Cold Email Deliverability Basics Every Founder Should Know
SPF, DKIM, DMARC, warm-up, and sending volume, explained without the jargon: the technical minimum that keeps outbound out of spam.
The short answer
Cold email deliverability rests on four things: send from a separate domain to your main business domain, authenticate it with SPF, DKIM, and DMARC, warm the mailbox gradually before sending volume, and keep bounces and spam complaints near zero. Content matters far less than most people assume; reputation matters far more.
Key takeaways
- Never run cold outbound from the domain your business depends on for real mail. Use a separate, similar domain.
- SPF, DKIM, and DMARC are the non-negotiable minimum. Missing any of them means major providers have no reason to trust your mail.
- Warm-up is about establishing a sending pattern, not about hitting a number. Ramp gradually over weeks, not days.
- Bounces and spam complaints damage reputation faster than anything you could write. Verified data is a deliverability control, not just a data-quality one.
Deliverability is whether your emails actually reach the inbox instead of spam. It’s determined mostly by three technical records on your domain, how gradually you ramp up sending volume, and how clean your recipient list is. Get those right before worrying about subject lines or copy, because none of that matters if the email never arrives.
SPF, DKIM, and DMARC, in plain terms
- SPF (Sender Policy Framework). A DNS record listing which mail servers are allowed to send email for your domain. Without it, receiving servers have no way to confirm an email claiming to be from your domain actually came from an authorised source.
- DKIM (DomainKeys Identified Mail).A digital signature added to outgoing email, verified against a public key published in your DNS. It proves the email wasn’t altered in transit and genuinely came from your domain.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance). A policy record that tells receiving servers what to do if an email fails SPF or DKIM checks (reject it, quarantine it, or let it through), and where to send reports about it.
All three are set up once, in your domain’s DNS settings, usually through whoever manages your domain or your email provider’s admin panel. Missing any of them makes your domain look less trustworthy to receiving mail servers, even before volume or content are a factor.
Warming up a new domain or mailbox
A brand new domain or mailbox has no sending history, which mail providers treat as a risk signal on its own. Sending high volume immediately, before any history exists, is one of the fastest ways to get flagged. Warming up means starting with low daily volume and increasing it gradually over several weeks, giving mailbox providers time to build a positive picture of how your domain sends mail.
Sending volume and pacing
Beyond the initial warm-up, consistent, moderate daily volume outperforms sporadic bursts. A domain that sends 20 emails a day, every day, builds a more stable reputation than one that sends nothing for two weeks and then 400 in a day.
List quality matters as much as any technical setting
Every bounce and every spam complaint counts against your domain’s reputation, regardless of how well SPF, DKIM, and DMARC are configured. This is why verifying every address before sending (see how to verify a B2B email address) is a deliverability practice, not just a data-quality one.
A basic checklist before your first campaign
- SPF, DKIM, and DMARC configured and verified for the sending domain.
- A warm-up plan for a new domain or mailbox, not immediate full volume.
- Every recipient address verified, not guessed.
- A visible, working way for a recipient to opt out.
- Consistent daily sending volume rather than large, irregular bursts.
Why a separate sending domain is not optional
Sending reputation attaches to a domain. If cold outbound damages the reputation of the domain you run your company on, the cost is not a worse campaign. It is your invoices, your password resets, and your replies to customers landing in spam. That is an unrecoverable class of problem to trade for a marginally simpler setup.
The standard arrangement is a second domain that is obviously yours but is not your primary: getyourcompany.com or yourcompany.io alongside yourcompany.com. Authenticate it fully, warm it separately, and if it ever gets burned, retire it without touching anything that matters.
The three DNS records, and what each one actually proves
| Record | What it does | What breaks without it |
|---|---|---|
| SPF | Lists which mail servers are allowed to send for your domain. | A receiving server has no way to know your sending provider was authorised. |
| DKIM | Cryptographically signs each message so the receiver can verify it came from your domain and was not altered. | Nothing ties the message to your domain beyond an easily-forged header. |
| DMARC | Tells receivers what to do when SPF and DKIM fail, and where to send reports. | The other two records are checks nobody is required to act on. DMARC is what turns them into enforcement. |
All three are DNS records, all three are a one-off setup, and all three are checkable in minutes with any free authentication tester. Start DMARC at p=none so you can read the reports without rejecting your own mail, then tighten once the reports are clean.
Warm-up: what it is actually establishing
Warm-up is often described as “building trust”, which makes it sound mystical. What it is doing is more prosaic: creating a sending history. A brand-new domain that sends four hundred messages on its first day looks exactly like a domain bought for one campaign, because that is usually what it is.
Ramp over several weeks, starting at a handful of messages a day and increasing gradually. Keep the pattern steady, because consistent daily volume matters more than the absolute number. And note what warm-up cannot do: it establishes a pattern, it does not repair damage. A warmed domain sending to unverified addresses still bounces, and bounces still cost you.
The two metrics that decide everything
Bounce rate. Keep it as near zero as your data allows. Mailbox providers read repeated bounces as evidence of a list you did not earn. This is why verification is a deliverability control and not merely a data-quality nicety. It is the single highest- leverage thing on this page.
Spam complaint rate. The heaviest-weighted signal there is, and the one you cannot fix with configuration. Complaints come from irrelevance, not from technical problems. Someone who receives a well-targeted, clearly-explained email from a real person might decline; they rarely report it. Someone who receives the fourth generic pitch this week marks it as spam, and that decision follows your domain around.
What content filters actually catch
Less than people think. The folklore about trigger words, never write “free”, never use the word “guarantee”, is largely obsolete; modern filtering is dominated by reputation, engagement, and authentication. There are still a few worthwhile content habits:
- Plain text or very light HTML. A first cold email should not look like a newsletter.
- Few or no links, and no tracking pixel, in a first touch.
- No attachments.
- A real, monitored reply-to address on a domain that resolves.
- A genuine, working opt-out route, honoured immediately.
Those last two are also compliance requirements in the UK and EU rather than best practice. See the PECR guide.
A minimum setup checklist
- Register a separate sending domain.
- Configure SPF, DKIM, and DMARC on it, and verify each with a tester.
- Create the sending mailbox and warm it gradually over several weeks.
- Verify every address before it enters a campaign.
- Keep daily volume modest and steady rather than spiky.
- Maintain a suppression list and check it before every send.
- Monitor bounces and complaints weekly, and stop rather than push through a rising trend.
This is the part of outbound No Stress Agents runs for its clients: per-account research, verified contacts, and a drafted email you approve before it sends.
See the cold email outreach service