The flow that Josh has outlined is correct, and it's also correct that the Marketo Email Invalid field cannot be mapped to SFDC. We have set ours up so that it is only a unidirectional (Marketo to SFDC) sync, as I didn't want anyone else telling Marketo whether an email address was invalid -- it isn't always used the way you want it to be used.
Also, in case you don't already have one set up, be sure to have an email invalid "uncheck" campaign for if the email address is updated. Otherwise, even if someone puts a new or corrected email address in, the person still won't be emailed.