How to Improve Cold Email Deliverability

To improve cold email deliverability, send from separate sending domains with correctly aligned SPF, DKIM, and DMARC, keep each mailbox under roughly 20-40 sends per day, verify your list so bounces stay under 2-3%, turn off open tracking, and keep spam complaints below 0.1%. Deliverability comes down to infrastructure hygiene plus recipient engagement. Mailbox providers decide where you land based on whether real people reply to you, not on which words you avoid in your subject line.

The rest of this guide is the operational detail: the exact DNS records, the volume math, how to tell whether you actually have a problem, and what to do when a domain is already burned.

What actually determines whether a cold email lands in the inbox?

Gmail, Outlook, and the major filters weigh roughly four things, in descending order of importance:

Subject-line "spam words" sit near the bottom of that list and get far more attention than they deserve. Filters in 2026 are behavioral and reputation-based. The word "free" in a message from a reputable domain to an engaged recipient lands fine.

How do I set up SPF, DKIM, and DMARC correctly?

All three must align with the domain in your From address. Alignment is the part people miss. A technically valid SPF record on a different domain than the one you're sending from still fails DMARC.

SPF

Publish exactly one SPF record per domain. Two records is a permanent failure, not a merge.

SPF has a hard limit of 10 DNS lookups (RFC 7208). Every include: counts, and nested includes count too. If you've stacked your CRM, your ESP, and two other tools into one record, you may already be over the limit and silently failing. Check it with any SPF validator that reports lookup count.

DKIM

Use a 2048-bit key and confirm it's actually enabled, not just published. In Google Workspace this lives under Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generating the key and adding the TXT record does nothing until you click "Start authentication." In Microsoft 365 you add the two selector1._domainkey / selector2._domainkey CNAMEs, then enable signing for the domain in the Defender portal.

DMARC

Start at monitoring, then tighten:

Read the aggregate reports for two weeks, confirm every legitimate source passes, then move to p=quarantine and eventually p=reject. Google and Microsoft both require a DMARC policy for bulk senders (the published threshold is 5,000 messages per day to their users). Enforcing p=reject also stops other people spoofing your domain and destroying reputation you built.

The records people forget

If you'd rather not hand-manage DNS across dozens of domains, this is the part worth automating. Inboxlogy configures SPF, DKIM, and DMARC automatically at provisioning, so the records are correct and aligned before the first send rather than after the first deliverability incident.

Should I send cold email from my main domain?

No. Use separate sending domains that are lookalikes or variants of your primary, such as getacme.com, acme-hq.com, or tryacme.io, and keep your real corporate domain out of outbound entirely.

The reason is blast radius. If a cold campaign generates complaints, the reputation damage attaches to the sending domain. If that domain is also the one your sales team, your invoices, your password resets, and your support replies go through, you've taken down the business to run an experiment. Burning a $12 domain is a rounding error. Burning your primary is a quarter-long recovery.

Practical rules:

How many emails per day can I send from one mailbox?

For cold outreach, plan on 20-40 sends per mailbox per day at steady state. Google Workspace's technical limit is far higher (2,000/day), but the technical limit is not the safe limit. It's the point at which Google stops you, not the point at which Gmail's filters start doubting you.

Ramp up rather than starting at the ceiling:

Consistency matters more than the absolute number. A mailbox that sends 30 a day, every weekday, looks like a person. One that sends 400 on Monday and nothing until Thursday looks like a tool. Spread sends across business hours in the recipient's timezone with randomized intervals rather than firing a batch at 9:00:00.

The volume math is straightforward. To reach 1,000 prospects per day at 30 sends/mailbox/day, you need roughly 34 mailboxes across 12-17 domains. Build the plan backwards from your target, and buy the infrastructure before you buy the leads. The common failure mode is a 50,000-contact list being force-fed through six mailboxes.

How do I warm up a new mailbox, and does warmup actually work?

