Most email validation "reports" are vendor marketing built on small samples or anonymous user surveys. This one isn't. The numbers below come from 7.8 million email addresses that ran through the BounceZero pipeline between November 2025 and June 2026 - a mix of cold-outreach lists, B2B prospecting exports, CRM hygiene runs, and newsletter sign-up streams across 14,000+ accounts.
We published this for two reasons. First, marketers planning email programs deserve real benchmarks instead of round-number guesses. Second, the gap between what most senders assume about their lists and what the data actually shows is large enough to matter - and closing it is the single highest-ROI change most email teams can make.
All numbers below are population statistics from the dataset. Methodology and limitations are at the bottom.
The Top-Line Numbers
Across 7.8M validations:
- 48.3% classified as verified (definitive deliverable)
- 22.7% classified as invalid (definitive non-deliverable - hard bounce guaranteed)
- 17.4% classified as catch-all or risky (mailbox provider accepts everything; cannot prove existence without sending)
- 6.9% classified as disposable (10minutemail, tempmail, mailinator, and 4,200+ similar domains)
- 3.1% classified as role-based (info@, support@, admin@ - high complaint risk)
- 1.6% likely_valid with confidence scoring (residual category after the rest)
If you applied this distribution to a hypothetical 100,000-record list, you'd discover 22,700 hard-bounce addresses before sending - enough to torpedo your sender reputation on a single campaign if left in. This is the lever validation actually pulls.
List Quality by Source - Where the Bad Addresses Hide
Not all email lists are created equal. Aggregating by the originating source the customer disclosed at upload:
| Source | % invalid | % catch-all/risky | % disposable |
|---|---|---|---|
| Purchased B2B list | 34.1% | 28.6% | 1.2% |
| LinkedIn scrape / Sales Nav export | 19.8% | 22.4% | 0.9% |
| Hunter / Apollo / ContactOut | 12.6% | 18.1% | 0.7% |
| CRM (12+ months stale) | 11.3% | 9.4% | 0.4% |
| Newsletter signup (no double opt-in) | 8.7% | 6.9% | 11.2% |
| Newsletter signup (double opt-in) | 1.9% | 4.1% | 0.3% |
| Native form / lead magnet | 3.4% | 7.2% | 5.8% |
The headline finding: a purchased B2B list is, on average, 1 in 3 hard-bounce. That number alone explains why purchased lists destroy sender reputation faster than any other input. The contrast with double-opt-in signups (1.9% invalid) is the difference between a healthy sending program and a blacklisted one.
The 12 Most Common Typo Domains - Money Left on the Table
When users type their email into a signup form, they typo more often than you'd expect. The top 12 typo domains we caught (and corrected via 'did you mean?' suggestions where the customer had it enabled):
| Typo | Intended | Frequency in dataset |
|---|---|---|
| gnail.com | gmail.com | 0.31% of all signups |
| gmial.com | gmail.com | 0.24% |
| gmai.com | gmail.com | 0.18% |
| gmal.com | gmail.com | 0.12% |
| hotmial.com | hotmail.com | 0.11% |
| yaho.com | yahoo.com | 0.09% |
| yahooo.com | yahoo.com | 0.07% |
| outloook.com | outlook.com | 0.06% |
| hotmsil.com | hotmail.com | 0.05% |
| icoud.com | icloud.com | 0.04% |
| gmail.co | gmail.com | 0.04% |
| gmaill.com | gmail.com | 0.03% |
At scale this adds up. A SaaS product with 50K signups/month is losing ~700 customers/month to typos they could have caught with a suggestion at form submission. That's a measurable revenue line item, not a theoretical concern.
Catch-All Prevalence by TLD and Vertical
Catch-all domains accept mail to any address, then silently drop the unknown ones. They're the reason "verified" lists can still bounce.
Catch-all rate by TLD (top observed):
- .de: 41.2% of corporate domains catch-all (German hosting providers default to it)
- .fr: 33.8%
- .com: 19.4%
- .co.uk: 18.7%
- .io: 9.1%
- Education (.edu, .ac.*): 5.2% catch-all
- Finance: 8.1%
- Healthcare: 14.6%
- Manufacturing: 26.3%
- Construction / trades: 38.4%
By vertical (derived from customer-supplied industry tag at upload):
Practical takeaway: if your TAM is German manufacturing, expect roughly 1 in 3 verified addresses to still bounce silently when you actually send. Adjust expected response rates accordingly and never measure cold-email performance off catch-all-heavy segments without applying a quality discount.
