Key takeaways
- Catch-all prevalence is structurally high in B2B because business email has consolidated onto a small number of hosted platforms.
- Accept-all is now a recommended anti-enumeration posture, so prevalence is trending up rather than down.
- Published third-party figures on catch-all share are scarce and inconsistently defined — treat any precise single number with suspicion.
- You can measure your own catch-all share directly, which is more useful than any industry average.
- The cost of the unresolved bucket is mostly invisible: silent discards, dead segments and distorted metrics rather than obvious bounces.
Short answer: catch-all domains are common enough in B2B lists to be a structural problem rather than an edge case, and the share is trending upward. But precise industry-wide percentages are hard to source honestly, definitions vary between vendors, and most quoted numbers do not disclose their methodology. This piece sets out what can be said with confidence, marks clearly where our own data would go, and shows you how to measure your own list — which is the only number that will actually change a decision.
Editorial note: we have deliberately not invented statistics for this article. Where a figure would come from VeriMailX's internal aggregate data, you will see a placeholder awaiting a confirmed internal number, rather than a plausible-sounding invention.
Why precise catch-all statistics are hard to find
Before any numbers, the caveats — because they explain why the numbers you see elsewhere disagree so violently.
Definitions differ. Some studies count *domains* that are catch-all. Others count *addresses* sitting on catch-all domains. The second figure is usually much larger, because catch-all is more common at bigger organisations with more staff. A report that does not say which it measured is not comparable to one that does.
Samples differ. A verification vendor's data reflects the lists its customers upload. A B2B prospecting tool's sample skews to companies people prospect. A consumer signup dataset looks nothing like either. None is representative of "the internet".
Buckets differ. Some tools report accept-all separately; others fold it into "risky" alongside role-based and low-confidence results. Comparing a clean accept-all figure to a risky bucket overstates the difference.
Snapshots decay. A domain's configuration can change at any time. A figure gathered in 2023 describes a mail landscape that has since consolidated further.
So when you see a confident "X% of business emails are catch-all", the correct response is to ask what was counted, over what sample, using whose definition, and when.
What can be said with confidence
Several things about catch-all prevalence are well-supported without needing a disputed percentage.
Business email has consolidated onto a few platforms
The large majority of business domains now use hosted mail from a small number of providers rather than independently-configured servers. That consolidation means platform defaults and recommended configurations propagate across a very large share of business domains at once, so behaviour that used to vary domain by domain is now close to uniform. The verification consequences are covered in Microsoft 365 and Google Workspace Catch-Alls.
Accepting all recipients is now a security recommendation
This is the single most important trend, and it is qualitative rather than statistical. A mail server that rejects unknown recipients confirms which mailboxes exist. That turns any receiving server into a free directory service for anyone building a phishing target list. Security guidance has moved steadily toward not disclosing that information, which means accepting mail for unknown recipients and dealing with it internally.
The implication is straightforward: catch-all prevalence is structurally increasing. Any plan that treats it as a temporary inconvenience is planning against the trend.
Prevalence skews toward larger organisations
Larger companies are more likely to have a dedicated IT or security function, to follow hardening guidance, to run mail migrations, and to accumulate legacy aliases. Every one of those factors pushes toward accept-all. Smaller organisations on default consumer-grade setups are less likely to have it configured deliberately.
For a B2B team this is the uncomfortable part: the unresolvable bucket concentrates at exactly the accounts with the largest deal sizes.
The share varies enormously by segment
Technology, finance, professional services and enterprise segments tend to show higher catch-all rates than small local businesses or consumer-facing lists. Region matters too, since hosting-platform adoption is not uniform globally. This variance is precisely why a single industry average is close to useless for planning.
VeriMailX aggregate data
Two figures we can stand behind, from VeriMailX's own resolution volume across customer lists:
- Roughly 95% of B2B catch-all addresses are resolved to a definitive valid or invalid verdict. The small remainder stays genuinely ambiguous and is returned as risky rather than as a false invalid.
- Customers see under 3% overall bounce rates after verifying with VeriMailX — comfortably inside the thresholds mailbox providers treat as healthy.
