All posts

How to Spot Fake, Disposable, and Catch-All Email Addresses

Fake, disposable, and catch-all emails all look normal on the surface. Here’s how to actually tell them apart before you send.

Sabbir Hossain
Sabbir Hossain
SF Email Verifier team
August 10, 2026

Three different problems get lumped under “bad email address,” and they’re not the same thing at all. A fake address is just made up. A disposable one is real but temporary, built to be thrown away. A catch-all sits in its own category entirely — the domain itself is configured to say yes to everything, whether the specific mailbox is real or not.

Knowing which one you’re looking at changes what you should do about it. Here’s how to tell them apart, why each one exists in the first place, and how to build a policy around each that doesn’t either waste real leads or keep dead weight on your list.

Fake emails

A fake address is one that was typed in but was never a real mailbox — either invented on the spot (“test@test.com,” “asdf@asdf.com”) or a typo so far off it doesn’t map to anything (“john@gmali.con”). These usually fail at the syntax or MX record layer, the earliest and simplest checks a verifier runs.

How to spot one: Obvious patterns — repeated keyboard-adjacent characters, placeholder-looking words like “test” or “none,” domains that don’t resolve at all. A syntax and MX check (the first two layers described in what an email verifier actually checks) catches nearly all of these instantly.

Why people submit fake addresses at all, and why it’s worth thinking about the underlying motivation rather than just the pattern: Usually one of a few reasons — someone rushing through a form and not caring about follow-up, a bot or automated script submitting garbage data at scale, or someone deliberately trying to avoid providing any real information at all while still getting past a required field. Understanding which of these is most common in your specific context (a signup form gets more bot traffic than a manually-entered CRM record, for instance) helps you decide how much scrutiny to apply and where.

Disposable emails

A disposable address is real — it works, mail delivered to it actually arrives — but it’s created through a service specifically built for temporary use, meant to be abandoned shortly after. Mailinator, Guerrilla Mail, and similar services are the common names here; they let anyone generate a working inbox with no signup, read whatever lands in it, and never touch it again.

How to spot one: The domain matches a known disposable-email provider. This isn’t guessable by eye in most cases — “getnada.com” and “yopmail.com” don’t look obviously fake — which is why verifiers maintain lists of known disposable domains rather than relying on pattern-matching alone. New disposable services appear regularly, too, so a verifier’s list needs ongoing maintenance rather than being a fixed, one-time reference.

Why people use them: Almost always to get past a signup gate — a gated PDF, a free trial, a “sign up to see pricing” wall — without committing a real address they’ll get marketing email on. It’s a rational move from the user’s side. It’s also a strong signal that whoever’s behind it isn’t a real, ongoing lead.

A subtler variant worth knowing, and one that trips up simpler detection systems: some people use a legitimate email alias or forwarding service (rather than a disposable one specifically) for privacy reasons — a service that forwards mail to their real inbox while masking the actual address from whoever they gave it to. These don’t behave like disposable addresses functionally (mail does reach a real person consistently), but they can sometimes get flagged similarly by less sophisticated detection systems that lump “any address not directly tied to a major consumer provider” into one bucket. A well-maintained disposable-domain list distinguishes genuine throwaway services from privacy-forwarding services, since the two represent very different user intents.

Catch-all domains

This is the trickiest category because it’s not about the address being fake — it’s that the domain’s mail server is configured to accept mail sent to any address at that domain, valid mailbox or not. Ask the server “does jane@company.com exist,” and it says yes. Ask it about “zzzzz@company.com,” and it also says yes.

How to spot one: You genuinely can’t tell by looking at the address. It requires actually testing the domain’s behavior — sending a check to a deliberately made-up address at that domain and seeing if the server accepts it anyway. If it does, every address at that domain gets flagged as catch-all rather than a confident valid or invalid, because the SMTP-level check (detailed in how to verify without sending an email) can’t distinguish real from fake there.

Why domains do this, which is worth understanding since it changes how suspicious you should be of the label: Sometimes intentionally, as a company mail policy — often specifically so a typo in a colleague’s name (jon@ instead of john@) doesn’t bounce and get lost, but instead lands somewhere, even if it’s the wrong inbox, where a human can redirect it. Other times it’s just a default configuration nobody changed when the company set up its mail server, inherited from whatever hosting provider or template they used. Either way, it’s common enough among small businesses that catch-all doesn’t mean “suspicious” — it means “unconfirmable,” which is a different thing entirely.

A detail worth knowing, since it changes how you should read multiple contacts at the same company: catch-all configuration is a domain-wide setting, not something that varies by individual address at that domain. If you’ve confirmed one address at a company is genuinely catch-all, every other address at that same domain will show the same catch-all status, regardless of whether that specific mailbox exists. This is useful context when you’re evaluating a whole team’s worth of contacts at the same company — you won’t get more clarity by checking a second or third address there, since the domain-level behavior is the same across all of them.

