Cold Email Deliverability: A Technical Guide to Reaching the Primary Inbox

Cold email deliverability is the share of your cold emails that land in the recipient's primary inbox instead of bouncing or being filtered to spam. Four levers control it, in order of impact: correctly authenticated infrastructure you actually own (SPF, DKIM and DMARC aligned on dedicated sending domains), low volume per mailbox (roughly 20-50 sends/day), verified lists that keep bounces under 2%, and content that earns replies rather than complaints.

Almost every "deliverability problem" is one of those four. The rest of this guide covers how to get each one right, how to tell which one is broken, and how to measure any of it without fooling yourself.

What is cold email deliverability, and how is it different from delivery rate?

Two different numbers get conflated constantly:

A campaign can show 99% "delivered" and 0% placement. If you are seeing normal delivery rates and near-zero replies, assume a placement problem until you have evidence otherwise.

Reasonable operating targets to hold your own setup to (these are thresholds to manage against, not published industry averages):

Why do cold emails land in spam?

In roughly descending order of how often it is the actual cause:

Note the ordering. Most people rewrite subject lines when the actual problem is a DKIM record or a mailbox sending triple the volume it should.

What DNS records do you need, and how do you set them up correctly?

You need SPF, DKIM, and DMARC on every sending domain, all passing with alignment, plus a custom tracking domain if you track clicks at all. Since Google and Yahoo's 2024 bulk sender requirements and Microsoft's equivalent rollout for Outlook.com in May 2025, senders above 5,000 messages/day to those providers must have all three, and non-compliant mail is routed to junk or rejected outright. Treat it as the floor regardless of your volume.

SPF

A single TXT record at the sending domain's root authorizing your provider's sending infrastructure. The two failure modes:

Use -all (hard fail) on dedicated cold-sending domains where you know every legitimate source. Use ~all on your main corporate domain where shadow senders are likely.

DKIM

A public key published at a selector subdomain, with the provider holding the private key and signing outbound mail. Use a 2048-bit key. 1024-bit is still accepted but is the weaker option and there is no reason to choose it. Verify the signature is actually present by inspecting a received message's headers, not by trusting a dashboard: look for dkim=pass in the Authentication-Results header of a test email sent to a Gmail account.

DMARC

A TXT record at _dmarc.yourdomain.com. DMARC's real function is alignment: it requires that the domain in the visible From: header matches the domain that passed SPF or DKIM. This is what actually stops someone else from sending as you.

Tracking domain

If you use open or click tracking, it must run through a CNAME on your own subdomain (e.g. link.yoursendingdomain.com). A shared tracking domain means your links resolve to a hostname that thousands of other senders, including bad ones, also use. That hostname carries reputation, and you do not control it.

Better: turn open tracking off entirely for cold email. The pixel adds a remote image load to an otherwise plain message, and since Apple Mail Privacy Protection the data it returns is noise. Keep click tracking only if you genuinely act on it.

Doing this by hand across dozens of mailboxes is where errors creep in. Inboxlogy provisions SPF, DKIM, and DMARC automatically per domain, which removes the most common single point of failure. The records are on your DNS, under your control, so verify them yourself after setup. Any provider's automation deserves one manual spot check.

How many cold emails can you send per mailbox per day?

20-50 per mailbox per day for established mailboxes, and under 20 for anything less than a month old. Scale by adding mailboxes, never by raising per-mailbox volume.

The published platform caps are not relevant guidance. Google Workspace permits on the order of 2,000 messages/day per user, and Exchange Online's recipient rate limits are in the thousands (Microsoft has been tightening external-recipient limits downward; check current documentation for your tenant). Those are abuse ceilings, designed to stop account takeover from spewing millions of messages. They describe what will get your account locked, not what will land in an inbox. Cold outreach at 500/day/mailbox will be filtered long before it is rate-limited.

Sensible arithmetic: if you need 1,000 sends/day, that's roughly 25-35 mailboxes at 30/day, spread across several sending domains with two or three mailboxes per domain. At typical infrastructure pricing, Inboxlogy starts at $2.80/mailbox/month, so the cost of over-provisioning mailboxes is trivially small compared to the cost of burning a domain.

Other rate discipline that matters:

How do you warm up a new mailbox and domain?

Ramp volume gradually over 2-4 weeks while generating genuine positive engagement, then hold steady. A workable schedule: 5-10 sends/day in week one, 15-20 in week two, 25-35 in week three, and 30-50 from week four if bounces and replies look healthy. Never jump. A mailbox going from 10 to 100 overnight is the pattern filters are built to catch.

An important clarification, because vendors frequently blur this: warmup runs in your sending tool, not in your infrastructure provider. Instantly, Smartlead, and ReachInbox each include warmup networks; you connect your mailboxes and configure the ramp there. Inboxlogy provides and authenticates the mailboxes. It does not run warmup itself. If a provider claims to do both, ask precisely what their warmup mechanism is.

Two honest caveats about automated warmup networks:

The highest-value warmup activity is unglamorous: send your first 100-200 messages to a hand-picked, genuinely relevant list with a message likely to earn a reply. Real replies from real humans are the strongest positive signal available to you.

Google Workspace, Microsoft 365, or an SMTP panel: what should you send from?

