Do I Own My Cold Email Mailboxes and Domains?

If your domains are registered in your name at a registrar you can log into, and your mailboxes live in a Google Workspace or Microsoft 365 tenant where you hold the super admin / global admin account, then yes, you own them, and your provider is a reseller you can walk away from. If all you received was a spreadsheet of SMTP credentials, with no admin console and no registrar login, you own nothing: you are renting access, and the vendor can revoke it at any time.

Most people asking this question have already paid for mailboxes and are now trying to work out, after the fact, what they actually bought. Ownership is verifiable in about fifteen minutes, without asking the vendor. This article shows you exactly how to check, what the answers mean, and what to do if the answer is bad.

What does "ownership" actually mean for cold email infrastructure?

"Ownership" is not one thing. It is four separate control points, and a vendor can honestly claim you own some while quietly holding others. Each one has a specific test.

If you can answer yes to all four, you own your infrastructure outright and your provider is a billing relationship. If you can only answer yes to some, you have partial ownership, which is usually fine but worth knowing precisely. If you answer no to the domain test, nothing else matters much. Whoever controls the domain controls where the mail goes.

How do I check right now whether I own my domains?

Run these five checks in order. They take about five minutes per domain and you can do all of them without contacting your provider.

One nuance worth knowing: a vendor buying domains inside their own registrar account is not automatically malicious. It is often just operationally easier at volume. The problem is that it is indistinguishable from lock-in until you try to leave. Ask for the domains to be pushed into a registrar account in your name, and treat reluctance as your answer.

How do I check whether I own my Google Workspace or Microsoft 365 mailboxes?

Google Workspace

Sign in at admin.google.com with your own account, not a shared one.

Microsoft 365

Sign in at admin.microsoft.com.

The red flags that mean you don't own anything

The last one deserves emphasis. Cheap mailboxes are sometimes cheap because they are unauthorized. Authorization is a verifiable property of the provider, not a marketing claim. Ask which partner programme they operate under and whether your tenant will show a reseller relationship in the admin console. If it does, that is evidence of a legitimate channel relationship. If your tenant shows no reseller at all yet you are paying a third party, ask where the licences actually come from.

Is a reseller relationship bad?

No, and conflating "reseller" with "doesn't own" is the most common mistake in this space. Both Google and Microsoft run formal channel programmes precisely so that a partner can handle provisioning, billing and support while the customer keeps the tenant. Under those programmes:

What makes a reseller arrangement dangerous is not the model, it is a vendor that layers extra dependencies on top of it: holding your domains, running your DNS, keeping super admin for themselves, or refusing to name the programme they operate under. Those are contractual and operational choices, and you can inspect every one of them before you pay.

Why does ownership actually matter?

Ownership sounds abstract until one of these happens. Each of these is a routine failure mode in cold email operations, not a hypothetical:

What does ownership not protect you from?

This is where most articles on this topic overpromise. Owning your infrastructure is necessary, not sufficient.

What should I ask a provider before I buy?

Paste these into an email. The acceptable answers are listed alongside. A provider who answers all ten cleanly and in writing is selling you infrastructure; one who deflects is selling you access.

What does leaving actually look like?

There are two very different scenarios, and people conflate them constantly.

Scenario A: changing reseller only (hours, no downtime)

Your tenant, domains, mailboxes and DNS all stay exactly where they are. Only the billing and delegated-admin relationship changes: generate a transfer token (Google) or add the new partner and remove the old relationship (Microsoft). Nothing about sending changes. No DNS edits, no password resets, no reconnecting mailboxes in your sending tool, no warmup interruption. This is the entire practical value of owning the tenant: your exit is a billing change, not a migration.

Scenario B: full migration to new domains and mailboxes (weeks)

This is what you are stuck with if you don't own things. You register new domains, stand up a new tenant, configure SPF/DKIM/DMARC from scratch, create mailboxes, connect them to your sending tool, warm them up, and rebuild every sequence, signature and tracking link. Old replies are lost unless you exported them. Budget weeks, not hours, and expect a gap in sending volume.

Whichever scenario applies, one detail catches people out: warmup and sending live in your sequencing tool, Instantly, Smartlead or ReachInbox, not in your infrastructure provider. Those tools connect to each mailbox via OAuth or IMAP/SMTP credentials. In Scenario A nothing changes, because the mailboxes are unchanged. In Scenario B you are reconnecting every mailbox and restarting warmup from zero on brand-new domains with no history.

Where does Inboxlogy fit?

Inboxlogy is a cold email infrastructure provider built specifically around the answer this article argues for: you get 100% ownership and admin access to authorized Google Workspace and Microsoft 365 mailboxes, on dedicated US or EU IPs, with SPF, DKIM and DMARC configured automatically at setup. There is a full API for provisioning and management, pricing starts at $2.80 per mailbox per month with $0 setup, and billing is monthly, so there is no annual lock-in, which is the contractual half of portability.

To be explicit about scope, because it matters when you are comparing providers: Inboxlogy does not run warmup. Warmup happens in whichever sending tool you connect: Instantly, Smartlead or ReachInbox. Inboxlogy provides the mailboxes, domains, DNS authentication and IPs; your sequencer provides warmup and sending.

And the honest framing: everything in the audit above is something you can and should run against Inboxlogy too. If a provider's ownership claims don't survive a look at your own admin console and registrar account, the claims are wrong, including ours.

FAQ

If my provider is a Google Workspace reseller, do I still own my mailboxes?

Yes, provided you hold super admin on the tenant. In the authorized reseller model the tenant and its data belong to the customer; the reseller holds billing and delegated admin access. You can generate a transfer token from your own admin console and move to another reseller or to direct billing with Google without the current reseller's permission.

My vendor registered my cold email domains for me. Are they mine?

Only if they are in a registrar account you can log into. Being described as the "owner" in an invoice or dashboard means nothing operationally, and public WHOIS is usually redacted so it won't confirm it either. Ask for the domains to be pushed to your own registrar account. Note that ICANN's transfer policy can impose a lock of up to 60 days after registration or after a change of registrant, so a short genuine delay is normal. An indefinite one is not.

Can I move my existing cold email mailboxes to a new provider without losing warmup?

If you own the tenant and domains, yes. A reseller or partner change leaves the mailboxes untouched, so warmup in Instantly, Smartlead or ReachInbox continues uninterrupted. If you are being forced onto new domains and a new tenant, warmup starts over; there is no way to transfer reputation to a domain that has no history.

What's the fastest way to tell if I don't own my infrastructure?

Try to do two things right now, without contacting anyone: log into the registrar that holds one of your domains, and open the Google or Microsoft admin console for your tenant. If either fails, you are renting. Fix the domain side first. The domain is the piece that is hardest to recover once a vendor relationship goes bad.