Guide / B2B data quality

Email verification explained: valid, catch-all, and what vendors hide

Published July 16, 2026 ยท VerifiedDesk

Every lead list vendor claims verified emails. Almost none explain what verification actually checked. The difference matters, because "verified" can mean anything from a confirmed live mailbox to a syntax check that only proves the address contains an @ sign.

What a real verification check does

Proper email verification talks to the receiving mail server. The verifier looks up the domain's MX records, connects to the mail server, and asks whether the specific mailbox exists, the same conversation a real email delivery would begin with, stopped before any message is sent. Three outcomes are possible:

  • Deliverable. The server confirmed the mailbox exists. This is the only outcome that deserves the word verified without qualification.
  • Catch-all (accept-all). The server accepts mail for any address at the domain, real or not, so it cannot confirm an individual mailbox. Common on Microsoft 365 and security conscious company domains.
  • Undeliverable or unknown. The mailbox was rejected, or the server refused to answer (greylisting, rate limiting, anti-scraping defenses).

The catch-all problem is bigger than vendors admit

A meaningful share of business domains run catch-all servers; in some industries and regions it is the majority. In our own delivery work we have built lists in segments where fewer than one in five contacts could be individually confirmed, not because the contacts were wrong, but because the servers refuse to say. Any vendor claiming 95 percent plus verified rates across all industries is either cherry picking easy segments or counting catch-all addresses as verified. That second practice is the industry's quietest lie.

The honest treatment is to label catch-all addresses as their own tier: the domain is real, the company is real, the address follows the company's confirmed email pattern, but the individual mailbox is unconfirmed. Priced and treated accordingly.

Pattern matching, used honestly

When a mailbox cannot be confirmed, a good researcher can still find the company's address format from addresses that did verify, published contact pages, or public correspondence. first.last@company.com is not a guess if four colleagues confirm the pattern. But it is still an inference, and a list that mixes inferred addresses in with confirmed ones without labels is hiding its real quality.

Questions that expose a weak vendor

  1. What percentage of this list was individually confirmed at the mailbox level, and when?
  2. How do you label catch-all addresses, and are they priced the same as confirmed ones?
  3. What happens to contacts that fail verification? Removed, disclosed, or quietly left in?
  4. Can you show a per row verification status, not just an overall accuracy claim?

A vendor with good data answers all four in one email. A vendor selling padding changes the subject.

This grading logic is the core of how VerifiedDesk lead lists work: Tier A confirmed, Tier B pattern matched on catch-all domains, Tier C directory grade, and dropped records disclosed with reasons. The tiers exist because the underlying reality has tiers, whoever you buy from.

Based on standard SMTP verification mechanics (RFC 5321 command flow) and VerifiedDesk delivery experience across verification tools and industry segments.