Why this matters more than it might seem for a “small” list

Even a modest signup list — a few hundred contacts, not thousands — benefits from this distinction, because the proportions matter less than the decisions you make with each category. A 300-contact list with 20 catch-all addresses handled correctly (kept, monitored, engaged) versus handled carelessly (discarded outright) is the difference between a list of 300 usable contacts and a list of 280, for no real reason beyond an overcautious policy.

Side-by-side comparison


Looks fake by eye?

Passes MX check?

Passes SMTP mailbox check?

Real risk

Fake/typo

Usually yes

Often fails

N/A

Will bounce

Disposable

Rarely

Yes

Yes (mailbox is real)

Low engagement, not a real lead

Catch-all

Never

Yes

Ambiguous (accepts everything)

Unconfirmable, could be real or fake

Why lumping all three together is a mistake

It’s tempting to treat “not clearly valid” as one undifferentiated pile of bad addresses, especially under time pressure. But each of these three categories calls for a genuinely different response, and collapsing them loses information you’d otherwise have.

Fake addresses are unambiguously worth removing — there’s no ambiguity, no real person behind them, nothing to lose by dropping them. Disposable addresses are worth excluding from marketing specifically, but the person behind one might still be a legitimate visitor who was simply cautious about giving out their real address, which is worth remembering if you’re ever evaluating overall signup quality rather than individual send decisions. Catch-all addresses are the one category where treating them the same as fake or disposable actively risks losing real, reachable contacts — the whole point of the catch-all label is that the tool genuinely doesn’t know, and assuming “unknown” means “bad” throws away information rather than acting on it honestly.

How these three categories show up differently depending on where your leads come from

The mix of fake, disposable, and catch-all addresses you’ll see isn’t random — it correlates fairly predictably with how you’re collecting emails in the first place, and knowing this pattern helps you anticipate what a given list is likely to contain before you’ve even run it through a checker.

Gated content and lead magnets (free PDFs, templates, checklists) tend to attract the highest disposable rate of the three collection methods, since the barrier to entry is low and the incentive to avoid future marketing email is high. Someone who just wants the PDF and nothing else is a rational candidate for a throwaway address.

Event and conference sign-ups, especially paper or semi-manual ones later transcribed, tend to produce the highest fake/typo rate, simply from the mechanics of handwriting misread during data entry, or people rushing through a sign-in sheet without double-checking what they wrote.

B2B signup forms gated behind a real product trial or demo request tend to have the lowest fake and disposable rates of the three, since someone requesting an actual demo generally has a real reason to want your team to reach them — but this is also where catch-all rates run highest, since B2B software buyers are disproportionately likely to be at small-to-midsize companies with less strict IT mail configuration than a large enterprise would have.

Knowing this pattern in advance doesn’t replace running an actual check, but it does help you set expectations and plan your review process — a lead-magnet list is worth extra scrutiny on the disposable front specifically, while a demo-request list’s catch-all group is more likely, on balance, to represent genuine, reachable prospects than a stranger’s random guess would suggest.

The cost of getting each category wrong, in both directions

It’s worth being explicit about the actual cost of misjudging each category, since the mistakes run in different directions depending on which one you get wrong.

Under-filtering fake addresses costs you directly through bounces and the deliverability damage covered in how bulk verification protects sender reputation — there’s no offsetting upside to keeping these, since there’s no real person behind them at all.

Over-filtering disposable addresses rarely costs you much, since by definition these represent people actively trying to avoid ongoing contact — you’re not likely to be losing a valuable relationship by excluding them from a nurture sequence, even if the underlying human might have been a legitimate visitor.

Over-filtering catch-all addresses is the costliest mistake of the three in the opposite direction — it’s the one category most likely to contain real, valuable, reachable people, and treating “unconfirmable” as synonymous with “bad” means quietly discarding leads and contacts that a slightly more patient approach (a small test send, a secondary corroborating signal like a LinkedIn profile) could have recovered.

This asymmetry is worth internalizing as a rule of thumb: be aggressive about excluding confirmed-fake addresses, moderately aggressive about disposable ones, and genuinely cautious about treating catch-all as equivalent to either of the other two.

A quick example

A course creator — call her Talia — runs a free-webinar funnel with a lead-magnet PDF gate. Reviewing her list of 500 signups, three categories jump out once she runs it through a verifier: 22 addresses are obvious typos and placeholders (fake), 34 are from known disposable providers, and 61 sit behind catch-all domains at small companies.

Without knowing the difference, Talia might have assumed all 117 of those were equally low-value and excluded them from her nurture sequence. But the 61 catch-all addresses are a mixed bag — some are real employees at real small businesses whose IT setup just isn’t strict. Excluding those outright would have meant losing potentially real leads over an ambiguous signal, not a confirmed bad one.

What Talia actually did, worth detailing: she kept the 61 catch-all addresses in her nurture sequence but tagged them separately in her email platform, and tracked their open and click rates over the following month as a group. About a third of them engaged at a rate roughly comparable to her confirmed-valid list — real evidence, gathered directly rather than assumed, that a meaningful chunk of that ambiguous group were genuine, engaged subscribers who simply happened to be at catch-all-configured companies.