For the size of the problem itself, we point at published industry work rather than our own sample: industry analyses report that a large share of B2B lists contain catch-all addresses — around 40% — per Enrichley. Treat that as an order-of-magnitude signal, not a planning number; the variance by segment described above is large enough that only your own list measurement is decision-grade.
We deliberately do not publish a breakdown of catch-all share by company-size band, industry or hosting platform. We have impressions, not figures we would defend in public, and a plausible-looking invented number is worse than an honest gap.
Methodology & scope
These are business-domain figures. VeriMailX's catch-all resolution focuses on business mail — Microsoft 365, Google Workspace and self-hosted domains. Consumer and free-mailbox catch-all providers (Yahoo, Comcast and similar consumer ISPs) are not currently covered, and addresses on those providers are returned with ordinary verification statuses rather than a resolved catch-all verdict. We would rather state that limitation plainly than let a headline number imply coverage we do not have. The same discipline governs every verdict: we never claim 100% accuracy, and genuinely ambiguous addresses come back as risky.
Measure your own list instead
Your own catch-all share is more useful than any published average, and you can get it in a single pass. Here is what to measure.
| Metric | How to get it | Why it matters |
|---|---|---|
| Catch-all share | Accept-all bucket ÷ total contacts after a bulk run | Sizes the problem in absolute terms |
| Catch-all share by industry | Same, split by firmographic field | Shows where the problem concentrates |
| Catch-all share by company size | Same, split by employee band | Usually rises with size |
| Revenue exposure | Pipeline value of accounts in the catch-all bucket | Turns a data issue into a commercial one |
| Valid rate after resolution | Valid ÷ total catch-all, post-resolution | Tells you what you were about to delete |
| Engagement gap | Engagement on catch-all segment vs verified segment | Reveals silent discards |
That last row is the one most teams have never looked at. If your catch-all segment shows normal delivery rates but markedly lower engagement than your verified segment, a meaningful portion of those "deliveries" are reaching nobody at all.
What the unresolved bucket actually costs
The direct cost — ESP fees for mailing dead addresses — is real but usually the smallest line. The expensive costs are the ones that do not appear on an invoice.
Silent discards masquerading as deliveries. A catch-all domain can accept your mail and quietly drop it. Your ESP records a delivery. You mail that contact again next month, and every month after. Over a year you accumulate a segment with excellent delivery statistics and no human on the other end.
Reputation drag on your valid contacts. Mailbox providers score list quality from bounces, complaints and engagement patterns. A large unengaged segment degrades placement for the whole domain, so the damage lands on the people who *do* want your mail. The thresholds are covered in Are Catch-All Emails Safe to Send?.
Wasted human time. A rep chasing a "delivered, no reply" contact that never existed spends real hours on nothing, and concludes the messaging is wrong when the address was.
Corrupted experiments. Every A/B test computed against a denominator containing unreachable addresses is noisier than it appears. Some conclusions drawn from that noise will be wrong, and you will act on them.
Deleted pipeline. The most-overlooked cost. Teams that suppress everything risky delete contacts at their best-fit accounts and never learn what they threw away.
How to use this page
If you are building a business case internally, the honest framing is this:
1. Do not lead with an industry percentage. Someone will ask for the source and the conversation will become about methodology instead of about your list. 2. Lead with your own measured catch-all share from a single bulk run. 3. Attach revenue exposure — the pipeline sitting in the unresolved bucket. 4. Show the engagement gap between catch-all and verified segments as evidence of silent discards. 5. Then quantify the alternative: resolution costs a defined amount per address; the unresolved bucket costs an undefined amount indefinitely.
For the underlying mechanics, What Is a Catch-All (Accept-All) Email Address? is the primer.
Get your own number
You do not need an industry statistic to make this decision — you need yours. Run a sample of your list through the free email checker to see how individual stuck contacts resolve, then check pricing for bulk credit packs that never expire.
The number that matters is the one from your own database.
Frequently asked questions
Ready to clean your list?
Verify your emails with VeriMailX and send your next campaign with more confidence, fewer bounces and better results. Unlimited free single email verification — no card required.
