How to Improve Cold Email Deliverability
To improve cold email deliverability, send from separate sending domains with correctly aligned SPF, DKIM, and DMARC, keep each mailbox under roughly 20-40 sends per day, verify your list so bounces stay under 2-3%, turn off open tracking, and keep spam complaints below 0.1%. Deliverability comes down to infrastructure hygiene plus recipient engagement. Mailbox providers decide where you land based on whether real people reply to you, not on which words you avoid in your subject line.
The rest of this guide is the operational detail: the exact DNS records, the volume math, how to tell whether you actually have a problem, and what to do when a domain is already burned.
What actually determines whether a cold email lands in the inbox?
Gmail, Outlook, and the major filters weigh roughly four things, in descending order of importance:
- Recipient engagement. Replies, opens from real humans, "not spam" marks, and messages moved out of spam are the strongest positive signals. Spam complaints, immediate deletes without reading, and silence are the strongest negative ones. That makes targeting a deliverability lever as much as a conversion lever. A relevant email to 100 people outperforms an irrelevant one to 10,000 in both revenue and inbox placement.
- Domain reputation. Built per sending domain over weeks. It follows the domain, not the mailbox, which is why adding mailboxes to a burned domain fixes nothing.
- Authentication. SPF, DKIM, and DMARC alignment. These don't earn you inbox placement. They're the entry ticket. Failing them is disqualifying; passing them is unremarkable.
- Sending pattern and infrastructure. Volume ramp, consistency, IP reputation, and whether your mailboxes were provisioned through legitimate channels.
Subject-line "spam words" sit near the bottom of that list and get far more attention than they deserve. Filters in 2026 are behavioral and reputation-based. The word "free" in a message from a reputable domain to an engaged recipient lands fine.
How do I set up SPF, DKIM, and DMARC correctly?
All three must align with the domain in your From address. Alignment is the part people miss. A technically valid SPF record on a different domain than the one you're sending from still fails DMARC.
SPF
Publish exactly one SPF record per domain. Two records is a permanent failure, not a merge.
- Google Workspace:
v=spf1 include:_spf.google.com ~all - Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all
SPF has a hard limit of 10 DNS lookups (RFC 7208). Every include: counts, and nested includes count too. If you've stacked your CRM, your ESP, and two other tools into one record, you may already be over the limit and silently failing. Check it with any SPF validator that reports lookup count.
DKIM
Use a 2048-bit key and confirm it's actually enabled, not just published. In Google Workspace this lives under Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generating the key and adding the TXT record does nothing until you click "Start authentication." In Microsoft 365 you add the two selector1._domainkey / selector2._domainkey CNAMEs, then enable signing for the domain in the Defender portal.
DMARC
Start at monitoring, then tighten:
v=DMARC1; p=none; rua=mailto:[email protected]; fo=1
Read the aggregate reports for two weeks, confirm every legitimate source passes, then move to p=quarantine and eventually p=reject. Google and Microsoft both require a DMARC policy for bulk senders (the published threshold is 5,000 messages per day to their users). Enforcing p=reject also stops other people spoofing your domain and destroying reputation you built.
The records people forget
- MX records on every sending domain. A domain that can't receive mail looks disposable. It also means you never see the bounces and replies that tell you what's happening.
- A real page at the root domain. A 301 redirect to your main site is acceptable. A parked page or a blank server is not.
- List-Unsubscribe. Even for one-to-one cold outreach where it isn't strictly required, giving recipients a one-click way out beats giving them only the spam button. One complaint costs you far more than one unsubscribe.
If you'd rather not hand-manage DNS across dozens of domains, this is the part worth automating. Inboxlogy configures SPF, DKIM, and DMARC automatically at provisioning, so the records are correct and aligned before the first send rather than after the first deliverability incident.
Should I send cold email from my main domain?
No. Use separate sending domains that are lookalikes or variants of your primary, such as getacme.com, acme-hq.com, or tryacme.io, and keep your real corporate domain out of outbound entirely.
The reason is blast radius. If a cold campaign generates complaints, the reputation damage attaches to the sending domain. If that domain is also the one your sales team, your invoices, your password resets, and your support replies go through, you've taken down the business to run an experiment. Burning a $12 domain is a rounding error. Burning your primary is a quarter-long recovery.
Practical rules:
- Age new domains for 2-4 weeks before sending. Domains registered yesterday are treated with suspicion.
- Avoid TLDs with poor aggregate reputation (
.top,.click,.xyzand similar)..comis the safe default. - Keep 2-3 mailboxes per domain, not ten. Ten mailboxes on one fresh domain is a recognizable pattern.
- Set DMARC on the sending domains too. They're spoofing targets precisely because they're new.
How many emails per day can I send from one mailbox?
For cold outreach, plan on 20-40 sends per mailbox per day at steady state. Google Workspace's technical limit is far higher (2,000/day), but the technical limit is not the safe limit. It's the point at which Google stops you, not the point at which Gmail's filters start doubting you.
