How to Buy Google Workspace Mailboxes for Cold Email at Scale
Buy Google Workspace seats on alternate domains you own, roughly 2–3 mailboxes per domain and one mailbox per ~30 sends/day. Two routes work: direct from Google (one tenant, many secondary domains), or through an authorized infrastructure provider like Inboxlogy that provisions the mailboxes and SPF/DKIM/DMARC for you at $2.80/mailbox/month. The mailboxes are the easy part. What determines whether they survive is domain structure, authentication, and a slow ramp inside your sending tool.
The mechanics below: how many mailboxes you need, where to buy them, how to structure domains and tenants, what DNS to set, how to connect and warm them, what it costs, and how to spot a vendor selling you accounts they will lose control of in three months.
How many Google Workspace mailboxes do I actually need?
Work backwards from daily send volume, not from a mailbox count someone quoted you.
- Per-mailbox volume: plan for 25–40 cold sends per day per mailbox once fully ramped. Google's published Workspace limit is far higher (2,000 messages/day for paid accounts, 500 for trial accounts), but that limit is about abuse prevention, not deliverability. Nobody gets burned for hitting Google's ceiling. They get burned for looking like a bulk sender from a brand-new domain.
- Mailboxes per domain: 2–3. Reputation is scored largely at the domain level, so a domain with 10 mailboxes is a single point of failure carrying 10x the load.
- Buffer: add 15–20% capacity over your target, because some mailboxes will underperform, get suspended, or sit in warmup at any given time.
So for 1,000 cold emails per day: 1,000 ÷ 30 ≈ 34 mailboxes, at 3 per domain ≈ 12 domains, plus a couple of spares. For 5,000/day: ~170 mailboxes across ~57 domains. The domain count is the real cost and the real operational burden, not the seats.
One point that trips people up: email aliases do not add capacity. Google gives you up to 30 aliases per user for free, and sequencers will happily let you send from them, but aliases share the underlying user's mailbox, sending limits, and reputation. Only additional users (seats) multiply capacity.
Should I buy direct from Google, through a reseller, or from an infrastructure provider?
Three legitimate routes, plus one you should avoid.
Direct from Google
Maximum control, no intermediary, and you can add secondary domains to a single tenant. The friction is operational: you create the tenant, verify every domain, create every user by hand or via script, set DKIM per domain in the admin console, and manage billing. At 12 domains this is a slow afternoon. At 57 domains it's a job. Month-to-month billing also costs more than an annual commitment, and annual commitments are exactly what you don't want on infrastructure you may rotate.
Through a Google reseller/partner
Consolidated billing and sometimes a discount off list. You still do the domain and DNS work yourself unless the partner specifically offers provisioning. Good fit if you already have a partner relationship. Rarely worth establishing one just for cold email.
Through a cold email infrastructure provider
This is where Inboxlogy fits: authorized Google Workspace (and Microsoft 365) mailboxes provisioned across your domains, with SPF, DKIM and DMARC written automatically, dedicated US or EU IPs, 100% ownership and super admin access handed to you, a full API for programmatic provisioning, from $2.80/mailbox/month with $0 setup and monthly billing. What you're paying for isn't cheaper Gmail. Domain verification, per-domain DKIM, user creation and DNS stop being 60 manual steps per domain. The API matters more than people expect once you're rotating domains quarterly.
What to avoid: grey-market and "aged account" panels
Sellers offering Workspace accounts at implausible prices are typically running accounts inside their tenant, on their domains, often against Google's terms. You get a login, not ownership. When the tenant gets flagged, and these do get flagged, every mailbox dies at once, you can't export, and you have no recourse. The tell is simple: ask whether you will be a super admin on the tenant and whether the domain is registered in your own registrar account. If either answer is no, walk.
What does "authorized" and "owned" actually mean when buying mailboxes?
These words get used loosely. Verify concretely:
- You are super admin on the Workspace tenant. You can log into admin.google.com, create and delete users, reset passwords, and change the billing method.
- The domains are in your registrar account, or transferable to it on request with no lock-in. If the vendor owns your domains, they own your pipeline.
- The seats are licensed through Google (direct or via a genuine reseller agreement), not shared out of a bulk tenant.
- You can leave. Ask what happens on cancellation: do mailboxes transfer to your own Google billing, or do they vanish? Can you export mail?
That last one is the fastest way to separate infrastructure providers from resellers of somebody else's problem.
How should I structure domains and tenants?
Never send cold email from your primary brand domain. A spam-rate spike there affects invoices, support replies, and everything else. Buy alternate domains: plain variants like getcompany.com, company-hq.com, trycompany.com. Keep them plausible. Lookalikes with hyphens and numbers read as phishing to both filters and humans.