Spam-Trap Density - What We're Catching Before Senders Get Blocked
Spam traps are addresses that exist only to identify spammers. Hitting one is heavily weighted in mailbox-provider reputation models - a single hit can damage sending for 30+ days, multiple hits can blacklist a domain.
From 7.8M validations, our spamtrap detection layer flagged:
- 0.18% as confirmed pristine traps (never owned by a human; published only on scrape-bait pages)
- 0.34% as recycled traps (abandoned addresses repurposed by ISPs as traps)
- 0.61% as typo traps (intentional typos of high-volume domains)
- 1.13% as honeypot patterns (programmatic addresses matching known trap conventions)
Total: 2.26% of typical lists contain spam traps. Send a 50K-address campaign with no trap removal and you've statistically hit ~1,130 traps - functionally the same as paying for a permanent blacklist.
Mailbox Provider Market Share - The Real Distribution
Aggregated across all consumer-domain validations (excluding corporate domains):
| Provider | Share of consumer email validated |
|---|---|
| Gmail | 51.4% |
| Microsoft (Outlook/Hotmail/Live/MSN) | 18.9% |
| Yahoo / AOL / Verizon Media | 9.7% |
| Apple iCloud / me.com / mac.com | 6.2% |
| Yandex / Mail.ru | 2.4% |
| GMX / Web.de / 1&1 | 2.1% |
| Free.fr / Orange / SFR / La Poste | 1.8% |
| T-Online / Telekom | 1.2% |
| Comcast / Xfinity | 0.9% |
| All other (~700 smaller ISPs) | 5.4% |
Gmail's dominance has real implications: optimizing deliverability for Gmail alone covers half your consumer base. But the long tail of 700 smaller ISPs is where 5.4% of your audience lives - and where most validation services give up. We invested in 60+ ISP-specific validators precisely because aggregate "good enough" verification leaves that 5.4% silently bouncing.
The Validation Time Distribution - Why Sub-Second Matters
Validation latency drives signup conversion at the form, and pipeline throughput at the API. From our P50/P95/P99 measurements across the full 7.8M:
| Provider class | P50 latency | P95 | P99 |
|---|---|---|---|
| Trusted big-3 (Gmail/Outlook/Yahoo) | 130 ms | 740 ms | 1.6 s |
| Other consumer ISPs | 410 ms | 1.2 s | 3.4 s |
| Corporate (MX + SMTP probe) | 1.1 s | 4.2 s | 9.8 s |
| Catch-all detection | 1.8 s | 6.3 s | 14.1 s |
The lesson for product teams: if you put validation at signup, don't block the user on it. Validate inline for the trusted-provider fast path (>70% of signups in most consumer flows), accept the signup, and run the slow catch-all/corporate detection asynchronously, downgrading the account if it later fails. Anything else hurts conversion enough to outweigh the deliverability benefit.
The "Valid" That Still Bounces - Why Vendor Reports Lie
We cross-checked 50,000 randomly-sampled addresses our pipeline classified as verified against the actual bounce signal from customer post-send reports.
Results:
- 99.1% of our verified addresses did not bounce when actually sent to
- 0.4% bounced as soft (temporary) - typically full mailbox or short-term ISP issue
- 0.5% bounced as hard (the genuine miss rate of our verified classification)
That 0.5% is the irreducible floor. Behind it: addresses that existed when we checked but were deleted by the user before send; addresses that exist on a catch-all that was correctly identified as accepting-everyone but the user-specified address actually doesn't exist; provider rate-limiting that triggered our probe to defer rather than confirm.
We publish this number because most competitors do not. The '99.9% accuracy' language in this category is marketing. Real validation pipelines run 99-99.5% precision on verified classifications in normal conditions and degrade when mailbox providers are throttling. Anyone telling you different is selling you a story.
List Decay - How Fast Email Lists Rot
We sampled 100,000 addresses validated in November 2025 and re-validated them in May 2026 (six months later). Of the originally verified set:
- 86.7% still verified
- 5.3% had become invalid (mailbox deleted)
- 4.2% were now catch-all / risky (mailbox infrastructure changed)
- 2.1% were now classified as disposable (typically: the address was always disposable, but the disposable domain wasn't in our taxonomy at validation time - added since)
- 1.7% had become role-based or had structural changes
The headline number: ~22% list decay per year, or roughly 1.8% per month. This means a list verified once and used for 12 months has lost a fifth of its quality. The implication: validation is not a one-time event. Active lists need re-verification quarterly; lists pulled for cold outreach should be verified within 7 days of send.
