Dedicated IP vs Shared IP for Cold Email: Which One Actually Helps
For most cold email programs, a dedicated sending IP is not what gets you into the inbox. Domain reputation, authentication, and list quality are. A dedicated IP matters in two specific situations: when you send high, steady volume through your own relay, and when your mailbox connection IP is shared with hundreds of unrelated senders, which is what actually gets Google Workspace and Microsoft 365 accounts flagged and suspended.
"Dedicated IP vs shared IP" is two different questions wearing the same name, and the right answer depends on which one you're asking.
What is the difference between a dedicated IP and a shared IP?
A shared IP is an IP address that many senders transmit from. Your reputation on that IP is an average of everyone using it, including people you've never met and can't control.
A dedicated IP is assigned to you alone. Every reputation signal recorded against it, whether complaint rate, spam trap hits, bounce rate, or blocklist entries, is caused by you. That cuts both ways: no one else can damage it, and no one else can absorb your mistakes.
The usual framing stops there, which is why most advice on this topic is useless for cold email. The missing piece is which IP you're actually talking about.
Does the IP even matter if I send from Google Workspace or Microsoft 365?
The honest answer depends on who controls the outbound hop, and it usually isn't you.
If you send cold email through real Google Workspace or Microsoft 365 mailboxes, which is what most serious cold outreach runs on today, you do not control the IP that delivers your mail. Google hands your message to the recipient from Google's own outbound ranges. Microsoft does the same from Exchange Online's ranges. Those are shared IPs, shared with millions of legitimate businesses, and no vendor can sell you a dedicated one for that hop. If someone tells you they'll give you a dedicated delivery IP on a standard Google Workspace mailbox, they're describing something else.
The dedicated IP in that setup is the connection and egress IP: the address your sending tool (Instantly, Smartlead, ReachInbox) logs in from when it authenticates to the mailbox and hands over messages. That IP matters a great deal, just not for the reason people assume:
- It affects account survival, not inbox placement. Google and Microsoft both watch where an account signs in from. A mailbox provisioned for a US company that suddenly authenticates from a rotating pool of addresses in three countries looks like a compromised account, not a sales team.
- Shared connection pools create guilt by association. If four hundred unrelated cold email accounts authenticate through the same handful of IPs and a chunk of them get reported, that IP becomes a signal the provider recognizes. Your accounts get caught in the same net.
- Geographic consistency is a real signal. A US-registered tenant should be connecting from a US IP, an EU tenant from an EU IP. Stable and matched beats fast and rotating.
This is the practical case for dedicated IPs in modern cold email, and it's why Inboxlogy assigns dedicated US or EU IPs to its authorized Google Workspace and Microsoft 365 mailboxes. You aren't buying better deliverability from Google's filters. You're buying an account neighborhood you control, so your mailboxes don't get suspended for someone else's behavior.
When is a dedicated sending IP genuinely the right choice?
If you send through your own SMTP relay or an ESP rather than mailbox providers, a dedicated delivery IP is worth it when all of these are true:
- Your volume is high and steady. Reputation systems need a meaningful, continuous signal. Providers that sell dedicated IPs publish a minimum sustained volume for exactly this reason, so check your provider's published number before you buy. Sporadic sending means the IP looks unfamiliar every time you use it.
- Your list quality is already good. A dedicated IP with a 1% complaint rate is a liability. The same list on a shared pool gets partially diluted by everyone else's good behavior.
- You need to isolate streams. Separating transactional mail from outbound prospecting so a cold campaign can never affect password resets and invoices is a legitimate, high-value use of a dedicated IP.
- You need diagnosability. With a dedicated IP, the IP reputation view in Google Postmaster Tools reflects only you. On shared infrastructure that data is noise.
Cold email rarely satisfies the first condition. A fleet of 30 mailboxes sending 25 messages a day each is roughly 20,000 messages a month spread across dozens of sender identities, well below the volume floor at which a dedicated delivery IP starts earning its keep.
When is a shared IP the better choice?
- Low or uneven volume. A well-managed shared pool carries established history. A cold dedicated IP carries none, and "unknown" is treated closer to "suspicious" than to "trusted."
- You're still testing offers and lists. Early campaigns are where complaint rates are highest. Doing that on your own IP writes those mistakes into a record with your name on it.
- You don't have someone watching deliverability weekly. A dedicated IP is an asset that needs maintenance: blocklist monitoring, complaint-rate tracking, volume pacing. Unmaintained, it's worse than a shared pool.
- You're on Google Workspace or Microsoft 365 anyway, where the delivery IP isn't yours to choose. Put that budget into domains, mailbox count, and list quality instead.
What actually determines whether cold email lands in the inbox?
Ranked roughly by how much leverage you have over each:
- Domain reputation. Your DKIM-signing domain is the durable identity that follows you across IPs and providers. It's the asset that matters most, and the one that cannot be reset by buying a new IP.
- Authentication that aligns. SPF, DKIM, and DMARC must all pass, and the DMARC-aligned domain should match your visible From domain. Google's published bulk-sender rules require SPF, DKIM, DMARC, and easy unsubscribe for senders above 5,000 messages a day to Gmail addresses. Microsoft introduced comparable requirements for high-volume senders to Outlook.com, Hotmail, and Live in 2025. Meet the bar whether or not you're over the threshold.
- Complaint rate. Google names 0.3% as the ceiling in Postmaster Tools and advises staying under 0.1%. Hold yourself to the lower number.
- List quality. Bounces and spam traps do more damage per message than almost anything else. Verify before sending, and never buy a list you can't trace to a source.
