Skip to content

Free Tool

Catch-All Email Detector

Check if a domain has catch-all (wildcard) email enabled. Essential for email verification, list cleaning, and understanding mail server configuration.

Free instant check — no signup required

Understanding Catch-All Email

A catch-all email configuration (also called a wildcard mailbox) tells a mail server to accept all incoming email for a domain, regardless of whether the recipient address actually exists. Instead of bouncing undeliverable messages, the server routes them to a designated mailbox or simply accepts them.

While catch-all can be useful for preventing lost emails, it creates challenges for email verification and list hygiene. When verifying an email address, the standard approach is to check if the mail server accepts the recipient via SMTP. With catch-all enabled, every address appears valid, making it impossible to distinguish real mailboxes from non-existent ones.

From a security perspective, catch-all domains are more susceptible to spam, phishing, and directory harvest attacks. Disabling catch-all is generally recommended unless you have a specific business need. Most modern email providers like Google Workspace and Microsoft 365 do not enable catch-all by default.

Use this detector alongside our mail server fingerprinting tool to get a complete picture of your mail server configuration, or run a full domain security report for a comprehensive audit.

Frequently Asked Questions

What is a catch-all email domain?
A catch-all (or wildcard) email domain is configured to accept all incoming emails regardless of the local part (the part before the @). For example, if example.com has catch-all enabled, emails sent to anything@example.com will be accepted — even if that specific mailbox doesn't exist. The mail server will not reject messages for non-existent addresses.
Why do some domains use catch-all?
Organizations use catch-all for several reasons: to prevent missed emails due to typos, to create disposable addresses on the fly (like support-ticket-123@company.com), to simplify email management for small teams, or to monitor what addresses are being targeted by spammers. Some domains use it temporarily during email migration to ensure no messages are lost.
Why is catch-all detection important for email verification?
When verifying email addresses, catch-all domains present a challenge because the mail server will accept any address — you can't tell if a specific mailbox actually exists. Email verification services flag catch-all domains as 'accept-all' or 'unverifiable' because an SMTP RCPT TO check will always return a positive result regardless of whether the recipient exists.
Is catch-all bad for security?
Catch-all can increase security risks. It makes your domain more attractive to spammers since every address they try will be accepted. It can also be exploited for directory harvest attacks, where attackers probe for valid addresses. Additionally, accepting all mail increases the volume of spam and phishing emails your domain processes, putting more strain on spam filters.
How does catch-all detection work?
The detector connects to the domain's mail server and performs an SMTP RCPT TO command with a randomly generated, unlikely-to-exist email address. If the server accepts the recipient, it indicates catch-all is enabled. If the server rejects it with a '550 user unknown' or similar error, the domain does not have catch-all enabled. Some servers use greylisting or defer responses, which can affect detection accuracy.

Need continuous monitoring?

Get automatic alerts when your mail server configuration changes. Monitor email security, blacklists, and DNS records.

Start Monitoring Free