Skip to main content
Lead Generation

Cold email deliverability in 2026

DNS records, warmup sequences, and sending limits that actually keep you out of spam.

1 prompts
6 steps
intermediate

Inbox placement has gotten harder every year since 2022, and 2026 is no different. Google and Yahoo enforced bulk sender authentication requirements in February 2024. Microsoft followed with tighter Outlook filtering shortly after. Those changes are now the baseline, not new news.

Spam filters no longer just check whether your headers look right. They score your domain reputation, your sending patterns, your message content, and your engagement history together. A clean SPF record does not save you if your reply rate is near zero and your domain is three days old.

This article covers the four areas that determine whether your cold emails land in the inbox: DNS authentication records, sending infrastructure setup, warmup sequences, and daily sending limits. Each section gives you specific numbers and configurations, not general advice.

21%
of cold emails never reach the inbox
Validity State of Email Deliverability 2024
45 days
average time to fully warm a new domain
Common benchmark across major sending platforms
3 records
SPF, DKIM, and DMARC all required
Google and Yahoo bulk sender mandate, enforced since Feb 2024
The context

Why deliverability is harder in 2026

The rules changed. Here is what is different now.

The February 2024 Google and Yahoo mandate set a clear line: domains sending over 5,000 emails per day must have SPF, DKIM, and DMARC configured correctly. No exceptions. Microsoft applied similar enforcement to Outlook around the same period. If any of those three records are missing or misconfigured, your mail goes to spam or gets rejected outright.

That mandate was the floor, not the ceiling. Mailbox providers moved well beyond header authentication in the years that followed. Google's Gemini-era filters and Microsoft's SmartScreen now read semantic content signals. They evaluate link destinations, message structure, and whether your phrasing matches known spam patterns. A message that passes authentication but reads like a template still gets filtered.

4
key insight

Reputation is domain-level now

Mailbox providers score your sending domain, not just your IP. A new IP on a warmed domain still inherits that domain's reputation. This is why domain age and history matter before you send a single email.

Helpful?

The other major shift is engagement-based filtering. Open rates, replies, and moves-to-inbox now feed back into your inbox placement score. Low engagement tanks future deliverability even when your authentication is clean. Microsoft's SmartScreen and Google's filters treat a mailbox that nobody replies to as a signal that the mail is unwanted.

This means cold email deliverability is no longer just a technical problem. Your copy, your targeting, and your reply rate all affect whether future messages land in the inbox. Infrastructure and content are now the same problem.

The foundation

DNS records — the non-negotiable foundation

SPF, DKIM, and DMARC explained without the jargon.

Three DNS records control whether receiving servers trust your email. SPF authorizes which servers can send on your behalf. DKIM signs each message so recipients can verify it was not tampered with in transit. DMARC tells receiving servers what to do when a message fails either check.

All three must be present and correctly configured. Missing one is enough to fail the Google and Yahoo bulk sender requirements. Having all three but misconfiguring DMARC to p=none gives you monitoring with no enforcement and no real protection.

Email authentication stack

DMARC

Policy enforcementReporting (rua/ruf)Alignment check

DKIM

Message signingPublic key in DNSHeader + body hash

SPF

Authorized sending IPsTXT record in DNSEnvelope-from check
How SPF, DKIM, and DMARC work together to verify a sent message
#1

SPF record

Lists every server authorized to send email from your domain.

Good:v=spf1 include:sendgrid.net include:_spf.google.com ~all
Bad:v=spf1 +all — authorizes any server on the internet to send as your domain
#2

DKIM record

A public key published in DNS that verifies your message signature.

Good:2048-bit key, selector matches your sending platform, key rotated every 6 to 12 months
Bad:1024-bit key (considered weak since 2023) or no DKIM record at all
#3

DMARC record

Sets the policy for what happens when SPF or DKIM checks fail.

Good:v=DMARC1; p=quarantine; rua=mailto:[email protected]; pct=100
Bad:v=DMARC1; p=none — monitoring only, no enforcement, no actual protection

The SPF lookup limit

SPF records allow a maximum of 10 DNS lookups. Adding too many 'include:' statements breaks authentication silently. Use an SPF flattening tool if you send through more than three platforms.