- Engagement. Replies and opens from real humans are the signal filters weight most heavily for a new sender. Relevance beats volume.
- Content and link domains. A pristine sending domain linking to a burned tracking or redirect domain inherits the problem.
- Volume ramp. New domains and mailboxes need weeks of gradual increase, not a day-one blast.
The IP, dedicated or shared, sits below every item on that list.
How do I check an IP's reputation before I send from it?
Do this before you commit, and repeat it monthly:
- Query the major blocklists. Look the IP up on Spamhaus (SBL, CSS, PBL), Barracuda, and SURBL. A multi-list check like MXToolbox covers most in one pass.
- Check Sender Score or Talos reputation for a historical view rather than a point-in-time yes/no.
- Verify reverse DNS. The IP should have a PTR record resolving to a hostname you control, and that hostname should resolve back to the IP. Missing or generic rDNS is a common, quiet cause of rejections.
- Ask the provider a direct question: how many accounts share this IP? If they won't answer, that's your answer. Ask whether the IP is dedicated to you or to a pool, and whether it rotates.
- Confirm the geography matches your tenant. A US entity connecting from EU addresses (or vice versa) is an avoidable flag.
- Run a seed test to Gmail, Outlook, and a corporate Microsoft 365 tenant before real volume, then read the full headers to confirm SPF, DKIM, and DMARC all pass and align.
How do I warm a dedicated IP without burning it?
Warming is a volume curve plus a quality constraint. Start low, increase gradually over several weeks, and send your best traffic first, meaning your most engaged and most relevant recipients, so the earliest signals recorded against the IP are positive ones. Increase only while complaint and bounce rates stay flat. If either moves, hold volume until it recovers rather than pushing through.
One honest note on tooling: Inboxlogy does not run warmup. Warmup runs inside your connected sending tool, whether Instantly, Smartlead, or ReachInbox, and that's where you configure the ramp. Inboxlogy provisions the mailboxes, dedicated IPs, and authentication. Your sending tool drives the sending behavior. Any provider claiming to handle both ends of that is worth a second look.
Will a dedicated IP fix a domain that's already burned?
No. Reputation for cold email is anchored to the domain, and moving a bad-reputation domain to a clean IP transfers the problem rather than solving it. Worse, you've now taught the filters to associate that clean IP with a known-bad domain.
The real fix is unglamorous: pause the burned domain, diagnose why complaints or bounces spiked, fix the list and the message, and rebuild on fresh domains with a slow ramp. If you must rotate domains, rotate them for capacity, not as a way to escape consequences, which filters detect and penalize.
What do people get wrong when they buy a dedicated IP?
- Buying one to solve a list problem. Isolation makes bad list quality more damaging, not less.
- Assuming "dedicated IP" means dedicated delivery IP. On Google Workspace and Microsoft 365 it almost always means the connection IP. Ask the vendor to state precisely which hop it covers.
- Not owning the accounts. A dedicated IP on mailboxes you can't administer, export, or audit isn't an asset you control. Insist on full admin access and real ownership of the tenant and domains. That's the difference between infrastructure you own and infrastructure you rent from someone who can turn it off.
- Letting it go idle. An IP with no recent sending history behaves like a new one. Warming isn't a one-time event.
- Skipping monitoring. Set up Google Postmaster Tools for every sending domain, watch the spam rate weekly, and check blocklists monthly. Without this, a dedicated IP is a liability you can't see.
What does a solid cold email setup look like end to end?
- Separate sending domains from your primary brand domain, each with correct DNS.
- Authorized Google Workspace or Microsoft 365 mailboxes: real mailboxes on real tenants, not SMTP accounts dressed up as mailboxes.
- SPF, DKIM, and DMARC configured and aligned from day one, verified in received headers.
- Dedicated IPs for mailbox connections, geographically matched to the tenant (US or EU).
- Full admin access to every tenant and domain, so you can read logs, enforce policy, and leave without negotiating for your own access.
- A verified, sourced list and a message specific enough to earn replies.
- Warmup and sending pace configured in your sending tool, ramping over weeks.
- Weekly Postmaster Tools review and monthly blocklist checks.
Inboxlogy covers the infrastructure half of that list: authorized Google Workspace and Microsoft 365 mailboxes with dedicated US or EU IPs, automated SPF/DKIM/DMARC, 100% ownership and admin access, and a full API for provisioning at scale, from $2.80 per mailbox per month with no setup fee on a monthly plan. The sending half (list, message, warmup, pacing) stays yours, in your sending tool, where it belongs.
Frequently asked questions
Is a dedicated IP worth it if I send 30 emails per mailbox per day?
Not for delivery-IP purposes. That volume is far too low to build meaningful IP reputation. It is worth it for the connection IP, so your mailboxes aren't authenticating through a pool shared with hundreds of unrelated senders. Spend the rest of your budget on list verification and more sending domains.
Can I get a dedicated delivery IP with Google Workspace?
Not on standard mailbox sending. Google delivers from its own outbound ranges regardless of your plan. What you can control is the IP your sending tool connects from, plus your domain reputation and authentication, which is where the leverage actually is.
How long does it take to warm a dedicated IP?
Plan on several weeks of gradual ramp, and expect that timeline to stretch if complaint or bounce rates rise. There's no fixed number. The curve is governed by your metrics staying clean, not by a calendar. Configure the ramp in your sending tool.
Does a dedicated IP protect me from being blocklisted?
It protects you from other people getting you blocklisted. It offers no protection from your own sending, and removes the dilution a shared pool would have provided. A dedicated IP concentrates responsibility; it doesn't reduce risk.