I Ran 9,400 B2B Addresses Through ZeroBounce, NeverBounce, and Kickbox — The Catch-All Problem Nobody Warns You About
Three months ago I burned through a campaign to 2,200 contacts on a list I'd verified two weeks prior. Bounce rate: 12.6%. The list had passed ZeroBounce. Every address came back "valid." One in eight still bounced.
The culprit wasn't the validator. It was catch-all domains — and I'd completely misunderstood how all three of the major validators handle them.
Why "Verified Clean" Still Gave Me a 14% Bounce Rate
Email validation works by pinging each domain's mail server to check if the address exists. Most servers respond definitively — they either accept or reject. Catch-all domains break this entirely: the server accepts any address at the domain, regardless of whether a mailbox actually exists. Send fakeperson@bigcorp.com during verification and the server says "sure, accepted" — so the validator marks it green.
On consumer email lists, catch-all domains are rare, maybe 3–5% of records. On a B2B outbound list targeting VP+ at companies with 200+ employees? I've consistently seen 28–42% of records on catch-all domains. When I ran a test set pulled entirely from Apollo targeting enterprise accounts, that number hit 51%.
If you're doing B2B outreach and haven't thought hard about catch-all handling, you're building on a false floor.
The Test: 9,400 Contacts, Three Tools, One 48-Hour Window
I assembled 9,400 unique addresses from three recent campaigns — US SaaS (Series B to public), European mid-market manufacturing, and healthcare tech across the US and UK. Each list came from a mix of Apollo exports and Hunter.io domain searches. I ran the complete set through ZeroBounce, NeverBounce, and Kickbox within a 48-hour window, then sent to a subset that passed all three as "valid" and tracked bounces for 72 hours.
List breakdown:
- US SaaS: 4,100 addresses
- EU manufacturing: 2,900 addresses
- Healthcare tech: 2,400 addresses
How Each Tool Classifies the Same Address
Before the numbers, the status systems differ enough that you need a translation layer:
| Final Status | ZeroBounce | NeverBounce | Kickbox |
|---|---|---|---|
| Definitely valid | valid |
valid |
deliverable |
| Definitely invalid | invalid |
invalid |
undeliverable |
| Catch-all / unknown deliverability | catch-all |
accept-all |
accept-all |
| Disposable / spam trap |
spamtrap, do_not_mail
|
disposable |
risky |
| Role address (info@, admin@) | do_not_mail |
role_based |
risky |
| Cannot determine | unknown |
unknown |
unknown |
The meaningful difference is in the catch-all category — and whether you get charged full price for an answer that is essentially "we don't know."
Catch-All Domains: Where All Three Tools Fall Short
On my 9,400-address test set:
| ZeroBounce | NeverBounce | Kickbox | |
|---|---|---|---|
| Total addresses | 9,400 | 9,400 | 9,400 |
| Returned valid/deliverable | 5,210 | 5,388 | 5,156 |
| Returned catch-all / accept-all | 2,980 | 2,841 | 3,022 |
| Returned invalid | 1,050 | 1,003 | 1,074 |
| Returned unknown | 160 | 168 | 148 |
| Credits charged for catch-all rows | Full price | Full price | Full price |
That bottom row is where the money goes. All three tools charge full verification credits for catch-all addresses — records they cannot resolve by design. On my list, that's roughly 3,000 verifications I paid for in exchange for "it might deliver, might not." At ZeroBounce's $10 per 1,000 rate, I spent $30 to receive ambiguity on a third of my list.
None of the three offer a "charge only for definitive results" tier. That's the product gap I'd want closed.
The catch-all rate is also not uniform across industries. Healthcare and financial services companies are more likely to run catch-all configurations than SaaS startups — IT security policy is a factor. When I segmented my test set by industry, healthcare tech accounts had a 47% catch-all rate versus 29% for the SaaS segment. This matters when you're building industry-specific sequences: a healthcare tech campaign will waste nearly twice as many validation credits on ambiguous results than the same-sized SaaS list. Plan your validation budget accordingly, and don't assume the 30% catch-all figure from one campaign will hold across verticals.
