Skip to content

Cold Email Deliverability: The Rules That Protect Your Domain

Separate domain, SPF, DKIM, DMARC, slow warm-up, modest volume and a verified list: the cold email deliverability rules that keep you out of spam.

By the Glintscout team11 min read

On this page
  1. Why cold email plays by stricter rules
  2. Rule 1: Send from a separate domain
  3. Rule 2: Authenticate with SPF, DKIM and DMARC
  4. Rule 3: Verify and narrow your list before every campaign
  5. Rule 4: Warm up new domains and mailboxes slowly
  6. Rule 5: Keep daily volume per mailbox modest
  7. Rule 6: Write like a person, not a campaign
  8. Rule 7: Make opting out easy, and honor it fast
  9. Rule 8: Monitor, and stop when the numbers turn
  10. What Google, Yahoo and Microsoft require
  11. A checklist before your first campaign
  12. FAQ

Cold email reaches the inbox when four things hold: the sending domain is authenticated with SPF, DKIM and DMARC, it has a sending history built up slowly, the list is verified and tightly targeted, and almost nobody reports your emails as spam. Break one and filters notice. Below are eight rules that protect your domain, followed by the requirements Google, Yahoo and Microsoft actually publish.

Why cold email plays by stricter rules

Mailbox providers write their sender guidelines for mail people asked for. Google's email sender guidelines tell senders to "make sure recipients opt in to get messages from you" and "don't purchase email addresses from other companies". Cold outreach has no opt-in by definition, so it has no cushion: nobody is expecting your email, and every recipient can report it.

The thresholds are tight. Google asks senders to keep the spam rate reported in Postmaster Tools below 0.1% and never to reach 0.3%. On 1,000 emails delivered to Gmail inboxes, 0.3% is three spam reports. The only protections cold email has are relevance, restraint and a clean list, and that's what the rules below are about.

Rule 1: Send from a separate domain

Spam reports and bounces attach to the domain you send from. If that's your main domain, one bad campaign can put your invoices, support replies and team mail at risk, so most cold emailers send from a separate domain that clearly belongs to the same company.

  • Pick a close variant. If your company uses example.com, an outreach domain might be getexample.com or example.co. A subdomain like outreach.example.com stays visibly tied to your main domain; a separate domain keeps the two apart.
  • Make it real. Redirect its website to your main site, create mailboxes for real people ([email protected]) and add MX records so replies arrive. Microsoft's sender recommendations ask for a From: address that "can receive replies".
  • Don't hide who you are. The name, company and address in your emails must be yours. A separate domain is for isolation, not disguise, and in the US, misleading header information is illegal under CAN-SPAM.
  • Give it time. A brand-new domain has no history. A common rule of thumb is to register it a few weeks before your first campaign, then warm it up (rule 4).

Rule 2: Authenticate with SPF, DKIM and DMARC

These three DNS records prove that mail from your domain really comes from you. Set up all three on every domain you send from.

SPF

SPF lists the servers allowed to send mail for your domain, in a single TXT record at the domain root. With Google Workspace, it looks like this:

getexample.com.  TXT  "v=spf1 include:_spf.google.com ~all"

Your email provider tells you what to include. Two rules from the standard trip people up: a domain must publish only one SPF record, and checking it may take no more than 10 DNS lookups. Break either and SPF fails with a permanent error (RFC 7208, sections 4.5 and 4.6.4).

DKIM

DKIM adds a signature to every message, which receivers check against a public key in your DNS. Turn it on in your email provider and publish the record it gives you, under a selector name such as google._domainkey.getexample.com. Use a 2048-bit key: the standard requires at least 1024 bits and recommends 2048 (RFC 8301).

DMARC

DMARC tells receivers what to do with mail that fails, and it requires the domain in your From: address to match the domain that passed SPF or DKIM. Start with a monitoring policy that sends you reports:

_dmarc.getexample.com.  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

p=none meets the bulk-sender requirements summarized at the end of this guide. Once the reports show that all your legitimate mail passes, tighten it to p=quarantine and then p=reject. Microsoft recommends a gradual rollout so a sender you forgot doesn't get its good mail rejected. The current DMARC standard is RFC 9989, published in May 2026 to replace RFC 7489.

