valid” for all forty is telling you it asked the door and believed the answer.
What to do with the ones that stay unresolved
Some will not resolve, and the honest answer is to treat them differently rather than pretend. Send them in a separate batch, on a lower volume, away from your primary sending domain, so if the bounce rate on that batch is bad, it damages a segment rather than your whole programme.
The rule of thumb worth keeping: never let unresolved addresses ride along in the same send as your verified ones. That is how one bad segment takes a good campaign down with it.



