Cold Email Deliverability: A Technical Guide to Reaching the Primary Inbox
Cold email deliverability is the share of your cold emails that land in the recipient's primary inbox instead of bouncing or being filtered to spam. Four levers control it, in order of impact: correctly authenticated infrastructure you actually own (SPF, DKIM and DMARC aligned on dedicated sending domains), low volume per mailbox (roughly 20-50 sends/day), verified lists that keep bounces under 2%, and content that earns replies rather than complaints.
Almost every "deliverability problem" is one of those four. The rest of this guide covers how to get each one right, how to tell which one is broken, and how to measure any of it without fooling yourself.
What is cold email deliverability, and how is it different from delivery rate?
Two different numbers get conflated constantly:
- Delivery rate is the percentage of messages the receiving server accepted. It counts anything that didn't hard bounce, including everything routed straight to the spam folder. Your sending tool reports this and it is almost always 97%+, which is why it is nearly useless.
- Inbox placement (true deliverability) is the percentage that reached the primary inbox. No sending tool can measure this reliably, because receiving mailbox providers do not tell senders where a message landed.
A campaign can show 99% "delivered" and 0% placement. If you are seeing normal delivery rates and near-zero replies, assume a placement problem until you have evidence otherwise.
Reasonable operating targets to hold your own setup to (these are thresholds to manage against, not published industry averages):
- Hard bounce rate under 2% per campaign; investigate at 3%, stop at 5%
- Spam complaint rate under 0.10%. Google's published enforcement threshold is 0.30%, and you do not want to operate anywhere near it
- Reply rate that is stable week over week. A sudden 60% drop with unchanged copy and lists is a deliverability event, not a messaging problem
Why do cold emails land in spam?
In roughly descending order of how often it is the actual cause:
- Authentication is missing, misaligned, or broken. No DKIM signature, SPF that fails because of a 10-lookup overflow, or a DMARC record with no aligned pass. This is binary and instantly disqualifying for high-volume senders at both Google and Microsoft.
- Volume per mailbox is too high, too fast. A one-week-old mailbox sending 150/day with no reply history is the clearest bot signature there is.
- Dirty lists. Invalid addresses, scraped role accounts (info@, sales@), and spam traps. High bounce rates are a direct reputation hit.
- Complaints and deletes-without-reading. Irrelevant targeting generates negative engagement, which is the signal filters weigh most heavily once authentication passes.
- Bad link and tracking hygiene. Shared tracking domains, URL shorteners, redirect chains, and tracking pixels on cold mail.
- Infrastructure you don't control. Mailboxes created through unauthorized resellers, bulk-provisioned on shared tenants, or sitting on IP space with unknown neighbours. You inherit their reputation and their suspension risk.
- Content and formatting. Real, but far less important than the folklore suggests. "Spam words" are a minor factor compared to all of the above.
Note the ordering. Most people rewrite subject lines when the actual problem is a DKIM record or a mailbox sending triple the volume it should.
What DNS records do you need, and how do you set them up correctly?
You need SPF, DKIM, and DMARC on every sending domain, all passing with alignment, plus a custom tracking domain if you track clicks at all. Since Google and Yahoo's 2024 bulk sender requirements and Microsoft's equivalent rollout for Outlook.com in May 2025, senders above 5,000 messages/day to those providers must have all three, and non-compliant mail is routed to junk or rejected outright. Treat it as the floor regardless of your volume.
SPF
A single TXT record at the sending domain's root authorizing your provider's sending infrastructure. The two failure modes:
- More than one SPF record on a domain. This is a permanent error. Receivers do not merge them. Merge the mechanisms into one record instead.
- Exceeding 10 DNS lookups. Each
include:costs lookups, and nested includes count too. Stacking Google, a CRM, a marketing tool, and a helpdesk will blow the limit, and the result ispermerror, a silent SPF failure. Check the lookup count, don't assume.
Use -all (hard fail) on dedicated cold-sending domains where you know every legitimate source. Use ~all on your main corporate domain where shadow senders are likely.
