Why Sending to Unverified Emails Is Like Mailing Letters to Abandoned Houses
Email verification sounds simple until you realize there are actually five distinct levels of checking, each catching problems the previous one missed. Most teams stop at level one or two, then wonder why their bounce rate sits at 7.5% instead of the sub-2% target that keeps deliverability healthy. Only 23.6% of B2B marketers verify their lists before campaigns, which partly explains why hard bounce rates across enrichment tools range from 0.9% all the way up to 11.2%.
Understanding each verification level helps you pick the right tool and set the right expectations. A tool that only does syntax checking is not in the same category as one that performs full mailbox verification with catch-all detection. Here is what actually happens at each level.
Level 1: Syntax Check
This is the most basic filter. A syntax check confirms that the email address follows the correct format: a local part, an @ symbol, and a domain. It catches typos like missing @ signs, double dots, spaces in the address, or invalid characters.
Examples of what syntax checking catches:
- john.smith@@company.com (double @)
- john smith@company.com (space in local part)
- john.smith@company (missing TLD)
- john.smith@.company.com (dot immediately after @)
Syntax checking is instantaneous and free to run. Every verification tool includes it. But it catches maybe 2-5% of bad addresses in a typical B2B list. The real problems are further down the stack.
Level 2: Domain Check
Domain verification confirms that the domain in the email address actually exists and is configured to receive email. This involves two lookups. First, a DNS lookup confirms the domain resolves to an IP address. Second, an MX (Mail Exchanger) record lookup confirms the domain has mail servers configured.
A domain check catches scenarios like:
- john@companytypo.com (misspelled domain that does not exist)
- john@oldcompany.com (company domain that expired after acquisition)
- john@internaldomain.local (internal domains that are not publicly reachable)
This level filters out another 3-8% of addresses in a typical list. It is fast, requiring only DNS queries, and adds maybe a fraction of a second per address. Combined with syntax checking, you have eliminated the obvious junk. But an address can pass both levels and still bounce hard.
Level 3: Mailbox Check
This is where verification gets meaningful. A mailbox check connects to the destination mail server via SMTP and simulates the beginning of an email delivery. The verification system says, essentially, "I have a message for john@company.com, will you accept it?" The mail server responds with either a 250 code (yes, that mailbox exists) or a 550 code (no, that user is unknown).
The SMTP conversation looks roughly like this: the verification server opens a connection, sends a HELO command, specifies a sender address, then asks the recipient server to verify the target address using the RCPT TO command. If the server rejects the recipient, the address is invalid.
Mailbox checking catches the most common real-world problem: addresses that look correct and have valid domains but belong to people who have left the company, changed roles, or never had that specific mailbox. Given that 15-20% of professionals switch jobs every year and job titles change for 65.8% of contacts within 12 months, this check is doing heavy lifting.
The catch with mailbox verification is that some mail servers are configured to accept all incoming addresses regardless of whether the mailbox exists. These are catch-all domains, and they are the subject of level four.
Level 4: Catch-All Detection
A catch-all domain is one where the mail server accepts email for any local part, real or not. Send an email to literally-anything@catchalldomain.com and the server will accept it. This means SMTP verification (level 3) cannot tell you whether a specific mailbox actually exists on that domain, because the server says yes to everything.
Catch-all detection tests this by sending a verification request for a deliberately fake address at the domain, something like randomstring8472@targetdomain.com. If the server accepts this obviously fake address, the domain is catch-all.
Why does this matter? Because catch-all domains create a verification blind spot. Your tool reports the address as valid (the server accepted it), but the individual mailbox might not exist. When you actually send an email, it could bounce, get silently dropped, or land in a general inbox nobody monitors.
The business impact is real. If 15-20% of your enriched list consists of catch-all domains and you treat them all as verified, you could be sending to addresses with a significantly higher bounce risk. The safe approach: flag catch-all addresses separately, send to them in smaller batches, and monitor bounce rates closely. Some teams reduce daily send volume to catch-all domains by 50-75% compared to fully verified addresses.
Level 5: Disposable and Role-Based Detection
The final verification level checks for two types of addresses that are technically valid but practically useless for B2B outreach.
Disposable email detection identifies temporary email addresses from services like Mailinator, Guerrilla Mail, and Temp Mail. These addresses self-destruct after minutes or hours. They pass every other verification level because the domain exists and the mailbox is active, but the person behind them has no intention of reading your email. These show up most often in free trial signups and gated content downloads.
Role-based detection identifies addresses like info@, sales@, support@, marketing@, and admin@. These are departmental addresses, not personal ones. They pass all technical checks because the mailboxes exist and receive email. But they are problematic for outbound sales because nobody feels personally addressed, open rates plummet, and some email providers flag high volumes of role-based sends as a spam signal.
Role-based addresses are not always bad. If you are sending a partnership inquiry, info@ might be appropriate. But for SDR outreach targeting a specific VP of Sales, a role-based address means your enrichment did not find a personal work email, and you should either re-enrich or flag for manual research.
What Good Verification Looks Like in Practice
A proper verification pipeline runs all five levels in sequence. For a list of 10,000 contacts, you would expect results roughly like this:
- Syntax failures: 100-300 addresses (1-3%)
- Domain failures: 200-500 addresses (2-5%)
- Mailbox failures: 500-1,500 addresses (5-15%)
- Catch-all flagged: 1,000-2,000 addresses (10-20%)
- Disposable/role-based flagged: 200-400 addresses (2-4%)
- Fully verified: 6,000-8,000 addresses (60-80%)
The catch-all category is the tricky one. Those addresses are not invalid, but they are not confidently valid either. Your options: send with caution, re-enrich through a different source to find a personal address at the same company, or accept the risk and monitor bounces.
How Verification Quality Varies Between Tools
Not all verification tools run all five levels. Some skip catch-all detection entirely. Others skip disposable detection. And the accuracy of mailbox-level checking varies because mail servers can behave unpredictably, including greylisting (temporarily rejecting the first attempt) and rate limiting (blocking verification requests if too many come from the same IP).
A benchmark study testing 20,000 contacts across multiple tools found hard bounce rates ranging from 0.9% to 11.2%. That is a 12x difference in quality between the best and worst performers. The 14.7% mismatch rate between company names and email domains in some tools suggests that verification alone is not enough if the underlying data is wrong to begin with.
The takeaway: verification is essential, but it is not a substitute for accurate enrichment. The best results come from pairing a high-quality waterfall enrichment provider (which finds the right email in the first place) with thorough five-level verification (which confirms it is deliverable). Skipping either step puts your deliverability and your domain reputation at risk. And once your domain lands on a blacklist like Spamhaus or Barracuda, recovery takes 2 to 8 weeks of lost outreach capacity.




