Check a domain
How it works
Read the MX
The mail exchangers are looked up first and matched against the hosts and security gateways that behave differently. That alone predicts most of the answer.
Probe with an impossible address
A random local part that no mailbox could have is offered to the server. Anything other than a rejection means the domain accepts everything.
Weigh the answer
A gateway in front of the mail server changes what the answer is worth, because gateways accept at the edge and reject later. That is reported as low confidence rather than hidden.
Decide what to keep
Strict domain: your verification results mean what they say. Catch-all: keep only addresses you have real evidence for, or resolve them a different way.
What catch-all means
A catch-all, or accept-all, domain is configured to deliver mail addressed to anything at the domain into one mailbox instead of rejecting unknown recipients. The reasons are usually mundane: a small business that does not want to lose mail sent to a misspelled name, a domain mid-migration, a forwarding service, a security gateway that was never given a recipient list. The effect on verification is total. When a verifier asks the server whether jane.doe@company.com exists, a catch-all server says yes. It says yes to j.doe@, janed@ and asdfgh@ as well. Every address you generated with a permutator comes back valid and exactly one of them, at most, is real.
Roughly one business domain in six behaves this way, and the proportion is higher in the segments cold email targets most — small companies on shared hosting, and enterprises behind a filtering gateway.
Why the MX matters more than the verdict
Google Workspace and Microsoft 365 both reject unknown recipients by default. When one of those domains comes back catch-all, somebody deliberately set a routing rule or left an accepted domain configured as an internal relay — it is a real property of that domain and you can rely on the finding. A security gateway is a different situation. Proofpoint, Mimecast, Barracuda, Cisco and the rest sit in front of the real mail server and, in most deployments, accept every recipient at the edge and let the mail server decide later. The verifier never speaks to the mail server, so it sees acceptance and reports catch-all, whether or not the mailbox exists. The tool names the gateway and marks the confidence down accordingly, because a false catch-all verdict makes you throw away addresses that were fine.
What to do with one
There are four honest options and no clever fourth. Keep only the addresses you have independent evidence for — a published address on the website, a signature in a forwarded thread, a press release — and discard the guesses. Send at very low volume from a domain you can afford to damage, accepting that bounces will not come back to tell you which addresses were wrong. Resolve them properly with a service that sends real mail and watches the behaviour of the receiving system rather than trusting the SMTP answer. Or drop the domain, which is perfectly defensible when it represents one contact on a list of thousands.
What you must not do is treat a catch-all domain as verified because a verifier returned valid. That is how a list with a 3% reported bounce rate produces 14% in production, and the damage lands on the sending domain, not on the list.
Where this fits
Run the email verifier on individual addresses, this checker on the domains it flags as uncertain, the list cleaner for the structural pass over a whole file, and the MX checker when you want the provider breakdown across a set of domains without probing any of them. For a full list including catch-all resolution, that is what Rooster4am does.
Frequently asked questions
Why only one domain at a time?
Every live probe is a real SMTP conversation with somebody else's mail server, and the daily allowance is shared across everyone using the site. Bulk belongs in a paid pipeline, not a free page.
Is a catch-all address worth sending to?
Sometimes. A catch-all domain is not a dead domain — the mail is being delivered somewhere. The problem is that you cannot tell whether it reaches the person you named, and a wrong name in the greeting is worse than no email.
Why does a big company show as catch-all?
Almost always a security gateway accepting at the edge. The tool names the gateway when it can and lowers the confidence, because the real mail server behind it may well reject unknown recipients.
Does the probe send an email?
No. The conversation stops before any message data, at the point where the server has said whether it would accept the recipient. Nothing is delivered and nobody sees it in a mailbox.
What does an inconclusive result mean?
Greylisting, a timeout or rate limiting — the server did not commit either way. Try again in a few minutes, and if it stays inconclusive, plan as though it were catch-all.
Can a domain stop being catch-all?
Yes, and they do. It is a configuration setting, so re-check a domain before a large campaign rather than trusting a result from six months ago.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace and Microsoft 365 inboxes
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.