Cold Email Deliverability Best Practices: The 2025 Rules, Updated for 2026
Cold email deliverability comes down to four things: authenticate every sending domain with aligned SPF, DKIM, and DMARC; send from mailboxes you genuinely own on authorized Google Workspace or Microsoft 365 tenants; keep per-mailbox volume low (roughly 20-40 emails per day) against a verified list; and keep your spam complaint rate in Google Postmaster Tools below 0.1%. Copy tweaks, send-time optimization, and spam-word checkers are a rounding error next to those four.
The rules tightened sharply between February 2024 and May 2025. Google and Yahoo introduced enforced bulk sender requirements, and Microsoft followed with its own for consumer Outlook domains. Both now reject or junk mail that fails basic authentication, no matter how good the copy is. The practices below reflect what is actually enforced today, with the specific checks you can run yourself.
What are the most important cold email deliverability best practices?
If you only do ten things, do these:
- Publish SPF, DKIM, and DMARC on every sending domain, and verify that at least one of SPF or DKIM aligns with your visible From domain.
- Send from a separate domain from your main company domain, so a reputation problem never touches your corporate email.
- Use real, authorized mailboxes on Google Workspace or Microsoft 365 tenants you own and have admin access to, not resold seats on someone else's tenant.
- Cap each mailbox at 20-40 cold emails per day and scale by adding mailboxes, not by raising per-mailbox volume.
- Warm each mailbox for 2-4 weeks before it sends campaign traffic.
- Verify every address before sending and keep your bounce rate under about 2%.
- Keep spam complaints below 0.1% (Google's hard line is 0.3%; above 0.1% you're already in trouble).
- Send plain-text-style email. No images, no HTML templates, at most one link.
- Turn off open tracking, or at minimum use a custom tracking subdomain. Open pixels are a filtering signal, and Apple's Mail Privacy Protection has made the data worthless anyway.
- Monitor Postmaster Tools, bounce codes, and reply rates weekly, and react to drops within days rather than weeks.
What do Google, Yahoo, and Microsoft actually require now?
These are published requirements, not folklore.
Google and Yahoo (enforced since February 2024)
- SPF and DKIM on all mail. DKIM signing is no longer optional.
- A DMARC record on the sending domain, with at least
p=none. - Alignment: the domain in SPF or DKIM must match the domain in the visible From header.
- Valid forward and reverse DNS on sending IPs (PTR record resolving back to the sending host).
- Spam rates below 0.3% as reported in Google Postmaster Tools, with 0.1% as the practical target.
- One-click unsubscribe (RFC 8058) for senders of 5,000 or more messages per day to Gmail.
Microsoft (enforced since May 2025)
Microsoft applied comparable requirements to high-volume senders to consumer Outlook, Hotmail, and Live addresses: SPF, DKIM, DMARC at minimum p=none, valid reverse DNS, and a functional unsubscribe mechanism. Non-compliant mail was first routed to Junk, with outright rejection as the stated endpoint. Microsoft 365 business tenants are filtered separately and more aggressively by Exchange Online Protection, which weights sender reputation and recipient engagement heavily.
The threshold nuance that matters for cold email: most cold email operations never hit 5,000 messages per day to a single provider from one domain, so the bulk-sender unsubscribe mandate often doesn't technically apply. Comply anyway. A plain-text opt-out line costs nothing and suppresses complaints, and complaints are the metric that actually kills you.
How do I set up SPF, DKIM, and DMARC correctly for cold email?
Authentication is where most "my emails go to spam" problems are born. It's also the only part of deliverability that is fully deterministic: either it passes or it doesn't.
SPF
Publish exactly one SPF record per domain. Two records is a permanent failure, not a merge. Stay within the 10 DNS lookup limit. Each include: counts, and nested includes count too. Exceeding it produces permerror, which many receivers treat as a fail.
Use -all (hard fail) if you're confident you've enumerated every sender, or ~all (soft fail) while you're still auditing. Never use the ptr mechanism. Check it with:
dig +short TXT yourdomain.com, and confirm one record, startingv=spf1.
DKIM
Use 2048-bit keys where your provider supports them. In Google Workspace, DKIM is not on by default for a new domain. You have to generate the key in the Admin console and publish it, then click Start authentication. In Microsoft 365, enable DKIM signing per custom domain and publish both CNAME selectors. Verify with:
dig +short TXT selector1._domainkey.yourdomain.com(Microsoft) ordig +short TXT google._domainkey.yourdomain.com(Google).
DMARC
Start at v=DMARC1; p=none; rua=mailto:[email protected] so you receive aggregate reports. Read them for two weeks, then move to p=quarantine and eventually p=reject once you've confirmed every legitimate sender passes. A permanent p=none satisfies the letter of the requirements but gives you no spoofing protection and no BIMI eligibility.