Ramp up rather than starting at the ceiling:
- Week 1: warmup only, no cold sends
- Week 2: 5-10 cold sends/day
- Week 3: 15-20/day
- Week 4+: 25-40/day, held steady
Consistency matters more than the absolute number. A mailbox that sends 30 a day, every weekday, looks like a person. One that sends 400 on Monday and nothing until Thursday looks like a tool. Spread sends across business hours in the recipient's timezone with randomized intervals rather than firing a batch at 9:00:00.
The volume math is straightforward. To reach 1,000 prospects per day at 30 sends/mailbox/day, you need roughly 34 mailboxes across 12-17 domains. Build the plan backwards from your target, and buy the infrastructure before you buy the leads. The common failure mode is a 50,000-contact list being force-fed through six mailboxes.
How do I warm up a new mailbox, and does warmup actually work?
Warmup is a mutual-engagement network. Your mailbox exchanges messages with other mailboxes in a pool, and those messages get opened, replied to, and rescued from spam automatically. That establishes a baseline sending history for a brand-new mailbox, which is genuinely useful. An account with zero history that suddenly sends 30 cold emails is a worse bet than one with three weeks of normal-looking traffic.
Be realistic about what it does and doesn't do:
- It does help a fresh mailbox establish history and stay warm during gaps in sending.
- It does not repair a domain damaged by complaints, and it does not compensate for bad targeting. Filters weigh engagement from real recipients on real campaigns far more heavily than pool traffic, and the large providers are well aware that warmup networks exist.
Run warmup continuously at a low level, 10-20 warmup messages/day, alongside live campaigns rather than only during onboarding.
One point worth being precise about: warmup runs in your sending tool, not in your infrastructure provider. Inboxlogy provisions the mailboxes. Warmup is enabled inside Instantly, Smartlead, or ReachInbox once you connect them. Any provider claiming their infrastructure "warms itself" is describing something else.
Why do cheap mailboxes get suspended, and what should I look for in a provider?
A large share of budget cold-email mailboxes are provisioned through unauthorized reseller channels or bulk-created accounts that violate the platform's terms. They work until an enforcement sweep hits, and then entire fleets go dark at once, usually mid-campaign, usually with the customer having no admin access, no data export, and no recourse because the account was never theirs.
The questions that separate real infrastructure from resold risk:
- Is the provider an authorized reseller? Authorized Google Workspace and Microsoft 365 partner status means the accounts exist through a sanctioned channel and won't vanish in a compliance action.
- Do you own the accounts? You should hold super-admin on the Workspace or 365 tenant and be able to change DNS, export mail, add users, and leave the provider taking everything with you.
- Can you leave? If migrating away means losing your mailboxes, you're renting reputation you can't move.
- Whose IPs are you on? Dedicated IPs isolate you from whatever the noisiest tenant on a shared pool is doing. EU-based IPs also matter if you're sending to European recipients, for both placement and data-residency reasons.
This is the specific gap Inboxlogy fills: authorized Google Workspace and Microsoft 365 mailboxes with 100% ownership and full admin access, dedicated US or EU IPs, automated authentication, and an API for provisioning at scale, from $2.80 per mailbox/month, $0 setup, billed monthly. The pricing matters less than the ownership. At scale, the difference between $2.80 and $4 a mailbox is noise compared to losing a 40-mailbox fleet to a suspension you can't appeal.
How do I clean a list so it doesn't burn my domain?
Bounce rate is the fastest way to destroy a new domain, and it's entirely preventable. Target under 2-3% hard bounces. Above 5% you should stop sending and fix the list before anything else.
- Verify every list before import, even from a reputable data vendor, and re-verify anything older than 60-90 days. B2B contact data decays at roughly 2-3% per month through job changes alone.
- Handle catch-all domains separately. Verification tools can't validate addresses on catch-all servers, because those servers accept everything. Segment catch-alls into their own campaign at lower volume rather than mixing them into your main sends, so if they bounce, they don't take a clean campaign down with them.
- Drop role addresses:
info@,sales@,support@,admin@,contact@. They complain at higher rates and convert at lower ones. Never send toabuse@orpostmaster@. Those are complaint desks. - Don't send to scraped or purchased lists. Beyond the legal exposure, they're the primary vector for spam traps, addresses that never opted into anything and exist specifically to identify senders who didn't collect their data legitimately. Recycled traps (abandoned real addresses) cost you reputation. Pristine traps (never-used addresses published only to catch scrapers) can get you listed at Spamhaus.
- Suppress aggressively. Unsubscribes, hard bounces, and past complainers go on a global suppression list across every domain and tool you run, permanently.
What should the email itself look like?
Cold email should be indistinguishable in structure from a normal person's email, because that's what filters are comparing it against.
