Catch-all email
A catch-all domain accepts mail for every possible address, including ones that do not exist. Because the server says yes to anything, no verifier can confirm whether a specific mailbox there is real.
Businesses set this up so mail to a misspelled address still arrives somewhere rather than bouncing. The side effect is that the usual verification conversation stops being informative: ask about a made-up address and the server accepts it as readily as the real one.
This is where the label "risky" comes from, and it is a genuine answer rather than a hedge. Roughly one business domain in five is configured this way, and small businesses on shared hosting are heavily over-represented — which unfortunately overlaps with the businesses most local lead lists are made of.
The workable approach is to segment rather than delete. Send to confirmed addresses first at normal volume, then send to the catch-all group separately in smaller batches and watch what bounces. A catch-all domain that swallows mail silently is a wasted send; one that delivers is a customer you would have thrown away.
Goes deeper: Email Verification, Explained Properly