The alignment trap that catches cold email specifically
DMARC requires SPF or DKIM to align with your From domain. Many sending tools and relays rewrite the envelope sender (Return-Path) to their own domain for bounce handling. When that happens, SPF still passes, but it passes for their domain, so SPF alignment fails and your DMARC result rests entirely on DKIM. If DKIM is misconfigured, DMARC fails even though every individual check looks green in a basic DNS checker.
How to verify properly: send a message to a Gmail address you control, open it, choose Show original, and read the Authentication-Results header. You want spf=pass, dkim=pass, and critically dmarc=pass, with the header.from and header.d values both your domain. If you see dkim=none, nothing is signing your mail.
Inboxlogy provisions SPF, DKIM, and DMARC automatically when mailboxes are created, which removes the most common failure mode: mailboxes going live with DKIM unsigned. Verify the headers yourself regardless of who sets it up. A two-minute check prevents a two-month reputation problem.
Should I send cold email from my main domain or a separate domain?
Use a separate domain. Always. Cold email generates complaints by definition. A fraction of recipients will mark unsolicited mail as spam no matter how relevant it is. You do not want that reputation attached to the domain your invoices, support replies, and password resets flow through.
The standard approach:
- Register one or more lookalike domains of your primary domain:
get-acme.com,acmehq.com,tryacme.io. Keep them plausible and readable. A recipient who searches the domain should find something coherent. - Put a real website on each one, even a one-page redirect to your main site with correct meta tags. Domains with no web presence look disposable.
- Age them before sending. Registration age is a signal. A domain registered yesterday that starts sending today is the single clearest spam pattern there is. Two to four weeks minimum.
- Run 2-5 mailboxes per domain, not twenty. Concentrating volume on one domain concentrates risk.
- Keep DMARC at
p=rejecton your primary domain even though you don't send cold mail from it. That's what stops anyone spoofing your real brand.
Subdomains (mail.acme.com) are a reasonable middle ground for transactional and marketing mail, but for cold outreach they're risky: subdomain reputation is not fully isolated from the root domain at every receiver.
How many cold emails per day can I send per mailbox?
20-40 per day per mailbox is the working range for cold outreach from a Google Workspace or Microsoft 365 mailbox. This is well below what the providers technically allow, and that gap is intentional.
The provider limits are much higher. Google Workspace permits roughly 2,000 messages per day per user on most paid tiers (500 on Business Starter), and Exchange Online enforces a recipient rate limit in the thousands per day plus a per-minute message rate cap. Those are abuse ceilings, not deliverability guidance. Hitting them with cold traffic gets you rate-limited and then filtered long before you get suspended.
The math you should actually do runs the other direction. Decide your daily send volume, then divide:
- 500 emails/day at 30 per mailbox → 17 mailboxes
- 1,000 emails/day at 30 per mailbox → 34 mailboxes
- 3,000 emails/day at 30 per mailbox → 100 mailboxes
Spread those mailboxes across multiple domains, and add random delays between sends rather than firing a sequence in one burst. This is why cost per mailbox drives cold email economics. At Inboxlogy's $2.80/mailbox/month, a 34-mailbox setup for 1,000 sends per day runs under $100/month with no setup fee, which is what makes the "many mailboxes, low volume each" architecture practical instead of theoretical.
How do I warm up new mailboxes properly?
Warmup means gradually building a positive sending history on a new mailbox and domain before exposing it to cold traffic. Mailbox providers evaluate new senders cautiously. A mailbox with three weeks of normal-looking, replied-to conversation behind it is treated very differently from one whose first action is 200 outbound messages.
A workable ramp:
- Week 1: 5-10 emails/day, warmup traffic only.
- Week 2: 10-20/day.
- Week 3: 20-30/day, begin mixing in a small amount of real campaign volume.
- Week 4 onward: steady state at 20-40/day, with warmup continuing in the background at reduced volume.
An important structural point: warmup runs inside your sending tool, not in your infrastructure. Inboxlogy does not run warmup. You connect your Inboxlogy mailboxes to Instantly, Smartlead, or ReachInbox, and that tool's warmup network handles the ramp. This is the normal division of labor across the industry: infrastructure provisions and hosts the mailboxes, and the sequencer handles warmup, sending logic, and reply detection. Be skeptical of any provider claiming to do both in one layer, and check that your mailboxes are actually enrolled in your sequencer's warmup pool before you launch a campaign. "I thought warmup was on" is a common and entirely avoidable cause of a dead domain.
Don't stop warmup after the ramp. Keep it running at low volume permanently. It maintains a baseline of positive engagement that cushions the complaint signal from cold traffic.
What kind of mailboxes should I buy, and why do cheap ones get suspended?
This is the part of deliverability that most guides skip, and it causes more catastrophic failures than any copy or DNS issue.