To check the setup, send a test email to a Gmail address, open it and choose "Show original": SPF, DKIM and DMARC should all say PASS.

Rule 3: Verify and narrow your list before every campaign

Bounces and spam reports are what burn a domain, and both come from the list. Our guide to email bounce rates explains the numbers; the short version:

  • Verify right before sending. Check every address and put only valid ones in the main campaign. A common rule of thumb is to keep hard bounces under 2%, and a freshly verified list should do far better.
  • Leave out catch-all and unknown addresses, or send them as a small, separate batch.
  • Narrow the target. One niche, one area, one offer. Spam reports come from emails that aren't relevant to the reader, and a narrow list is the best defense.
  • Build the list from where businesses publish their details instead of buying addresses, which Google's guidelines specifically advise against.

If you build lists with Glintscout, verification is part of the run: a Google Maps search finds the businesses for each city and niche, every address gets a verdict from a check that sends no email, and only valid addresses reach your CSV.

Rule 4: Warm up new domains and mailboxes slowly

Google's guidance fits cold email exactly: "Start with a low sending volume to engaged users, and slowly increase the volume over time. Avoid introducing sudden volume spikes if you do not have a history of sending large volumes."

In practice, start each new mailbox with a handful of emails a day, ideally to people likely to reply, and raise the volume week by week. An example ramp (a common starting point, not a standard):

Week New cold emails per mailbox per day
1 5 to 10
2 10 to 20
3 20 to 30
4 onward Up to 30 to 50, if bounces and replies look healthy

Services that warm up mailboxes by trading automated messages exist, but they can't fix a bad list or an email people report as spam. If bounces or deferrals rise during the ramp, step back: Google advises reducing volume until errors fall, then increasing slowly again.

Rule 5: Keep daily volume per mailbox modest

No provider publishes a safe number for cold email. A common rule of thumb is 30 to 50 new cold emails per mailbox per day after warm-up, spread across business hours on weekdays, with follow-ups counted in the total.

Your provider's limits are ceilings, not targets. Google Workspace allows up to 2,000 messages a day per user (500 on trial accounts), and a user who hits a limit can be blocked from sending for up to 24 hours (Google Workspace sending limits). Sending cold email anywhere near those numbers from one mailbox is asking for trouble.

Teams that need more volume usually add a few mailboxes rather than pushing one hard. But more volume is rarely the answer: a better-targeted list gets more replies from fewer emails.

Rule 6: Write like a person, not a campaign

A first email should look like a note from one person to another, because that's what it is:

  • Plain text, short, one idea. No images, no attachments and at most one link. Skip link shorteners: Google's guidelines say links "should be visible and easy to understand".
  • Honest subject lines. No fake "Re:" or "Fwd:". In the US, CAN-SPAM prohibits deceptive subject lines, and a fake reply is a quick way to earn a spam report.
  • Something true and specific about the recipient's business in the first line. Our cold email templates for local businesses show how.
  • Go easy on tracking. Open tracking adds a hidden image to every message and click tracking rewrites your links. Open counts are unreliable anyway: Apple's Mail Privacy Protection downloads remote content in the background whether or not an email is read (Apple). Many cold emailers turn open tracking off and measure replies; if you track clicks, use a custom tracking domain.

Rule 7: Make opting out easy, and honor it fast

A recipient who can't find a way out has one button left: "Report spam". Give them a better one.

  • Put an opt-out in every email. A plain line works: "Not relevant? Reply 'no' and I won't email you again."
  • Add one-click unsubscribe if your tool supports it. Google and Yahoo require one-click unsubscribe (RFC 8058) for bulk marketing mail, and it costs nothing to turn on.
  • Honor opt-outs fast. Google recommends processing unsubscribes within 48 hours, Yahoo requires 2 days, and CAN-SPAM's legal maximum is 10 business days.
  • Suppress everywhere. Keep one suppression list shared across every mailbox, domain and tool you send from.

Whether you may email a business without consent at all depends on where it is. In Germany, for example, advertising emails generally need prior consent, even between businesses. Our guide Is cold email legal? covers the main laws. This is general information, not legal advice.