- Plain text, or near-plain HTML. No templates, no header images, no brand banners, no footers full of social icons. A colleague emailing you doesn't send a newsletter.
- Turn off open tracking. This is the highest-value change most senders haven't made. Open pixels are a known filter signal, and since Apple's Mail Privacy Protection pre-fetches images, the data they produce is largely fiction anyway. You're paying a real deliverability cost for a metric that isn't true.
- Be careful with link tracking. If you must track clicks, use a custom tracking domain that matches your sending domain. Never a shared redirect domain used by thousands of other senders, and never a link shortener like bit.ly.
- One link maximum, ideally zero in the first message. No attachments in cold outreach, ever.
- Short. 50-125 words. Length correlates with reply rate in the wrong direction, and reply rate is a deliverability input.
- Vary the copy. Identical bodies sent from 30 mailboxes to 10,000 recipients is a fingerprint. Use spintax or genuine personalization tokens so messages aren't byte-identical.
- Include a plain-language opt-out and a physical postal address. CAN-SPAM requires the address and honoring opt-outs within 10 business days. If you're emailing EU or UK recipients, you also need a lawful basis under GDPR and PECR. For B2B that's typically legitimate interest, which requires the contact to be genuinely relevant to their role and documented as such.
How do I measure deliverability instead of guessing?
Most senders discover a deliverability problem three weeks after it started, from a drop in meetings booked. Instrument it directly:
- Google Postmaster Tools is the only first-party data you get. Verify each sending domain and watch spam rate, domain reputation, and authentication pass rates. One caveat: it needs meaningful daily volume to Gmail before it populates, so at cold-email volumes you may see sparse data. Aggregate across your domains where you can.
- Spam complaint rate below 0.1%. Google's stated ceiling for bulk senders is 0.3%, and hitting it is already a crisis. At 0.1% you have room.
- Reply rate is your best real proxy. It's the one metric that can't be faked by a pixel. A campaign whose reply rate halves week over week without a copy or list change has a placement problem, not a messaging problem.
- Bounce rate, monitored daily, with an automatic pause rule above 5%.
- Blocklists: check Spamhaus (SBL, CSS, DBL) for your domains and IPs. Treat Spamhaus listings as urgent. Treat UCEPROTECT and similar aggressive lists as noise, since almost nobody filters on them.
- Seed/placement tests are directional only. A seed inbox has no engagement history with you, which is the single biggest factor in real placement. Use them to catch catastrophic failures, not to measure a few percentage points.
What do I do if deliverability has already crashed?
In order, and don't skip to step 4:
- 1. Stop sending on the affected domain. Not reduce. Stop. Continuing to send while diagnosing deepens the damage every hour.
- 2. Find the cause. Check Postmaster spam rate, recent bounce rate, whether a new list segment was added, whether authentication broke (an expired DKIM key or a second SPF record added by another team is a common culprit), and whether you're blocklisted.
- 3. Fix the actual cause. Purge the bad segment, repair DNS, request delisting where you're listed.
- 4. Rest the domain 2-4 weeks with warmup running but no cold sends.
- 5. Restart at 20% of previous volume with your best-performing, highest-relevance segment, and rebuild from there.
Two honest caveats. A domain burned badly enough may never fully recover, and the correct call is to retire it. And rotating to fresh domains without changing the behavior that burned the last ones just produces a longer list of burned domains. The infrastructure was rarely the root cause.
Frequently asked questions
How long does it take to improve cold email deliverability?
Authentication fixes (SPF, DKIM, DMARC) take effect within 24-48 hours of DNS propagation. Reputation changes take longer: expect 2-4 weeks to see meaningful movement in Postmaster Tools after correcting volume and list problems, and 4-8 weeks to fully rehabilitate a domain that was damaged rather than merely new.
Does a dedicated IP improve cold email deliverability?
It isolates you, which matters, because on a shared pool another tenant's complaints affect your placement. But an IP only builds reputation with consistent volume, and at cold-email volumes your domain reputation carries far more weight than your IP reputation. Treat dedicated IPs as risk reduction, not as a fix for placement problems caused by targeting or list quality.
Is Google Workspace or Microsoft 365 better for cold email?
Both perform well when properly configured. In practice, many senders run a mix: Google Workspace mailboxes tend to reach Gmail recipients slightly more reliably and Microsoft 365 mailboxes tend to reach Outlook/Microsoft-hosted recipients more reliably, so splitting your fleet across both and segmenting by recipient MX is a reasonable optimization. The provisioning channel matters more than the platform. An unauthorized Google mailbox is worse than an authorized Microsoft one, and vice versa.
Do I need an unsubscribe link in a cold email?
Legally it depends on jurisdiction, but operationally you should include one regardless. The alternative to an easy opt-out isn't silence. It's the spam button, and a spam complaint damages your domain reputation in a way an unsubscribe never does. A single line of plain text ("Reply 'no' and I won't follow up") plus a List-Unsubscribe header is enough.