A large share of cheap cold email mailboxes are resold seats on someone else's Google Workspace or Microsoft 365 tenant, sold in bulk outside the providers' reseller programs. The problems are structural:
- You don't have admin access. You can't rotate DKIM keys, change DNS, enable OAuth, export data, or audit what else is happening on the tenant.
- You share fate with every other tenant occupant. If another buyer on the same tenant gets reported for abuse, the whole tenant can be suspended, including your mailboxes, mid-campaign.
- Unauthorized resale violates the providers' terms, so suspensions arrive without warning, without appeal, and with no data export.
- You cannot migrate. When the mailboxes die, the conversation history and reply threads die with them.
What to require instead:
- Authorized provisioning through legitimate Google Workspace and Microsoft 365 channels.
- 100% ownership and full admin access to the tenant and the domain. You should be able to log into the admin console yourself.
- Automated but inspectable authentication: SPF, DKIM, and DMARC set up for you, with DNS you can read and change.
- API access for provisioning and rotating mailboxes at scale without ticket queues.
- Monthly terms, so a provider has to keep earning the business.
Inboxlogy was built around exactly this specification: authorized Google Workspace and Microsoft 365 mailboxes, dedicated US and EU IPs, automated SPF/DKIM/DMARC, 100% ownership with admin access, a full API, from $2.80/mailbox/month with $0 setup and monthly billing. The ownership point is the one worth fixating on regardless of vendor. If you don't control the tenant, you don't control your deliverability.
One technical note on authentication to your mailboxes: Microsoft has been retiring basic authentication for SMTP client submission in Exchange Online, and Google requires 2-step verification plus app passwords or OAuth. Confirm your sequencer connects over OAuth 2.0 rather than a stored password. Connections that break on an auth deprecation deadline look, from the outside, exactly like a deliverability collapse.
How do I keep my list clean enough to stay out of spam?
Bounces and complaints are the two signals receivers weight most heavily, and both are list problems rather than sending problems.
- Verify every address before sending. Target a bounce rate under 2%; above roughly 5% you should expect active filtering.
- Handle catch-all domains deliberately. Verifiers can't confirm individual addresses on catch-all domains, so they come back "unknown" or "risky." Either exclude them or segment them into separate low-volume campaigns on separate mailboxes so the uncertainty is contained.
- Strip role accounts:
info@,support@,sales@,admin@,abuse@. They convert poorly and are disproportionately monitored or trapped. - Suppress hard bounces globally and permanently, across every campaign and every tool. Re-sending to a known-bad address is one of the strongest negative signals available.
- Never buy scraped lists. Aged scraped data is where spam traps live, and a single pristine trap hit can land your domain on Spamhaus DBL.
- Re-verify anything older than 60-90 days. B2B data decays continuously through job changes.
- Honor opt-outs instantly and globally. Someone who asked once and gets contacted again is the most likely person in your list to hit the spam button.
How should I write cold emails so filters don't flag them?
Content filtering is less about forbidden words than about resembling bulk mail. "Spam word checkers" are largely obsolete. Modern filters evaluate structure and engagement, not a blocklist of phrases.
- Send plain text, or HTML that looks like plain text. No templates, no header images, no logos, no signature graphics. Real person-to-person email doesn't have a hero image.
- One link maximum, and ideally zero in the first message. Multiple links in a first-contact email is a bulk-mail pattern.
- Avoid URL shorteners entirely. Bit.ly-class domains carry pooled reputation from everyone else using them.
- Use a custom tracking domain or no tracking at all. A shared tracking domain means you inherit the reputation of every other sender on it. Since Apple Mail Privacy Protection pre-fetches images and inflates open rates into noise, dropping open tracking altogether costs you little and removes a filtering signal.
- Keep it short, roughly 50-125 words for a first touch. Short is both better-converting and less bulk-like.
- Test merge fields with deliberately broken data. "Hi {{first_name}}," or "Hi ," reaching a prospect is worse than no email, and empty-field errors are the most common cause of complaint spikes. Always set fallbacks.
- Don't lean on spintax to fake variety. Mechanical synonym swapping produces awkward sentences while leaving the structure identical. It fools nothing and reads badly.
- Include a plain-text opt-out: "If this isn't relevant, just reply 'no' and I won't follow up." It reduces complaints, which is the metric you're actually protecting.
- Optimize for replies, not opens. Replies are the strongest positive engagement signal a receiver can observe, and the only metric that is both deliverability-relevant and still measurable.
How do I know if my emails are actually landing in the inbox?
Use provider-reported data first, seed tests second, and never trust a single source.
- Google Postmaster Tools: the only authoritative view of your Gmail spam rate, domain reputation, and authentication pass rates. Add every sending domain on day one. It needs volume to populate, so set it up before you need it.
- Microsoft SNDS and JMRP: IP-level data and complaint feedback for mail to consumer Outlook, available if you control the sending IPs.