Use real Google Workspace or Microsoft 365 mailboxes for cold outreach. SMTP relay panels and bulk-sending platforms are cheaper per message and measurably worse at primary-inbox placement, because receiving filters weight the sending platform's reputation heavily and those platforms carry a heavy concentration of low-quality mail.

How to choose between the two:

One note on IPs: when you send through Google Workspace or Microsoft 365, the outbound IP belongs to that provider, so classic IP reputation management does not apply the way it does to self-hosted SMTP or an ESP relay. Where dedicated IP space does matter is the infrastructure around your mailboxes and your choice of region. Inboxlogy runs dedicated US and EU IPs, which also matters if you have EU data residency obligations.

Why does mailbox ownership matter for deliverability?

Because mailboxes provisioned through unauthorized resellers can be suspended en masse, and if you don't hold admin access you cannot audit, fix, or migrate anything. This is the risk most buyers discover only after it fires.

Concretely, ask any mailbox vendor these questions and insist on specific answers:

This is the specific gap Inboxlogy is built around: authorized Google Workspace and Microsoft 365 mailboxes with 100% ownership and admin access, your DNS, a full API, no setup fee, and month-to-month billing. The useful part of that list is not the price. It's that nothing about your sending capability is hostage to a vendor relationship.

How should you structure your sending domains?

Never send cold email from your primary brand domain. Use dedicated sending domains, 2-3 mailboxes each, and keep them structurally separate from the domain your customers, invoices, and signups depend on.

A workable structure:

What actually makes cold email content get filtered?

Structure and engagement, far more than vocabulary. The "spam word list" advice is largely obsolete. Modern filters are classifiers trained on recipient behaviour, not keyword matchers. What still matters:

How do you keep your list clean enough?

Verify every address before sending and keep hard bounces under 2%. List quality is the one lever that is fully within your control and the one most often skipped.

How do you measure cold email deliverability properly?

Use seed testing plus reply rate as your core metrics, and ignore open rates entirely. Open tracking is unreliable post-MPP and the pixel itself is a small liability on cold mail.

What to actually monitor:

Microsoft's SNDS and JMRP are IP-based and therefore not usable when you send via Microsoft 365, since the egress IPs aren't yours. Don't waste time there.

How do you diagnose a sudden deliverability drop?

Work from the mechanical causes outward (authentication, then volume, then list, then content) and change one variable at a time.

  1. Stop sending on the affected domain. Continuing while you diagnose deepens the damage.
  2. Send a test to a seed Gmail account and read the raw headers. Confirm spf=pass, dkim=pass, dmarc=pass. A DNS change, an expired record, or a registrar migration breaks this more often than people expect.
  3. Check for SPF overflow. If a teammate added an include: for a new tool, you may be over 10 lookups and failing silently.
  4. Audit volume and ramp. Look for any mailbox that spiked. Check whether a new campaign launched on mailboxes that weren't warmed.
  5. Audit the list that was running when it broke. Pull the bounce rate for that specific campaign. A single unverified or purchased segment is the most common trigger.
  6. Check your links. A newly added domain, a shortener, or a shared tracking domain introduced in the same window.
  7. Then look at copy. Last, not first.

If the domain is genuinely damaged, be realistic: recovery means weeks at drastically reduced volume with high-engagement sends, and it does not always work. This is why spare warmed domains are worth their trivial cost. Replacement is a reliable fix, rehabilitation isn't.

What are the legal rules for cold email?

Not legal advice, but the rules you need to know before you send:

Operationally: keep a record of where each contact came from, honor every opt-out across all tools immediately, and never obscure who you are. These overlap almost perfectly with good deliverability practice, and that is no coincidence. Filters are built to approximate the same rules.

A setup checklist you can work through

Frequently asked questions

How long does it take to get good cold email deliverability on a new domain?

Three to four weeks from registration to full sending volume. Roughly: a few weeks of domain age with DNS configured, then a 2-4 week mailbox ramp from 5-10 sends/day to 30-50. Compressing this is the most common cause of a domain that never performs. If you need volume sooner, the answer is more mailboxes and more domains in parallel, not a faster ramp on fewer.

Does email warmup software actually work?

It helps establish a baseline engagement history on a new mailbox and provides a structured volume ramp, both of which are genuinely useful. It does not repair reputation damaged by bad lists or complaints, and reciprocal-reply networks are a pattern receiving providers have every reason to recognize. Treat it as part of a ramp, run it in your sending tool (Instantly, Smartlead, ReachInbox), and prioritize real replies from real prospects. Those are worth far more than simulated ones.

Can I just use my main company domain for cold email?

No. If cold outreach damages that domain's reputation, you also lose password resets, invoices, customer support replies, and signup confirmations, and recovery takes weeks with no guarantee. The cost of separate sending domains is a few dollars a month. There is no scenario where the trade is worth it.

Is cheaper infrastructure worth the risk?

The price difference between authorized mailboxes and bulk-resold ones is small in absolute terms; the risk difference is not. Unauthorized or bulk-provisioned accounts get suspended in batches, and if you don't hold the tenant and admin access you cannot audit your own authentication, export your mail, or migrate. Judge a provider on whether you own what you're paying for (authorized Workspace and Microsoft 365 mailboxes, admin access, your DNS, an API, and no lock-in) rather than on per-mailbox price.