DKIM
A public key published at a selector subdomain, with the provider holding the private key and signing outbound mail. Use a 2048-bit key. 1024-bit is still accepted but is the weaker option and there is no reason to choose it. Verify the signature is actually present by inspecting a received message's headers, not by trusting a dashboard: look for dkim=pass in the Authentication-Results header of a test email sent to a Gmail account.
DMARC
A TXT record at _dmarc.yourdomain.com. DMARC's real function is alignment: it requires that the domain in the visible From: header matches the domain that passed SPF or DKIM. This is what actually stops someone else from sending as you.
- Start at
p=nonewith arua=reporting address so you can see what's being sent as your domain. - Move dedicated cold-sending domains to
p=reject. They have exactly one legitimate sending source, so there is nothing to break. - Be far more careful moving your primary brand domain to reject. Audit the aggregate reports first; invoices, calendar invites, and forgotten SaaS tools get caught here.
Tracking domain
If you use open or click tracking, it must run through a CNAME on your own subdomain (e.g. link.yoursendingdomain.com). A shared tracking domain means your links resolve to a hostname that thousands of other senders, including bad ones, also use. That hostname carries reputation, and you do not control it.
Better: turn open tracking off entirely for cold email. The pixel adds a remote image load to an otherwise plain message, and since Apple Mail Privacy Protection the data it returns is noise. Keep click tracking only if you genuinely act on it.
Doing this by hand across dozens of mailboxes is where errors creep in. Inboxlogy provisions SPF, DKIM, and DMARC automatically per domain, which removes the most common single point of failure. The records are on your DNS, under your control, so verify them yourself after setup. Any provider's automation deserves one manual spot check.
How many cold emails can you send per mailbox per day?
20-50 per mailbox per day for established mailboxes, and under 20 for anything less than a month old. Scale by adding mailboxes, never by raising per-mailbox volume.
The published platform caps are not relevant guidance. Google Workspace permits on the order of 2,000 messages/day per user, and Exchange Online's recipient rate limits are in the thousands (Microsoft has been tightening external-recipient limits downward; check current documentation for your tenant). Those are abuse ceilings, designed to stop account takeover from spewing millions of messages. They describe what will get your account locked, not what will land in an inbox. Cold outreach at 500/day/mailbox will be filtered long before it is rate-limited.
Sensible arithmetic: if you need 1,000 sends/day, that's roughly 25-35 mailboxes at 30/day, spread across several sending domains with two or three mailboxes per domain. At typical infrastructure pricing, Inboxlogy starts at $2.80/mailbox/month, so the cost of over-provisioning mailboxes is trivially small compared to the cost of burning a domain.
Other rate discipline that matters:
- Randomize intervals. Sends spaced at an exact 120 seconds are machine-obvious. Most tools support a jittered delay; use it.
- Respect business hours in the recipient's timezone. Beyond reply rates, 3am bursts are an anomaly signal.
- Rotate mailboxes within a campaign so no single mailbox absorbs a whole sequence.
How do you warm up a new mailbox and domain?
Ramp volume gradually over 2-4 weeks while generating genuine positive engagement, then hold steady. A workable schedule: 5-10 sends/day in week one, 15-20 in week two, 25-35 in week three, and 30-50 from week four if bounces and replies look healthy. Never jump. A mailbox going from 10 to 100 overnight is the pattern filters are built to catch.
An important clarification, because vendors frequently blur this: warmup runs in your sending tool, not in your infrastructure provider. Instantly, Smartlead, and ReachInbox each include warmup networks; you connect your mailboxes and configure the ramp there. Inboxlogy provides and authenticates the mailboxes. It does not run warmup itself. If a provider claims to do both, ask precisely what their warmup mechanism is.
Two honest caveats about automated warmup networks:
- They simulate engagement between participating mailboxes. That builds a baseline, but it is not equivalent to real recipients replying, and mailbox providers have strong incentives to recognize reciprocal-reply patterns.
- Warmup cannot fix bad targeting. If your real campaigns generate complaints, no amount of warmup volume offsets them. Treat warmup as a ramp, not a repair tool.
The highest-value warmup activity is unglamorous: send your first 100-200 messages to a hand-picked, genuinely relevant list with a message likely to earn a reply. Real replies from real humans are the strongest positive signal available to you.
