Every few weeks a founder shows us a purchased list and says the same thing: "it's verified." Then the campaign starts and the bounces arrive anyway. Nobody lied to them. They just misunderstood what a verification is.
Verification is a conversation, not a certificate
When a tool "verifies" an email address, it opens a conversation with the receiving mail server and asks whether the mailbox would accept mail. The answer is true for that server, from that network, at that moment. It is not a property of the address that travels with it. People change jobs constantly - B2B contact data decays every month, and the mailbox that answered "yes" in March may be deactivated by June.
That is why our operating rule is that verification happens immediately before the first send, not when the list was built. A verification from three months ago is an opinion, not a fact.
Catch-all domains say yes to everything
A large share of business domains run catch-all mail: the server accepts mail for any address at the domain, real or not. Ask it about a made-up mailbox and it still says yes. A "verified" flag on a catch-all address means only that the domain exists. Serious senders treat catch-all as its own risk tier - sendable in controlled volume, watched closely, never counted as clean.
Gateways answer with policy, not truth
When the receiving domain sits behind a security gateway - Proofpoint, Mimecast, Barracuda and peers - the machine answering your verification is the gateway, not the mailbox. Some gateways accept everything at the connection stage and only reject later, after your message is inside; the bounce arrives minutes after your tool told you the address was fine. You can check what is actually answering for any domain with our mail provider lookup - if the MX points at a gateway, read verification results with that in mind.
What this means in practice
The bounce rate you see is a lagging report on the decisions you made before sending. The rules we run:
- Re-verify at send time, every time. List age is bounce risk.
- Classify the receiving environment first; a gateway "valid" is a policy answer, not a mailbox answer.
- Put catch-all addresses in their own tier with their own volume rules.
- Treat verification failures and timeouts as "unknown", never as "fine" - an unanswered question is not a yes.
None of this is exotic. It is the difference between treating deliverability as a purchase and treating it as an operating discipline - and it is why the same list produces different outcomes in different hands. Your bounce handling also feeds your sender reputation, which is much harder to repair than a list.
For the measured version of this argument - six bounce traps from a real postmortem, including the vendor-validation OR trap - see why verified email lists still bounce.