A bounce is not a neutral event. When you send to an address that doesn't exist, the receiving mail server tells your provider, and your provider remembers. Do it a few times across a thousand sends and nothing happens. Do it two hundred times in a week from a three-month-old domain and Gmail starts putting you in spam, Microsoft starts deferring your messages, and your mailbox provider may throttle or suspend the account outright.
This is the single most avoidable deliverability problem in cold email, and it's the one people skip most often — usually because they exported a list, saw 4,000 rows, and wanted to start sending that afternoon.
Sendvanta now has email verification built in, included on every paid plan. Below is what it does, what it can't do, and how to actually use the results.
What a hard bounce actually costs you
Mailbox providers use bounce rate as a proxy for list quality. A sender with a clean list is probably emailing people who asked to hear from them. A sender with a 12% bounce rate is probably working from a scraped or purchased file, and scraped files correlate with spam.
The rough tolerances, based on what senders observe in practice:
- Under 2% — normal. Even good lists decay; people change jobs.
- 2–5% — the warning band. Gmail and Microsoft will start applying pressure here, especially on a young domain with little positive engagement to offset it.
- Above 5% — you are actively damaging the domain. Expect deferrals, spam placement, and in some cases mailbox suspension from your own provider (Google Workspace and Microsoft 365 both police outbound abuse).
The damage is not per-campaign. It attaches to the domain and the sending IP reputation, and it lingers for weeks after you stop. A single 3,000-lead blast with an 8% invalid rate is 240 bounces — enough to knock a new domain into deferral territory in one afternoon, and enough to undo a month of careful warm-up.
Bounces also hide real problems. If 8% of your sends bounce, your reply rate looks worse than it is, your open data is skewed, and you spend a week rewriting copy that was never the issue.
What email verification actually checks
Verification is not a database lookup against a list of "known emails." A good verifier talks to the receiving mail server in real time and asks whether the mailbox exists, using the same protocol conversation a real message would start — without delivering anything.
The checks stack up in layers:
- Syntax — is the address structurally valid at all? Catches typos like `john@@company.com` and `jane@companycom`.
- Domain and MX records — does the domain exist and does it publish mail servers? A domain with no MX records cannot receive mail, period.
- Mailbox existence — a live conversation with the mail server to confirm the specific mailbox is real and accepting mail.
- Disposable domains — throwaway addresses from temp-mail services. Almost always junk in a B2B context.
- Role accounts — `info@`, `support@`, `sales@`, `admin@`. Real mailboxes, but shared ones.
- Known spam traps and recycled addresses — the ones that do disproportionate reputation damage.
In Sendvanta, every lead comes back with one of three labels: valid, invalid, or risky. How you treat each one matters more than the check itself.
Valid, invalid, risky — how to act on each
| Result | What it means | What to do |
|---|---|---|
| Valid | The mail server confirmed the mailbox exists and accepts mail | Send |
| Invalid | Mailbox doesn't exist, is disabled or suspended, the domain can't receive mail, or the address is disposable or a known trap | Do not send. Remove or suppress. |
| Risky | Deliverability can't be confirmed — catch-all domain, role account, or a full inbox | Judgment call. See below. |
Invalid is easy: those are the bounces you were about to generate. Delete them or leave them suppressed and move on. Disabled and suspended mailboxes fall here too — that's the ex-employee whose account was shut off in March but whose address is still sitting in your CRM.
Risky is where people get confused, so it's worth being precise.
Catch-all domains are unverifiable, not bad
A catch-all domain accepts mail addressed to anything@thedomain.com and sorts it out internally. From outside, there is no way to distinguish a real mailbox from an invented one — the server says yes to everything. That's why no verifier can confirm a catch-all address, and why anyone claiming 99% accuracy on catch-alls is selling you a guess.
The correct read is: catch-all means unknown, not dead. Plenty of well-run companies use catch-all configurations. The risk depends entirely on where the address came from.
- A contact who replied to you last year, on a catch-all domain — send. You have direct evidence the mailbox works.