Google Workspace, Microsoft 365, or an SMTP panel: what should you send from?
Use real Google Workspace or Microsoft 365 mailboxes for cold outreach. SMTP relay panels and bulk-sending platforms are cheaper per message and measurably worse at primary-inbox placement, because receiving filters weight the sending platform's reputation heavily and those platforms carry a heavy concentration of low-quality mail.
How to choose between the two:
- Match your prospects' mail provider where you can. Provider-to-provider routing is not symmetric. Microsoft's filtering is generally the harder of the two to get through from outside. If your list is enterprise-heavy (mostly Exchange Online MX records), having a share of your mailboxes on Microsoft 365 is worth testing.
- Split across both rather than concentrating everything on one. It diversifies risk and lets you compare placement by provider.
- Segment campaign reporting by recipient MX provider. This single change explains more "mysterious" reply rate differences than anything else you can do with analytics.
One note on IPs: when you send through Google Workspace or Microsoft 365, the outbound IP belongs to that provider, so classic IP reputation management does not apply the way it does to self-hosted SMTP or an ESP relay. Where dedicated IP space does matter is the infrastructure around your mailboxes and your choice of region. Inboxlogy runs dedicated US and EU IPs, which also matters if you have EU data residency obligations.
Why does mailbox ownership matter for deliverability?
Because mailboxes provisioned through unauthorized resellers can be suspended en masse, and if you don't hold admin access you cannot audit, fix, or migrate anything. This is the risk most buyers discover only after it fires.
Concretely, ask any mailbox vendor these questions and insist on specific answers:
- Are you an authorized Google Workspace and Microsoft partner/reseller? Bulk-created accounts outside authorized channels get terminated in batches, and your mailboxes disappear with the reseller's account, not because of anything you did.
- Do I own the Workspace/365 tenant, with super-admin access? Without admin console access you cannot inspect DKIM, change SPF, read audit logs, set retention, or export mail.
- Who controls the DNS for my sending domains? If it's not you, you cannot verify your own authentication.
- Can I migrate away and keep the mailboxes? If leaving means losing your domains and inbox history, you don't have infrastructure, you have a rental with no exit.
- Is there an API? At 30+ mailboxes, provisioning and DNS by hand is how misconfigurations happen.
This is the specific gap Inboxlogy is built around: authorized Google Workspace and Microsoft 365 mailboxes with 100% ownership and admin access, your DNS, a full API, no setup fee, and month-to-month billing. The useful part of that list is not the price. It's that nothing about your sending capability is hostage to a vendor relationship.
How should you structure your sending domains?
Never send cold email from your primary brand domain. Use dedicated sending domains, 2-3 mailboxes each, and keep them structurally separate from the domain your customers, invoices, and signups depend on.
A workable structure:
- Buy close variants of your brand:
get[brand].com,try[brand].com,[brand]hq.com. Stick to.comand.co; novelty TLDs carry worse baseline reputation. - Let new domains age before sending. A few weeks of existence with DNS configured is cheap insurance; a domain registered yesterday is a flag.
- 301 redirect each sending domain to your real site and put a basic page or redirect in place. Recipients and filters both check whether the domain resolves to something real.
- 2-3 mailboxes per domain, maximum. Domain-level reputation is shared across its mailboxes, so concentration multiplies blast radius.
- Isolate by campaign risk. Keep your most experimental segments on their own domains so a bad list can't contaminate a proven one.
- Keep spare, warmed capacity. Domains do get damaged. Recovery is slow and uncertain; replacement is fast. Having 20% idle warmed capacity turns an outage into a non-event.
What actually makes cold email content get filtered?
Structure and engagement, far more than vocabulary. The "spam word list" advice is largely obsolete. Modern filters are classifiers trained on recipient behaviour, not keyword matchers. What still matters:
- Send plain text or minimal HTML. No templates, no header images, no multi-column layouts, no brand banners. A cold email should look like something a person typed.
- One link, at most. Zero in the first message is better. Never use
bit.ly-style shorteners or redirect chains. Both are heavily abused and treated accordingly. - No attachments. Ever, on cold mail.