- Your own reply and bounce data. A reply rate that drops by half with no change to copy or targeting is a deliverability event, not a messaging event. This is usually the earliest signal you'll get.
- Bounce codes, read literally.
550 5.7.1means you're being blocked outright.421 4.7.28from Google means rate-limited for unusual traffic. Any bounce text mentioning "unsolicited mail" is a reputation warning, not a transient error. - Blocklist checks on your domains and IPs: Spamhaus SBL/CSS for IPs and DBL for domains, plus Barracuda. Check weekly, not after a crisis.
- Seed tests (placement tests) are directionally useful but systematically optimistic. Seed inboxes have no engagement history, and Gmail in particular treats an unengaged seed account differently from a real prospect. Use them to catch total failures, not to measure placement precisely.
What should I do when deliverability suddenly drops?
Work in this order, and resist the urge to rewrite your copy first. Copy is almost never the cause of a sudden drop.
- Pause the affected mailboxes immediately. Continuing to send into a filtering event deepens the reputation damage.
- Check authentication. Send yourself a test and read the headers. Expired DKIM keys, a DNS change that broke SPF, or a provider migration are the most common culprits.
- Check blocklists for your domains and IPs.
- Check Postmaster Tools for a spam-rate spike and correlate it to a specific campaign or send date.
- Audit the last list you loaded. A single unverified or purchased segment explains most sudden complaint spikes.
- Verify warmup is still running in your sequencer and that the mailboxes are still enrolled.
- Then recover slowly. Resume at 25% of previous volume on your highest-quality segment and ramp over two to three weeks. Returning to full volume immediately re-triggers the filter.
If a domain's reputation is genuinely burned, meaning sustained "Bad" in Postmaster Tools or persistent 550 blocks, retire it. Domain reputation recovery is slow and unreliable. Replacing the domain is faster and cheaper than rehabilitating it, which is another argument for keeping cold outreach off anything you care about.
What has changed since 2025, and what should you prepare for?
The direction of travel has been consistent and shows no sign of reversing:
- Authentication is now table stakes, not an advantage. SPF, DKIM, and DMARC get you to the filter. They don't get you through it. Differentiation is entirely in engagement.
- DMARC enforcement is becoming the norm.
p=nonesatisfies the minimum, but the ecosystem is trending toward quarantine and reject, and BIMI requires enforcement. Move your primary domain top=reject. - Engagement weighting keeps increasing. Receivers are leaning harder on whether recipients open, reply, and don't complain. This structurally penalizes high-volume, low-relevance sending, and the only durable defense is tighter targeting and fewer, better emails.
- Basic auth is disappearing. Microsoft has been retiring basic authentication for SMTP client submission in Exchange Online. Confirm every integration uses OAuth 2.0 and check your provider's current deadlines rather than assuming your existing connection survives.
- Mailbox provisioning is being scrutinized more closely. Enforcement against unauthorized bulk resale of Workspace and Microsoft 365 seats has tightened, and suspension waves hit grey-market providers hardest. Owned, authorized infrastructure is now a risk control, not a nice-to-have.
The practices that worked in 2025 still work. What's changed is that the margin for sloppiness has shrunk: the same misconfiguration that cost you 10% of placement two years ago now costs you the domain.
FAQ
Can I send cold email from my Google Workspace account on my main domain?
Technically yes; practically, don't. Complaints from cold outreach attach to your domain's reputation, and that's the same reputation your invoices, contracts, and password resets depend on. Use a separate lookalike domain with its own mailboxes, and keep your primary domain on p=reject for spoofing protection.
Does Inboxlogy handle email warmup?
No. Inboxlogy provisions and hosts authorized Google Workspace and Microsoft 365 mailboxes with SPF, DKIM, and DMARC configured, dedicated US/EU IPs, and full ownership plus admin access. Warmup runs in your connected sending tool: Instantly, Smartlead, or ReachInbox. Connect your mailboxes there and enable that tool's warmup before launching any campaign.
How long before a new domain and mailbox can send real campaigns?
Plan on three to four weeks total. Let the domain age at least two weeks after registration, with a live website on it, and run mailbox warmup for two to four weeks, beginning to mix in real campaign volume around week three. Compressing this is the single most common cause of a domain dying in its first month.
Is cold email legal if I follow deliverability best practices?
Deliverability and legality are separate questions. In the US, CAN-SPAM permits unsolicited commercial email but requires accurate headers, a valid physical address, and a working opt-out that you honor. In the EU and UK, GDPR and PECR mean B2B cold email generally relies on legitimate interest and demands relevance, clear identification, and easy objection. In Canada, CASL requires consent or a documented implied-consent basis, and penalties are substantial. Get jurisdiction-specific advice for your markets. Passing SPF has no bearing on whether a send is lawful.