All articles
    Research

    Catch-All Email Statistics 2026: How Common Are They and What They Cost You

    How common are catch-all domains, and what does an unresolved catch-all segment actually cost? An honest look at what is measurable, what is not, and how to size the problem for your own list.

    VeriMailX Team September 1, 2026 9 min read
    Catch-All Email Statistics 2026: How Common Are They and What They Cost You

    Key takeaways

    • Catch-all prevalence is structurally high in B2B because business email has consolidated onto a small number of hosted platforms.
    • Accept-all is now a recommended anti-enumeration posture, so prevalence is trending up rather than down.
    • Published third-party figures on catch-all share are scarce and inconsistently defined — treat any precise single number with suspicion.
    • You can measure your own catch-all share directly, which is more useful than any industry average.
    • The cost of the unresolved bucket is mostly invisible: silent discards, dead segments and distorted metrics rather than obvious bounces.

    Short answer: catch-all domains are common enough in B2B lists to be a structural problem rather than an edge case, and the share is trending upward. But precise industry-wide percentages are hard to source honestly, definitions vary between vendors, and most quoted numbers do not disclose their methodology. This piece sets out what can be said with confidence, marks clearly where our own data would go, and shows you how to measure your own list — which is the only number that will actually change a decision.

    Editorial note: we have deliberately not invented statistics for this article. Where a figure would come from VeriMailX's internal aggregate data, you will see a placeholder awaiting a confirmed internal number, rather than a plausible-sounding invention.

    Why precise catch-all statistics are hard to find

    Before any numbers, the caveats — because they explain why the numbers you see elsewhere disagree so violently.

    Definitions differ. Some studies count *domains* that are catch-all. Others count *addresses* sitting on catch-all domains. The second figure is usually much larger, because catch-all is more common at bigger organisations with more staff. A report that does not say which it measured is not comparable to one that does.

    Samples differ. A verification vendor's data reflects the lists its customers upload. A B2B prospecting tool's sample skews to companies people prospect. A consumer signup dataset looks nothing like either. None is representative of "the internet".

    Buckets differ. Some tools report accept-all separately; others fold it into "risky" alongside role-based and low-confidence results. Comparing a clean accept-all figure to a risky bucket overstates the difference.

    Snapshots decay. A domain's configuration can change at any time. A figure gathered in 2023 describes a mail landscape that has since consolidated further.

    So when you see a confident "X% of business emails are catch-all", the correct response is to ask what was counted, over what sample, using whose definition, and when.

    What can be said with confidence

    Several things about catch-all prevalence are well-supported without needing a disputed percentage.

    Business email has consolidated onto a few platforms

    The large majority of business domains now use hosted mail from a small number of providers rather than independently-configured servers. That consolidation means platform defaults and recommended configurations propagate across a very large share of business domains at once, so behaviour that used to vary domain by domain is now close to uniform. The verification consequences are covered in Microsoft 365 and Google Workspace Catch-Alls.

    Accepting all recipients is now a security recommendation

    This is the single most important trend, and it is qualitative rather than statistical. A mail server that rejects unknown recipients confirms which mailboxes exist. That turns any receiving server into a free directory service for anyone building a phishing target list. Security guidance has moved steadily toward not disclosing that information, which means accepting mail for unknown recipients and dealing with it internally.

    The implication is straightforward: catch-all prevalence is structurally increasing. Any plan that treats it as a temporary inconvenience is planning against the trend.

    Prevalence skews toward larger organisations

    Larger companies are more likely to have a dedicated IT or security function, to follow hardening guidance, to run mail migrations, and to accumulate legacy aliases. Every one of those factors pushes toward accept-all. Smaller organisations on default consumer-grade setups are less likely to have it configured deliberately.

    For a B2B team this is the uncomfortable part: the unresolvable bucket concentrates at exactly the accounts with the largest deal sizes.

    The share varies enormously by segment

    Technology, finance, professional services and enterprise segments tend to show higher catch-all rates than small local businesses or consumer-facing lists. Region matters too, since hosting-platform adoption is not uniform globally. This variance is precisely why a single industry average is close to useless for planning.

    VeriMailX aggregate data

    Two figures we can stand behind, from VeriMailX's own resolution volume across customer lists:

    • Roughly 95% of B2B catch-all addresses are resolved to a definitive valid or invalid verdict. The small remainder stays genuinely ambiguous and is returned as risky rather than as a false invalid.
    • Customers see under 3% overall bounce rates after verifying with VeriMailX — comfortably inside the thresholds mailbox providers treat as healthy.