- Keep it short. Under 125 words. This helps replies and reduces the surface area for anything to look templated.
- Don't fake personalization.
{{first_name}}plus a merged company name is pattern-detectable and reads as bulk to recipients, which produces exactly the negative engagement you're trying to avoid. One specific, genuinely researched sentence beats five merge fields. - Use spintax sparingly. Heavy spintax to evade similarity detection tends to degrade your copy faster than it helps your placement.
- Give people a way out. A plain one-line opt-out ("Reply 'no' and I won't follow up") costs you nothing and converts would-be complaints into harmless replies. For any bulk sending, implement the
List-Unsubscribeheader with one-click support (RFC 8058); it's required for high-volume senders at Google, Yahoo, and Microsoft. - Watch your follow-up count. Long sequences to unresponsive recipients are a complaint factory. Three to four touches, then stop.
How do you keep your list clean enough?
Verify every address before sending and keep hard bounces under 2%. List quality is the one lever that is fully within your control and the one most often skipped.
- Run every list through a verification service immediately before the campaign, not months earlier. B2B addresses decay continuously as people change jobs.
- Handle catch-all domains deliberately. Verifiers can't confirm them, so they accept everything and tell you nothing. Either exclude them or cap them at a small share of each send and watch the results.
- Drop role accounts:
info@,support@,admin@,sales@. They don't convert and they are disproportionately likely to be monitored or trapped. - Never email scraped lists you didn't build or buy from a verifiable source. Purchased lists are the most reliable way to hit spam traps, and a trap hit damages domain reputation in a way that is hard to undo.
- Maintain a global suppression list across every tool and mailbox: opt-outs, bounces, complaints, existing customers, open deals. Emailing someone who already opted out is both a complaint risk and, in several jurisdictions, a legal one.
How do you measure cold email deliverability properly?
Use seed testing plus reply rate as your core metrics, and ignore open rates entirely. Open tracking is unreliable post-MPP and the pixel itself is a small liability on cold mail.
What to actually monitor:
- Seed accounts you control. Keep real Gmail, Outlook.com, and (ideally) a corporate Google Workspace and a corporate Microsoft 365 mailbox outside your tenant. Enroll them in live campaigns at intervals and check manually: primary, promotions, or spam. This is the only direct read on placement you can get.
- Reply rate per mailbox and per domain, tracked over time. Your own trend line is the signal. A mailbox whose reply rate collapses while its siblings hold steady has a mailbox-level problem; all of them dropping at once points at the domain or the list.
- Bounce rate per campaign, and read the actual bounce text.
550 5.7.1, Microsoft5.7.509, or Google421-4.7.0throttling messages name the problem directly: authentication failure, policy rejection, rate limiting. - Google Postmaster Tools, with the honest caveat that it needs meaningful daily volume to a domain before it reports spam rate data, so low-volume cold senders often see little. Set it up anyway; it's free and it's the only first-party reputation data Google offers.
- A one-time check with a message-inspection tool (mail-tester and similar) per new domain, to catch authentication and formatting errors. Useful for setup validation, not for ongoing placement measurement. The score is not inbox placement.
Microsoft's SNDS and JMRP are IP-based and therefore not usable when you send via Microsoft 365, since the egress IPs aren't yours. Don't waste time there.
How do you diagnose a sudden deliverability drop?
Work from the mechanical causes outward (authentication, then volume, then list, then content) and change one variable at a time.
- Stop sending on the affected domain. Continuing while you diagnose deepens the damage.
- Send a test to a seed Gmail account and read the raw headers. Confirm
spf=pass,dkim=pass,dmarc=pass. A DNS change, an expired record, or a registrar migration breaks this more often than people expect. - Check for SPF overflow. If a teammate added an
include:for a new tool, you may be over 10 lookups and failing silently. - Audit volume and ramp. Look for any mailbox that spiked. Check whether a new campaign launched on mailboxes that weren't warmed.
- Audit the list that was running when it broke. Pull the bounce rate for that specific campaign. A single unverified or purchased segment is the most common trigger.
