Cold Email Deliverability Best Practices: The 2025 Rules, Updated for 2026

Cold email deliverability comes down to four things: authenticate every sending domain with aligned SPF, DKIM, and DMARC; send from mailboxes you genuinely own on authorized Google Workspace or Microsoft 365 tenants; keep per-mailbox volume low (roughly 20-40 emails per day) against a verified list; and keep your spam complaint rate in Google Postmaster Tools below 0.1%. Copy tweaks, send-time optimization, and spam-word checkers are a rounding error next to those four.

The rules tightened sharply between February 2024 and May 2025. Google and Yahoo introduced enforced bulk sender requirements, and Microsoft followed with its own for consumer Outlook domains. Both now reject or junk mail that fails basic authentication, no matter how good the copy is. The practices below reflect what is actually enforced today, with the specific checks you can run yourself.

What are the most important cold email deliverability best practices?

If you only do ten things, do these:

What do Google, Yahoo, and Microsoft actually require now?

These are published requirements, not folklore.

Google and Yahoo (enforced since February 2024)

Microsoft (enforced since May 2025)

Microsoft applied comparable requirements to high-volume senders to consumer Outlook, Hotmail, and Live addresses: SPF, DKIM, DMARC at minimum p=none, valid reverse DNS, and a functional unsubscribe mechanism. Non-compliant mail was first routed to Junk, with outright rejection as the stated endpoint. Microsoft 365 business tenants are filtered separately and more aggressively by Exchange Online Protection, which weights sender reputation and recipient engagement heavily.

The threshold nuance that matters for cold email: most cold email operations never hit 5,000 messages per day to a single provider from one domain, so the bulk-sender unsubscribe mandate often doesn't technically apply. Comply anyway. A plain-text opt-out line costs nothing and suppresses complaints, and complaints are the metric that actually kills you.

How do I set up SPF, DKIM, and DMARC correctly for cold email?

Authentication is where most "my emails go to spam" problems are born. It's also the only part of deliverability that is fully deterministic: either it passes or it doesn't.

SPF

Publish exactly one SPF record per domain. Two records is a permanent failure, not a merge. Stay within the 10 DNS lookup limit. Each include: counts, and nested includes count too. Exceeding it produces permerror, which many receivers treat as a fail.

Use -all (hard fail) if you're confident you've enumerated every sender, or ~all (soft fail) while you're still auditing. Never use the ptr mechanism. Check it with:

DKIM

Use 2048-bit keys where your provider supports them. In Google Workspace, DKIM is not on by default for a new domain. You have to generate the key in the Admin console and publish it, then click Start authentication. In Microsoft 365, enable DKIM signing per custom domain and publish both CNAME selectors. Verify with:

DMARC

Start at v=DMARC1; p=none; rua=mailto:[email protected] so you receive aggregate reports. Read them for two weeks, then move to p=quarantine and eventually p=reject once you've confirmed every legitimate sender passes. A permanent p=none satisfies the letter of the requirements but gives you no spoofing protection and no BIMI eligibility.

The alignment trap that catches cold email specifically

DMARC requires SPF or DKIM to align with your From domain. Many sending tools and relays rewrite the envelope sender (Return-Path) to their own domain for bounce handling. When that happens, SPF still passes, but it passes for their domain, so SPF alignment fails and your DMARC result rests entirely on DKIM. If DKIM is misconfigured, DMARC fails even though every individual check looks green in a basic DNS checker.

How to verify properly: send a message to a Gmail address you control, open it, choose Show original, and read the Authentication-Results header. You want spf=pass, dkim=pass, and critically dmarc=pass, with the header.from and header.d values both your domain. If you see dkim=none, nothing is signing your mail.

Inboxlogy provisions SPF, DKIM, and DMARC automatically when mailboxes are created, which removes the most common failure mode: mailboxes going live with DKIM unsigned. Verify the headers yourself regardless of who sets it up. A two-minute check prevents a two-month reputation problem.

Should I send cold email from my main domain or a separate domain?

Use a separate domain. Always. Cold email generates complaints by definition. A fraction of recipients will mark unsolicited mail as spam no matter how relevant it is. You do not want that reputation attached to the domain your invoices, support replies, and password resets flow through.

The standard approach:

Subdomains (mail.acme.com) are a reasonable middle ground for transactional and marketing mail, but for cold outreach they're risky: subdomain reputation is not fully isolated from the root domain at every receiver.

How many cold emails per day can I send per mailbox?

20-40 per day per mailbox is the working range for cold outreach from a Google Workspace or Microsoft 365 mailbox. This is well below what the providers technically allow, and that gap is intentional.

The provider limits are much higher. Google Workspace permits roughly 2,000 messages per day per user on most paid tiers (500 on Business Starter), and Exchange Online enforces a recipient rate limit in the thousands per day plus a per-minute message rate cap. Those are abuse ceilings, not deliverability guidance. Hitting them with cold traffic gets you rate-limited and then filtered long before you get suspended.