Then decide on tenant topology:
- One tenant, many secondary domains. Google supports adding hundreds of domains to a single Workspace account. One admin console, one bill, one DKIM workflow you repeat per domain. Far less overhead. The risk is correlated failure: a tenant-level suspension takes everything with it.
- Multiple tenants. More billing and admin overhead, but blast radius is contained. Sensible once you're past a few hundred mailboxes, or if cold email is your core revenue channel.
A reasonable middle ground at scale: shard into tenants of 40–60 mailboxes each, so no single suspension removes more than a slice of capacity.
Per domain, also: point it at a real (even minimal) website rather than a parked page, add a redirect or short landing page, and give each mailbox a real human name, signature, and profile photo. None of these are magic ranking factors. They are the difference between a recipient who replies and one who reports.
What DNS records does every sending domain need?
All four, on every domain, before a single send:
- MX: Google's MX records, so replies actually arrive.
- SPF: one record, including
include:_spf.google.com. One SPF record per domain, never two, and stay under the 10-lookup limit. - DKIM: generated per domain in the Google admin console (Apps → Google Workspace → Gmail → Authenticate email), 2048-bit, then published and switched on. This is the step most people skip on domains 5 through 50, and unsigned mail is the single most common cause of a "why is everything in spam" ticket.
- DMARC: start at
p=nonewith a reporting address, confirm alignment, then move top=quarantine.
Two extras worth doing. Use a custom tracking domain (a subdomain of the sending domain) rather than your sequencer's shared tracking domain. And leave catch-all off: a catch-all domain accepts mail addressed to anything, which invites backscatter and spam-trap traffic onto a domain you're trying to keep clean.
Inboxlogy automates SPF, DKIM and DMARC at provisioning time, the tedious part. If you're doing it yourself, script it against your registrar's API rather than clicking through 57 DNS panels.
What are Google's bulk sender rules and do they apply to me?
Google's sender guidelines set stricter requirements for senders exceeding 5,000 messages per day to Gmail addresses, measured per sending domain: SPF and DKIM, a DMARC policy, alignment between the From domain and authenticated domain, TLS, one-click list-unsubscribe, and a spam complaint rate kept below 0.3% (Google advises aiming under 0.1%).
Because cold email is spread across many domains at low per-domain volume, most cold senders sit under the 5,000/day bulk threshold on any individual domain. Do not treat that as a loophole. Gmail evaluates reputation regardless of whether you cross the bulk bar, and the 0.3% complaint threshold is a useful ceiling to hold yourself to at any volume. Authenticate everything and include a real unsubscribe mechanism whether or not the rules technically compel you to.
A related note on measurement: Google Postmaster Tools needs meaningful daily volume per domain before it reports anything. At 90 sends/day per domain you will mostly see empty charts. Your real instruments are reply rate, bounce rate, and spam-placement tests, not Postmaster.
How do I connect the mailboxes and warm them up?
Two connection methods:
- OAuth: preferred where your sequencer supports it. Cleaner, no password to rotate, survives password changes.
- SMTP/IMAP with an app password: requires 2-Step Verification enabled on the user first, since app passwords aren't available without it. Enable IMAP in Gmail settings (or org-wide in the admin console) before connecting.
On warmup, be clear on who does what. Inboxlogy does not run warmup. Warmup runs inside the sending tool you connect the mailboxes to. Instantly, Smartlead, ReachInbox and similar platforms all include it. Inboxlogy delivers ready, authenticated, fully owned mailboxes; the warmup pool, ramp schedule and reply simulation happen in your sequencer. Any infrastructure vendor claiming to warm your mailboxes for you is either running a warmup network you didn't ask about or describing something else.
A workable ramp, starting from zero:
- Days 1–14: warmup only, no cold sends. Let the tool's warmup network build inbox placement and engagement history.
- Week 3: 5–10 cold sends/day/mailbox, warmup still running.
- Week 4: 15–20/day.
- Week 5+: 25–40/day, holding warmup on permanently at a reduced level.
Ramp slower if bounce rate exceeds 3% or replies fall off a cliff. The constraint is list quality as much as mailbox age. Verify every address before it enters a sequence, because hard bounces damage domain reputation faster than volume does.
What does buying Google Workspace mailboxes at scale actually cost?
Three line items, and people usually only budget the first:
- Seats. At Google's list price for its entry business plan, 34 seats runs a few hundred dollars a month; month-to-month pricing is higher than an annual commitment. Through Inboxlogy, mailboxes start at $2.80/mailbox/month, $0 setup, billed monthly, so 34 mailboxes is roughly $95/month with no annual lock.