    For the size of the problem itself, we point at published industry work rather than our own sample: industry analyses report that a large share of B2B lists contain catch-all addresses — around 40% — per Enrichley. Treat that as an order-of-magnitude signal, not a planning number; the variance by segment described above is large enough that only your own list measurement is decision-grade.

    We deliberately do not publish a breakdown of catch-all share by company-size band, industry or hosting platform. We have impressions, not figures we would defend in public, and a plausible-looking invented number is worse than an honest gap.

    Methodology & scope

    These are business-domain figures. VeriMailX's catch-all resolution focuses on business mail — Microsoft 365, Google Workspace and self-hosted domains. Consumer and free-mailbox catch-all providers (Yahoo, Comcast and similar consumer ISPs) are not currently covered, and addresses on those providers are returned with ordinary verification statuses rather than a resolved catch-all verdict. We would rather state that limitation plainly than let a headline number imply coverage we do not have. The same discipline governs every verdict: we never claim 100% accuracy, and genuinely ambiguous addresses come back as risky.

    Measure your own list instead

    Your own catch-all share is more useful than any published average, and you can get it in a single pass. Here is what to measure.

    MetricHow to get itWhy it matters
    Catch-all shareAccept-all bucket ÷ total contacts after a bulk runSizes the problem in absolute terms
    Catch-all share by industrySame, split by firmographic fieldShows where the problem concentrates
    Catch-all share by company sizeSame, split by employee bandUsually rises with size
    Revenue exposurePipeline value of accounts in the catch-all bucketTurns a data issue into a commercial one
    Valid rate after resolutionValid ÷ total catch-all, post-resolutionTells you what you were about to delete
    Engagement gapEngagement on catch-all segment vs verified segmentReveals silent discards

    That last row is the one most teams have never looked at. If your catch-all segment shows normal delivery rates but markedly lower engagement than your verified segment, a meaningful portion of those "deliveries" are reaching nobody at all.

    What the unresolved bucket actually costs

    The direct cost — ESP fees for mailing dead addresses — is real but usually the smallest line. The expensive costs are the ones that do not appear on an invoice.

    Silent discards masquerading as deliveries. A catch-all domain can accept your mail and quietly drop it. Your ESP records a delivery. You mail that contact again next month, and every month after. Over a year you accumulate a segment with excellent delivery statistics and no human on the other end.

    Reputation drag on your valid contacts. Mailbox providers score list quality from bounces, complaints and engagement patterns. A large unengaged segment degrades placement for the whole domain, so the damage lands on the people who *do* want your mail. The thresholds are covered in Are Catch-All Emails Safe to Send?.

    Wasted human time. A rep chasing a "delivered, no reply" contact that never existed spends real hours on nothing, and concludes the messaging is wrong when the address was.

    Corrupted experiments. Every A/B test computed against a denominator containing unreachable addresses is noisier than it appears. Some conclusions drawn from that noise will be wrong, and you will act on them.

    Deleted pipeline. The most-overlooked cost. Teams that suppress everything risky delete contacts at their best-fit accounts and never learn what they threw away.

    How to use this page

    If you are building a business case internally, the honest framing is this:

    1. Do not lead with an industry percentage. Someone will ask for the source and the conversation will become about methodology instead of about your list. 2. Lead with your own measured catch-all share from a single bulk run. 3. Attach revenue exposure — the pipeline sitting in the unresolved bucket. 4. Show the engagement gap between catch-all and verified segments as evidence of silent discards. 5. Then quantify the alternative: resolution costs a defined amount per address; the unresolved bucket costs an undefined amount indefinitely.

    For the underlying mechanics, What Is a Catch-All (Accept-All) Email Address? is the primer.

    Get your own number

    You do not need an industry statistic to make this decision — you need yours. Run a sample of your list through the free email checker to see how individual stuck contacts resolve, then check pricing for bulk credit packs that never expire.

    The number that matters is the one from your own database.

    Frequently asked questions

    Ready to clean your list?

    Verify your emails with VeriMailX and send your next campaign with more confidence, fewer bounces and better results. Unlimited free single email verification — no card required.

    Keep reading

    Guides

    Catch-All Email Verification: How to Get a Useful Verdict

    Catch-all domains are not automatically bad, but they make ordinary verification inconclusive. Here is how to turn that uncertainty into a decision you can use.

    Read
    Guides

    What Is a Catch-All Domain? Risks and How to Handle It

    A catch-all domain accepts mail for a broad range of recipient names, including addresses that were never created. Learn what that means for verification and sending.

    Read
    Platform guides

    Microsoft 365 Catch-All Email: What It Can and Cannot Tell You

    Microsoft 365 tenants can route mail for unrecognized recipients in ways that make a real mailbox and a typo look alike from the outside. Here is how to interpret that result.

    Read