The math you should actually do runs the other direction. Decide your daily send volume, then divide:

Spread those mailboxes across multiple domains, and add random delays between sends rather than firing a sequence in one burst. This is why cost per mailbox drives cold email economics. At Inboxlogy's $2.80/mailbox/month, a 34-mailbox setup for 1,000 sends per day runs under $100/month with no setup fee, which is what makes the "many mailboxes, low volume each" architecture practical instead of theoretical.

How do I warm up new mailboxes properly?

Warmup means gradually building a positive sending history on a new mailbox and domain before exposing it to cold traffic. Mailbox providers evaluate new senders cautiously. A mailbox with three weeks of normal-looking, replied-to conversation behind it is treated very differently from one whose first action is 200 outbound messages.

A workable ramp:

An important structural point: warmup runs inside your sending tool, not in your infrastructure. Inboxlogy does not run warmup. You connect your Inboxlogy mailboxes to Instantly, Smartlead, or ReachInbox, and that tool's warmup network handles the ramp. This is the normal division of labor across the industry: infrastructure provisions and hosts the mailboxes, and the sequencer handles warmup, sending logic, and reply detection. Be skeptical of any provider claiming to do both in one layer, and check that your mailboxes are actually enrolled in your sequencer's warmup pool before you launch a campaign. "I thought warmup was on" is a common and entirely avoidable cause of a dead domain.

Don't stop warmup after the ramp. Keep it running at low volume permanently. It maintains a baseline of positive engagement that cushions the complaint signal from cold traffic.

What kind of mailboxes should I buy, and why do cheap ones get suspended?

This is the part of deliverability that most guides skip, and it causes more catastrophic failures than any copy or DNS issue.

A large share of cheap cold email mailboxes are resold seats on someone else's Google Workspace or Microsoft 365 tenant, sold in bulk outside the providers' reseller programs. The problems are structural:

What to require instead:

Inboxlogy was built around exactly this specification: authorized Google Workspace and Microsoft 365 mailboxes, dedicated US and EU IPs, automated SPF/DKIM/DMARC, 100% ownership with admin access, a full API, from $2.80/mailbox/month with $0 setup and monthly billing. The ownership point is the one worth fixating on regardless of vendor. If you don't control the tenant, you don't control your deliverability.

One technical note on authentication to your mailboxes: Microsoft has been retiring basic authentication for SMTP client submission in Exchange Online, and Google requires 2-step verification plus app passwords or OAuth. Confirm your sequencer connects over OAuth 2.0 rather than a stored password. Connections that break on an auth deprecation deadline look, from the outside, exactly like a deliverability collapse.

How do I keep my list clean enough to stay out of spam?

Bounces and complaints are the two signals receivers weight most heavily, and both are list problems rather than sending problems.

How should I write cold emails so filters don't flag them?

Content filtering is less about forbidden words than about resembling bulk mail. "Spam word checkers" are largely obsolete. Modern filters evaluate structure and engagement, not a blocklist of phrases.

How do I know if my emails are actually landing in the inbox?

Use provider-reported data first, seed tests second, and never trust a single source.

What should I do when deliverability suddenly drops?

Work in this order, and resist the urge to rewrite your copy first. Copy is almost never the cause of a sudden drop.

If a domain's reputation is genuinely burned, meaning sustained "Bad" in Postmaster Tools or persistent 550 blocks, retire it. Domain reputation recovery is slow and unreliable. Replacing the domain is faster and cheaper than rehabilitating it, which is another argument for keeping cold outreach off anything you care about.

What has changed since 2025, and what should you prepare for?

The direction of travel has been consistent and shows no sign of reversing:

The practices that worked in 2025 still work. What's changed is that the margin for sloppiness has shrunk: the same misconfiguration that cost you 10% of placement two years ago now costs you the domain.

FAQ

Can I send cold email from my Google Workspace account on my main domain?

Technically yes; practically, don't. Complaints from cold outreach attach to your domain's reputation, and that's the same reputation your invoices, contracts, and password resets depend on. Use a separate lookalike domain with its own mailboxes, and keep your primary domain on p=reject for spoofing protection.

Does Inboxlogy handle email warmup?

No. Inboxlogy provisions and hosts authorized Google Workspace and Microsoft 365 mailboxes with SPF, DKIM, and DMARC configured, dedicated US/EU IPs, and full ownership plus admin access. Warmup runs in your connected sending tool: Instantly, Smartlead, or ReachInbox. Connect your mailboxes there and enable that tool's warmup before launching any campaign.

How long before a new domain and mailbox can send real campaigns?

Plan on three to four weeks total. Let the domain age at least two weeks after registration, with a live website on it, and run mailbox warmup for two to four weeks, beginning to mix in real campaign volume around week three. Compressing this is the single most common cause of a domain dying in its first month.

Is cold email legal if I follow deliverability best practices?

Deliverability and legality are separate questions. In the US, CAN-SPAM permits unsolicited commercial email but requires accurate headers, a valid physical address, and a working opt-out that you honor. In the EU and UK, GDPR and PECR mean B2B cold email generally relies on legitimate interest and demands relevance, clear identification, and easy objection. In Canada, CASL requires consent or a documented implied-consent basis, and penalties are substantial. Get jurisdiction-specific advice for your markets. Passing SPF has no bearing on whether a send is lawful.