- Domains. 12 domains at typical registrar renewal pricing is a modest but recurring cost, and it scales linearly with volume. At 57 domains it's no longer a rounding error.
- Your sequencer. Most cold email platforms price partly by connected mailbox or by contact volume. At 170 mailboxes this frequently exceeds the mailbox cost itself. Check the pricing tier before you provision.
The hidden cost is labor. Manually standing up 57 domains (registration, DNS, tenant setup, domain verification, DKIM generation, user creation, 2SV, app passwords, sequencer connection) is a multi-day project each time you rotate. That's the specific problem an API-driven provider solves, and it's the right lens for comparing $2.80 against Google's list price.
What should I ask a vendor before I buy?
- Will I be super admin on the Workspace tenant?
- Whose name are the domains registered in, and can I transfer them out?
- Are the licenses authorized through Google, direct or via reseller agreement?
- Do you set SPF, DKIM and DMARC per domain, or is that on me?
- Is there an API for provisioning, or is it a support ticket every time?
- What's the billing term: monthly, or an annual commitment on infrastructure I may rotate?
- What's the replacement policy if a mailbox is suspended, and how fast?
- Do you offer dedicated IPs, and can I choose US or EU (relevant for both latency and data residency)?
- Who runs warmup? The honest answer is your sequencer. If a vendor says otherwise, ask exactly what they mean.
How do I keep mailboxes healthy and replace them over time?
Treat mailboxes as consumable. Domains burn. That's a cost of doing cold outreach rather than proof you did something wrong, though the cause is usually list quality or messaging.
- Watch bounce rate per domain weekly. Above 3–5% sustained, pause that domain and audit the list segment feeding it.
- Watch reply rate as a placement proxy. A domain whose reply rate drops by half while messaging stays constant is landing in spam. Confirm with a seed-list placement test.
- Rotate before failure, not after. Keep 2–3 spare domains warmed and idle so you can swap capacity in the same day.
- Rest burned domains rather than pushing harder. Some recover after 30–60 days of no sending; some don't.
- Consolidate replies into your sequencer's unified inbox or forward to one central mailbox, so nobody is checking 34 Gmail tabs.
Do I need anything besides mailboxes to send legally?
Yes, and scale magnifies the exposure. In the US, CAN-SPAM requires accurate headers, a valid physical postal address, and a working opt-out honored promptly. In the EU and UK, B2B cold email is typically defended under legitimate interest with clear opt-out and disclosure, but rules vary by member state. Canada's CASL is consent-based and materially stricter. None of this is legal advice. But "we bought 170 mailboxes and skipped the unsubscribe link" is a bad position in every jurisdiction, and unsubscribes reduce complaint rates, the metric Gmail is scoring you on.
What are the most common mistakes at scale?
- Sending from the primary brand domain.
- Stacking 10+ mailboxes on one domain to save on registrations.
- Configuring SPF and forgetting per-domain DKIM.
- Using aliases and expecting more capacity.
- Skipping warmup because the mailbox "works fine."
- Jumping to 50/day in week one.
- Using the sequencer's shared tracking domain.
- Buying from a panel where you're not the admin.
- Not verifying lists, then blaming the mailboxes.
- Signing annual commitments on infrastructure with a 6–12 month practical lifespan.
FAQ
How many emails per day can one Google Workspace mailbox send for cold email?
Google's published limit for paid Workspace accounts is 2,000 messages per day, but for cold outreach the practical ceiling is 25–40 per day per mailbox after a 3–4 week ramp. The limit that matters is reputational, not technical.
Is buying Google Workspace mailboxes for cold email against Google's terms?
Buying and operating legitimately licensed Workspace seats is not the problem. Sending unsolicited bulk mail in violation of Google's spam policies is. Use authorized licenses where you hold admin access, authenticate every domain, honor unsubscribes, and keep complaint rates under 0.3%. The accounts that get terminated are almost always grey-market seats or genuine spam operations, not compliant B2B outreach.
Google Workspace or Microsoft 365 for cold email?
Google generally offers simpler provisioning and better tooling integration; Microsoft 365 tends to deliver better to Microsoft-hosted recipients, which is most enterprise inboxes. Running a mix and routing by recipient MX is the advanced play. Inboxlogy provisions both, which makes splitting your fleet a configuration choice rather than a second vendor relationship.
Does Inboxlogy warm up my mailboxes?
No. Inboxlogy provisions authorized, fully owned Google Workspace and Microsoft 365 mailboxes with SPF, DKIM and DMARC configured and dedicated US/EU IPs. Warmup runs in the sending tool you connect them to: Instantly, Smartlead, ReachInbox or similar, with that platform's warmup network and ramp settings.