Rule 8: Monitor, and stop when the numbers turn

Watch these for every campaign and every mailbox:

  • Bounce rate. Pause a mailbox whose hard bounces pass your limit.
  • Spam rate. Google Postmaster Tools shows it for mail to personal Gmail accounts. At cold-email volumes its data can be thin or missing, so don't read silence as a clean bill of health.
  • Deferrals and blocks. Codes like 421 4.7.28 (rate limited) or 550 5.7.1 (blocked by policy) in your bounce messages mean a provider has noticed you.
  • Reply rate. A sudden drop with no change to your emails often means you've started landing in spam.
  • Blocklists. If replies fall or blocks appear, look up your domain and sending IPs on the major blocklists, such as Spamhaus.

When a number turns, stop the affected mailbox, find the cause and restart at a lower volume. Sending through a problem only makes it bigger.

What Google, Yahoo and Microsoft require

Gmail Yahoo Outlook and Hotmail
Every sender SPF or DKIM; spam rate under 0.3% SPF or DKIM; spam rate under 0.3% Recommended, not required
Bulk senders SPF, DKIM and DMARC; one-click unsubscribe SPF, DKIM and DMARC; one-click unsubscribe SPF, DKIM and DMARC
Who counts as bulk Close to 5,000 or more messages a day to personal Gmail accounts No number published More than 5,000 emails a day
Unsubscribes honored within 48 hours 2 days Not specified

The details are in Google's guidelines and FAQ, Yahoo's sender best practices and Microsoft's requirements for high-volume senders. Four points matter for cold email:

  • Google's bulk status is permanent. A domain that has once sent close to 5,000 messages to personal Gmail accounts in a day stays a bulk sender, and since November 2025 Gmail has been stepping up enforcement, with temporary and permanent rejections of mail that doesn't comply.
  • Microsoft rejects failing mail from high-volume senders with the error 550 5.7.515.
  • The DMARC they require can be monitoring only (p=none), as long as it passes and your From: domain aligns with SPF or DKIM.
  • Google also requires valid forward and reverse DNS for sending servers, TLS and messages formatted to RFC 5322. If you send through Google Workspace or Microsoft 365, they take care of these for you.

Most B2B cold emailers never reach the bulk thresholds, which count mail to personal mailboxes. Meet the bulk rules anyway: once set up they cost nothing, and many of the businesses you email run their mail on Google Workspace or Microsoft 365.

A checklist before your first campaign

  • A separate outreach domain, redirected to your main site, with MX records and real mailboxes
  • SPF (one record, under 10 lookups), DKIM (2048-bit) and DMARC (p=none with reports), all passing in "Show original"
  • Each mailbox warmed up for three to four weeks (rule of thumb)
  • A list verified within the last few days, with only valid addresses in the main campaign
  • A plain-text first email: honest subject, at most one link, your name, company and postal address, and an opt-out line
  • A daily cap per mailbox that includes follow-ups
  • One suppression list across all mailboxes and tools
  • Bounce and reply tracking, with a rule for when to stop

FAQ

How many cold emails can I send per day?

No mailbox provider publishes a safe number for cold email. A common rule of thumb is 30 to 50 per mailbox per day after warm-up. Google Workspace's limit of 2,000 messages per user per day is a ceiling for normal use, not a target.

Do I need DMARC for cold email?

Google, Yahoo and Microsoft require it for bulk senders, and most cold emailers never reach their thresholds. Set it up anyway: a p=none record takes minutes, sends you reports on who is sending as your domain and meets the requirement if you ever cross the line.

Should I use a subdomain or a separate domain?

A separate domain keeps your main domain's reputation furthest from your outreach; a subdomain is still visibly tied to it. Either way, authenticate it fully and warm it up before sending.

How long does warm-up take?

A common rule of thumb is three to four weeks of gradually rising volume before a mailbox reaches its full daily volume, and longer if bounces or deferrals appear along the way.

Does open tracking hurt deliverability?

No provider says it does, but it adds a tracking image to every email and gives you unreliable data, since some mail apps load images automatically. Many cold emailers turn it off and measure replies instead.

Keep reading

All articles