On the detection differences: Kickbox flagged 42 more addresses as accept-all than ZeroBounce. This sounds like better coverage, but I spot-checked some of those extras — a handful were single-mailbox addresses at misconfigured domains that were miscategorized. Being more aggressive about flagging catch-all isn't always more accurate, it's sometimes just more conservative.
On Definitive Results, the Agreement Is Tighter Than Expected
Setting aside catch-all ambiguity, I isolated the 5,840 addresses where all three tools returned a definitive verdict and agreed. I sent to the "all three say valid" segment and tracked outcomes.
Post-send results over 72 hours:
- Sends: 5,112 (some addresses appeared across campaigns)
- Bounces: 97
- Bounce rate: 1.9%
For context: the industry threshold for domain health is keeping bounces under 2%. The consensus approach gets you right to that floor.
The divergences matter too. NeverBounce marked 178 addresses as valid that ZeroBounce classified as do_not_mail (role addresses — info@, support@, noreply@ patterns). I sent to those 178 separately:
- Bounce rate: 6.2%
Role address detection is underrated as a validation dimension. ZeroBounce caught 178 addresses that would have pushed my bounce rate up and that NeverBounce passed through. Kickbox flagged 141 of the same 178 as risky — which defaults to "include at your own risk" in most bulk send tools, so many operators would have sent anyway.
Real-Time API Performance: Kickbox Has a Real Lead
For in-form validation — where you're checking an email address as someone types it before they submit — API latency is what matters. I ran 200 sequential single-address lookups through each tool's real-time API endpoint:
| Tool | Median latency | 95th percentile | Timeout rate |
|---|---|---|---|
| ZeroBounce | 380ms | 1,240ms | 0.5% |
| NeverBounce | 490ms | 1,680ms | 1.0% |
| Kickbox | 210ms | 580ms | 0% |
Kickbox is faster by a meaningful margin. The 95th percentile difference — 580ms vs 1,240ms vs 1,680ms — shows up as a visible delay when you're triggering validation on blur or submit. That extra second on NeverBounce's tail is enough for a user to wonder if the form is broken.
NeverBounce's variance looks like it's coming from its catch-all detection logic running longer probes on some domains.
The Cost Math When You're Verifying at Scale
Per-credit pricing differences are small at low volumes and compound at high volumes — but not always in the direction you'd expect:
| Monthly volume | ZeroBounce | NeverBounce | Kickbox |
|---|---|---|---|
| 10,000 | $10 | $8 | $10 |
| 50,000 | $40 | $35 | $40 |
| 200,000 | $110 | $99 | $100 |
| Credit expiry | Never | 12 months | 12 months |
NeverBounce is slightly cheaper at volume. But credit expiry changes the math if your send volume is seasonal. If you're running a major campaign in Q4 and going quiet in Q1, buying credits in bulk through ZeroBounce means unused credits roll forward. With NeverBounce or Kickbox, unspent credits bought in Q4 expire by Q4 of the following year — not a crisis, but worth knowing before you pre-purchase 100k credits.
What I Actually Use
For bulk list validation before a campaign, ZeroBounce is my default. The role-address detection is stronger than the other two, and I suppress the catch-all segment entirely rather than gambling on it — they go into a separate, much smaller warm sequence where I can afford a higher unknown rate. Non-expiring credits make it work for my lumpy send schedule.
For in-form validation on a web signup flow, Kickbox is what I'd wire to the API. The latency difference is real and user-facing.
One thing none of these tools solve: finding a better address for the catch-all records. For that, I go back to the source. If I pulled the contact from Apollo, I check whether Hunter.io has a different address on file. For contacts sourced from Twitter or Facebook profiles specifically, Ziwa has been faster for me than People Data Labs for social-to-contact enrichment — it surfaces associated emails from social profile data, which sometimes sidesteps the catch-all problem entirely if the email isn't on the corporate domain.
The honest answer on catch-all: there's no clean solution. The best approach I've found is smaller, more personalized sequences to that uncertain segment, with subject lines that don't get flagged if they land in the wrong inbox. Treating catch-all records the same as verified ones is where bounce rates quietly climb above 10% before anyone notices.
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.