- A name from a conference attendee list or a LinkedIn export with a verified work address — usually fine.
- A pattern-guessed address (`first.last@`) generated by a tool on a catch-all domain — this is where bounces come from. The server accepts the message, then silently drops it or bounces it hours later. You get no reply and no signal.
Practical rule: if more than about 30% of a list comes back catch-all, split it into its own campaign and send it on a separate mailbox from your verified-valid leads. That way, if the catch-all segment bounces badly or gets no engagement, it doesn't drag the rest of your sending down with it.
Role accounts and full inboxes
Role accounts (`info@`, `support@`, `contact@`) are real. They just aren't people. They're monitored by rotating staff, frequently forwarded into ticketing systems, and disproportionately likely to be marked as spam because nobody feels personally addressed by a cold email sent to a shared queue. For most B2B outbound, exclude them. For very small businesses where `info@` genuinely is the owner's inbox, they can work — but treat that as a deliberate segment, not the default.
Full inboxes are a soft signal: the mailbox exists but is currently over quota. Sometimes it clears, sometimes the account is abandoned. Low priority, low risk if you send once.
Verification is necessary, not sufficient
Be honest about the limits. Verification tells you an address can receive mail. It does not tell you:
- Whether the person still works there (they may have a valid mailbox and a new job).
- Whether your message will land in the inbox or the spam folder — that's a separate problem, covered in deliverability vs. inbox placement.
- Whether the contact is a fit for your offer.
- Whether your authentication is set up correctly. A perfectly verified list still fails without proper SPF, DKIM, and DMARC.
Verification removes one specific failure mode. It doesn't replace warm-up, sensible daily volume, or good copy.
How verification works in Sendvanta
Verification is included on all paid plans and runs against live mail servers before a campaign sends, so dead addresses are caught rather than bounced.
How it's structured:
- One credit verifies one address. Included one-time credits: Starter 10,000, Growth 30,000, Pro 60,000.
- Extra credits are $20 per 10,000, and they never expire. No monthly reset, no use-it-or-lose-it.
- Results are cached for 30 days. Re-verifying the same address inside that window costs nothing — so re-running a list you already checked last week is free.
- Bulk verification runs in the background. Kick off a whole lead list, keep working, and per-lead labels appear directly in the leads table as results come in. Filter by status and build campaign segments from there.
Verification sits alongside the rest of Sendvanta's deliverability layer — mailbox and domain health scoring, SpamAssassin scoring of drafts before send, seed-mailbox inbox placement tests, and automatic slow-down when risk thresholds are crossed. You can see the full list on the features page, and plan details and credit allocations on pricing.
One caveat worth stating plainly: verification costs credits, and credits cost money. If you're on the free plan and working with a small, hand-built list of 200 known contacts, you probably don't need it. If you're importing 5,000 rows from a data provider, verifying is cheaper than rebuilding a burned domain.
What bounce rate is too high for cold email?
Under 2% is normal. Between 2% and 5% you're in the warning band and Gmail and Microsoft will start applying pressure, especially on a young domain. Above 5% you should stop the campaign and clean the list before sending again.
Should I send to catch-all addresses?
It depends on the source. A known-good contact on a catch-all domain is fine to email. A pattern-guessed address on a catch-all domain is a real bounce risk. If catch-alls are a large share of your list, send them as a separate segment on a separate mailbox.
How often should I re-verify a list?
B2B email data decays roughly 20-30% a year as people change jobs. Re-verify any list older than about three months before a new campaign. In Sendvanta, results are cached for 30 days, so re-checking recently verified addresses costs no credits.
Do verification credits expire?
No. Included credits and any extra credits you purchase never expire, and there's no monthly reset.
Does verification guarantee my emails reach the inbox?
No. Verification confirms the mailbox exists and can receive mail. Landing in the inbox rather than spam depends on authentication, domain reputation, warm-up, sending volume, and content — separate problems with separate fixes.
Ready to send outbound that lands?
Create your free Sendvanta workspace — no credit card required.
Start free