- Check your links. A newly added domain, a shortener, or a shared tracking domain introduced in the same window.
- Then look at copy. Last, not first.
If the domain is genuinely damaged, be realistic: recovery means weeks at drastically reduced volume with high-engagement sends, and it does not always work. This is why spare warmed domains are worth their trivial cost. Replacement is a reliable fix, rehabilitation isn't.
What are the legal rules for cold email?
Not legal advice, but the rules you need to know before you send:
- United States (CAN-SPAM): permits cold B2B email without prior consent, but requires accurate From and header information, a non-deceptive subject line, a valid physical postal address, a working opt-out mechanism, and that opt-outs be honored within 10 business days.
- EU/EEA (GDPR + ePrivacy): stricter and country-dependent. B2B outreach is commonly grounded in legitimate interest, which requires that the contact be relevant to the recipient's professional role, a documented balancing assessment, a clear opt-out, and a privacy notice explaining where you got the data. Some member states require consent even for B2B. Role-relevance is not optional here.
- Canada (CASL): consent-based, with narrow implied-consent exceptions (such as a conspicuously published business address relevant to the recipient's role). Penalties are substantial. Treat Canadian lists with care.
- United Kingdom (PECR): broadly permits B2B email to corporate subscribers with an opt-out, but not to sole traders or partnerships without consent.
Operationally: keep a record of where each contact came from, honor every opt-out across all tools immediately, and never obscure who you are. These overlap almost perfectly with good deliverability practice, and that is no coincidence. Filters are built to approximate the same rules.
A setup checklist you can work through
- Dedicated sending domains registered, aged, and 301-redirected to your main site
- Authorized Google Workspace or Microsoft 365 mailboxes, 2-3 per domain, with your own admin access
- SPF (single record, under 10 lookups), DKIM (2048-bit, verified in a real message header), DMARC (
p=rejecton sending domains), all confirmed manually - Custom tracking subdomain configured, or tracking disabled entirely
- Mailboxes connected to your sending tool with warmup enabled and a 2-4 week ramp
- Per-mailbox daily cap set to 30-50, with randomized send intervals and recipient-timezone business hours
- Lists verified immediately pre-send; role accounts and catch-alls excluded or capped
- Global suppression list unified across every tool and mailbox
- Seed mailboxes at Gmail, Outlook.com, Google Workspace, and Microsoft 365 enrolled in live campaigns
- Google Postmaster Tools connected; reply rate tracked per mailbox and per domain
- Spare warmed domains and mailboxes held in reserve at roughly 20% of active capacity
Frequently asked questions
How long does it take to get good cold email deliverability on a new domain?
Three to four weeks from registration to full sending volume. Roughly: a few weeks of domain age with DNS configured, then a 2-4 week mailbox ramp from 5-10 sends/day to 30-50. Compressing this is the most common cause of a domain that never performs. If you need volume sooner, the answer is more mailboxes and more domains in parallel, not a faster ramp on fewer.
Does email warmup software actually work?
It helps establish a baseline engagement history on a new mailbox and provides a structured volume ramp, both of which are genuinely useful. It does not repair reputation damaged by bad lists or complaints, and reciprocal-reply networks are a pattern receiving providers have every reason to recognize. Treat it as part of a ramp, run it in your sending tool (Instantly, Smartlead, ReachInbox), and prioritize real replies from real prospects. Those are worth far more than simulated ones.
Can I just use my main company domain for cold email?
No. If cold outreach damages that domain's reputation, you also lose password resets, invoices, customer support replies, and signup confirmations, and recovery takes weeks with no guarantee. The cost of separate sending domains is a few dollars a month. There is no scenario where the trade is worth it.
Is cheaper infrastructure worth the risk?
The price difference between authorized mailboxes and bulk-resold ones is small in absolute terms; the risk difference is not. Unauthorized or bulk-provisioned accounts get suspended in batches, and if you don't hold the tenant and admin access you cannot audit your own authentication, export your mail, or migrate. Judge a provider on whether you own what you're paying for (authorized Workspace and Microsoft 365 mailboxes, admin access, your DNS, an API, and no lock-in) rather than on per-mailbox price.