Warmup is a mutual-engagement network. Your mailbox exchanges messages with other mailboxes in a pool, and those messages get opened, replied to, and rescued from spam automatically. That establishes a baseline sending history for a brand-new mailbox, which is genuinely useful. An account with zero history that suddenly sends 30 cold emails is a worse bet than one with three weeks of normal-looking traffic.

Be realistic about what it does and doesn't do:

Run warmup continuously at a low level, 10-20 warmup messages/day, alongside live campaigns rather than only during onboarding.

One point worth being precise about: warmup runs in your sending tool, not in your infrastructure provider. Inboxlogy provisions the mailboxes. Warmup is enabled inside Instantly, Smartlead, or ReachInbox once you connect them. Any provider claiming their infrastructure "warms itself" is describing something else.

Why do cheap mailboxes get suspended, and what should I look for in a provider?

A large share of budget cold-email mailboxes are provisioned through unauthorized reseller channels or bulk-created accounts that violate the platform's terms. They work until an enforcement sweep hits, and then entire fleets go dark at once, usually mid-campaign, usually with the customer having no admin access, no data export, and no recourse because the account was never theirs.

The questions that separate real infrastructure from resold risk:

This is the specific gap Inboxlogy fills: authorized Google Workspace and Microsoft 365 mailboxes with 100% ownership and full admin access, dedicated US or EU IPs, automated authentication, and an API for provisioning at scale, from $2.80 per mailbox/month, $0 setup, billed monthly. The pricing matters less than the ownership. At scale, the difference between $2.80 and $4 a mailbox is noise compared to losing a 40-mailbox fleet to a suspension you can't appeal.

How do I clean a list so it doesn't burn my domain?

Bounce rate is the fastest way to destroy a new domain, and it's entirely preventable. Target under 2-3% hard bounces. Above 5% you should stop sending and fix the list before anything else.

What should the email itself look like?

Cold email should be indistinguishable in structure from a normal person's email, because that's what filters are comparing it against.

How do I measure deliverability instead of guessing?

Most senders discover a deliverability problem three weeks after it started, from a drop in meetings booked. Instrument it directly:

What do I do if deliverability has already crashed?

In order, and don't skip to step 4:

Two honest caveats. A domain burned badly enough may never fully recover, and the correct call is to retire it. And rotating to fresh domains without changing the behavior that burned the last ones just produces a longer list of burned domains. The infrastructure was rarely the root cause.

Frequently asked questions

How long does it take to improve cold email deliverability?

Authentication fixes (SPF, DKIM, DMARC) take effect within 24-48 hours of DNS propagation. Reputation changes take longer: expect 2-4 weeks to see meaningful movement in Postmaster Tools after correcting volume and list problems, and 4-8 weeks to fully rehabilitate a domain that was damaged rather than merely new.

Does a dedicated IP improve cold email deliverability?

It isolates you, which matters, because on a shared pool another tenant's complaints affect your placement. But an IP only builds reputation with consistent volume, and at cold-email volumes your domain reputation carries far more weight than your IP reputation. Treat dedicated IPs as risk reduction, not as a fix for placement problems caused by targeting or list quality.

Is Google Workspace or Microsoft 365 better for cold email?

Both perform well when properly configured. In practice, many senders run a mix: Google Workspace mailboxes tend to reach Gmail recipients slightly more reliably and Microsoft 365 mailboxes tend to reach Outlook/Microsoft-hosted recipients more reliably, so splitting your fleet across both and segmenting by recipient MX is a reasonable optimization. The provisioning channel matters more than the platform. An unauthorized Google mailbox is worse than an authorized Microsoft one, and vice versa.

Do I need an unsubscribe link in a cold email?

Legally it depends on jurisdiction, but operationally you should include one regardless. The alternative to an easy opt-out isn't silence. It's the spam button, and a spam complaint damages your domain reputation in a way an unsubscribe never does. A single line of plain text ("Reply 'no' and I won't follow up") plus a List-Unsubscribe header is enough.