What to actually do with each category

  • Fake/typo — remove. These are dead ends, no ambiguity.

  • Disposable — exclude from marketing sends. If it’s a support or transactional context rather than marketing, use judgment; not everyone using a disposable address is being adversarial.

  • Catch-all — treat as medium confidence. Don’t auto-exclude, especially for smaller, high-value lists. Do watch bounce behavior if you include them in a large send.

Building a lightweight scoring approach instead of a binary include/exclude

For teams handling this at any real scale, a slightly more nuanced approach than a strict include/exclude rule can pay off: treat each category as carrying a different weight rather than a hard yes/no. Fake and clearly invalid addresses get excluded outright, no exceptions. Disposable addresses get excluded from marketing sends by default but flagged (not deleted) so a support or sales context can still reach them if relevant. Catch-all addresses get included by default in most contexts, but segmented into their own tracked group so you can monitor their actual engagement over time and adjust your confidence in that segment based on real data rather than assumption.

This kind of lightweight scoring doesn’t require sophisticated tooling — a simple tag or column in your CRM or spreadsheet marking each category, reviewed periodically against actual engagement, gets you most of the benefit without building anything elaborate.

How disposable domain lists actually get maintained

It’s worth understanding, briefly, what’s behind a verifier’s claim to detect disposable addresses, since it’s not a static, one-time-built list. New disposable email services launch fairly regularly — often small, low-profile projects that don’t attract much attention until they’ve been used to bypass signup gates on a meaningful number of sites. A serious verification provider tracks this landscape on an ongoing basis: monitoring for new services, checking domain registration patterns common to throwaway-email providers, and incorporating community and industry-shared lists of known offenders.

This matters practically because a verifier’s disposable detection is only as good as how recently its list was updated. A tool that built a disposable-domain list once, years ago, and never revisited it will increasingly miss newer services as they appear — which is one more reason “verified” isn’t a fixed, one-size-fits-all guarantee across every tool claiming to offer it.

Check which category your list actually falls into

Run your addresses through the homepage checker or the bulk verifier on sfemailverifier.com to see fake, disposable, and catch-all flagged separately — not lumped into one vague “bad” bucket. For a full breakdown of every possible status a check can return, see what “email verified” actually means.



Share this post

Questions

Frequently asked questions

Can I tell if a domain is a catch-all just by looking at it?

No. Catch-all status can only be reliably determined by testing the domain’s mail server behavior. There’s no visual pattern, domain name, or naming convention that reliably identifies a catch-all domain.

Are all disposable emails from the same handful of providers?

No. New disposable-email services appear regularly. That’s why a good verifier continuously maintains and updates its list of known disposable domains rather than relying on a fixed, outdated list.

Is a catch-all address more likely to be fake than real?

Not necessarily. Catch-all is a mail server configuration choice and doesn’t indicate whether a particular address belongs to a real person. It’s an ambiguous result, not a signal that the address is probably fake.

Why would a legitimate company use a catch-all mail setup?

It may simply be the default configuration, or the company may intentionally use catch-all to prevent messages from being lost because of minor address typos, such as sending to jon@ instead of john@. Neither reason is inherently suspicious.

Do fake, disposable, and catch-all emails all show up as the same status?

No. They are different categories and should be reported separately because each requires a different response. sfemailverifier.com, for example, distinguishes these statuses as part of its email verification results.

If one address at a company comes back to catch-all, will every address at that company show the same result?

Yes. Catch-all is a property of the domain’s mail server configuration rather than an individual email address. Once a domain is confirmed as catch-all, that configuration applies to addresses across the domain.

Should I pay extra attention to a specific person’s role when evaluating a catch-all address?

It can be useful as a secondary signal. A catch-all address associated with a named employee who has a verifiable presence at the company is generally more credible than an address with no supporting information. However, this should complement not replace email verification.

Is it worth handling privacy-forwarding email services separately from disposable ones?

For many everyday use cases, treating privacy-forwarding addresses similarly to disposable addresses such as excluding them from marketing is a reasonable simplification. A more nuanced policy may be worthwhile if these addresses appear frequently in your data.

How quickly do new disposable email services get added to a verifier’s detection list?

It varies by provider. A well-maintained verifier should update its disposable-domain list continuously rather than treating it as a one-time task, since new throwaway services appear regularly. If disposable detection is important to your use case, it’s worth asking the provider how frequently its list is updated.

Should I treat a catch-all address differently at a large, well-known company versus a small one?

Company size can be a useful secondary signal, but it isn’t conclusive. Larger organizations with dedicated IT teams may be less likely to use catch-all configurations, while smaller businesses may inherit them from default hosting settings. However, large companies can also intentionally use catch-all, so domain size alone shouldn’t determine whether an address is accepted or rejected.

Sabbir Hossain
Written by
Sabbir Hossain
CTO

Passionate about technology, innovation, and creating impactful digital solutions.

LinkedIn
/// stop guessing

Clean your list in 60 seconds.

Run your next campaign against a verified list. 20 free credits every day, no card required.

Start free