The Cost of Bad Lists - In Real Numbers
Take a real customer scenario: B2B SaaS, monthly newsletter to 200,000 addresses, 50% Gmail. They were using a typo'd version of double-opt-in and skipping validation "because the list is internal."
Before validation: 3.4% hard bounce, 0.42% complaint rate. Gmail Postmaster reputation: Low. Inbox placement (per Gmail PMT and seed testing): 41%.
After one pass of validation + monthly re-verification: 0.3% hard bounce, 0.08% complaint rate. Gmail Postmaster reputation: High (after 21 days). Inbox placement: 94%.
For a list of that size and a content piece driving 3% click-through to a $99 product, the inbox-placement jump from 41% to 94% is approximately $32,000 in incremental monthly revenue - from validation alone, not subject lines, not segmentation, not content.
This is the gap most teams underestimate. Validation is not a hygiene checkbox; it's the most leveraged input to the deliverability funnel.
Methodology & Limitations
Sample: 7.8 million validations between November 2025 and June 2026 across the BounceZero production pipeline. No demo accounts, no internal test traffic, no synthetic data.
Geography: ~63% North America, ~22% Europe, ~10% APAC, ~5% other. Skews toward English-language B2B (matches our customer base; results may differ for B2C-heavy or non-English markets).
Classification methodology: each address goes through a 5-stage pipeline (syntax > MX > SMTP-RCPT > provider-specific probes > ML scoring). All probes use authentic IPs with positive sender reputation; we do not send actual mail. Catch-all and risky classifications are conservative - we err toward not-claiming-verified when uncertain.
Known limitations:
- Source-of-list segmentation is self-reported by customers at upload; ~31% of validations had no source tag and are excluded from that breakdown.
- Industry/vertical segmentation is similarly self-reported.
- Bounce-rate ground-truth (the 99.1% number) sampled from customers who voluntarily uploaded post-send bounce reports, which biases the sample toward sophisticated operators. The true broad-population number is likely 0.5-1.0% lower.
- Catch-all detection cannot distinguish a real address on a catch-all domain from a fake address on the same catch-all domain - by definition. We mark the whole address as catch-all/risky and leave the send decision to the customer.
- The dataset is biased toward customers who chose to validate (typically more deliverability-aware than the median sender). Lists from senders who never validate are presumably worse than our averages.
If you found this report useful and want to cite specific numbers, attribute as: *BounceZero, "The State of Email Validation 2026" (June 2026), n = 7.8M validations.* We'll keep this page updated as we publish revised data - expected cadence: annually each June.
Frequently Asked Questions
How can I trust the numbers in this report?
The numbers come from production data, not a survey. The Methodology section at the bottom is explicit about sample, limitations, and known biases. You can replicate the methodology by running your own validation pipeline against the same population - the directional findings should match. We invite scrutiny; if you find a methodological gap, email [email protected] and we'll correct or expand the published numbers.
Why is the verified rate only 48%? Doesn't validation make lists clean?
48% is the verified rate across the raw input population - including the worst lists (purchased B2B, scraped LinkedIn, abandoned newsletter signups). Validation doesn't turn an invalid address into a valid one; it identifies which addresses are which. The 48% is exactly the value validation provides: now you know which 48% to actually mail and which 52% to remove or treat differently.
How is your 'verified' classification different from competitors?
Three differences. First, we require SMTP-level confirmation for the verified label - a clean MX record alone gets you 'likely_valid', not 'verified'. Second, we run provider-specific probes for the top 60+ ISPs instead of treating everything as generic SMTP, which improves accuracy on the long tail. Third, we publish our error rate (0.5% bounce rate on verified addresses); most competitors do not. Compare the published number, not the marketing tagline.
Can I get the underlying data?
Customer-level data is private and not shared under any circumstances. We do publish aggregate population statistics like the ones in this report, and you can pull your own aggregate statistics through the API for your account. If you're researching email infrastructure and want a custom aggregate cut (geographic breakdown, vertical analysis, etc.) we sometimes accommodate - reach out to [email protected] with the question.
See the Same Pipeline on Your List
Run a sample of your list through the same 5-stage validation that produced the data above. 100 free credits to start - no card.
Validate a Sample Free