What DMARC reports actually tell you

DMARC aggregate reports (rua) arrive as XML files. They show which IPs sent mail claiming to be your domain, whether SPF and DKIM passed, and what the receiving server did with each message.

You can parse these manually or use a free tool like Google Postmaster Tools, or a paid service like Dmarcian or Valimail. Look for unauthorized sending sources first. These often indicate a compromised account or a third-party tool you forgot to authorize in your SPF record.

Forensic reports (ruf) go message-level, but many providers have stopped sending them due to privacy concerns. Do not rely on ruf being available in your monitoring setup.

Infrastructure

Setting up a sending infrastructure that scales

Domain structure, mailbox counts, and sending limits before you write a single email.

Your primary domain stays clean. Cold outreach runs from secondary domains that mirror your brand. Examples: getbrandname.com, trybrandname.com, hellobrandname.com. If a secondary domain gets flagged or blacklisted, your main domain reputation stays intact.

This is standard practice for anyone running outreach at volume. Secondary domains are not a workaround. They are the correct architecture for separating cold outreach risk from your core business domain.

Recommended setup
Common mistake
Send cold email from a secondary domain (trybrand.com)
Send cold email from your primary company domain
Run 2 to 3 mailboxes per domain maximum
Stack 10 or more mailboxes on a single domain
Use Google Workspace or Microsoft 365 for mailboxes
Use shared hosting or cheap SMTP relays for cold outreach
Set up a separate domain per campaign type or region
Mix cold outreach and transactional email on the same domain
Age new domains for 2 to 4 weeks before warming
Start sending on a domain registered yesterday
15
key insight

The 3-2-1 infrastructure rule

A practical starting point: 3 secondary domains, 2 mailboxes each, 1 warm-up period before any cold sends. This gives you 6 active mailboxes with isolated risk and room to rotate if one domain takes a hit.

Helpful?

Google Workspace and Microsoft 365 mailboxes have better inbox placement than shared SMTP services. Mailbox providers trust consumer-grade infrastructure more than generic relay services. This matters most in the first 90 days of a domain's life.

Dedicated IP addresses become relevant above roughly 50,000 emails per month. Below that threshold, shared IPs from reputable ESPs work fine. Dedicated IPs add complexity and require their own warmup process. Do not add them before you need them.

Warmup

Warmup sequences — what works and what wastes your time

A realistic ramp schedule and what automated tools can and cannot do.

Warmup is the process of gradually increasing send volume from a new mailbox. Receiving servers build a reputation signal before you hit full sending speed. A new mailbox that suddenly sends 200 emails per day looks like a spam source. Warmup mimics organic growth so the ramp looks normal.

The goal is to accumulate positive engagement signals: opens, replies, and inbox placements. Those signals tell mailbox providers that real people want your mail. Without them, even a perfectly authenticated domain will see spam placement once volume increases.

1

Register and age the domain

Buy the domain 2 to 4 weeks before you plan to send. Set up all DNS records immediately. Let the domain sit with no sending activity. This builds basic domain age and avoids the 'brand new domain' penalty that filters apply.

2

Configure mailboxes and authenticate

Create 2 to 3 mailboxes per domain. Verify that SPF, DKIM, and DMARC all pass using MXToolbox or a similar checker. Do not start warmup until all three records are confirmed clean.

3

Start warmup at low volume

Begin with 5 to 10 emails per mailbox per day in week one. Use real-looking conversations, not obvious templates. Automated warmup tools handle this by sending to a pool of other warming mailboxes and auto-replying to simulate engagement.

4

Ramp volume gradually

Increase by roughly 20 to 30 percent per week. A typical ramp: 10, 20, 40, 70, 100, 150 emails per day over 6 weeks. Do not skip weeks or jump volume suddenly. Sudden spikes are a spam signal regardless of your domain age.

5

Monitor placement during warmup

Use Google Postmaster Tools to watch domain reputation scores. Check spam placement rates weekly. If reputation drops to medium or low, pause sending and investigate before continuing the ramp.

6

Transition to cold sends at week 6 to 8

Start cold outreach at 50 to 60 percent of your maximum warmed volume. Keep warmup emails running in parallel to maintain engagement signals. Do not turn off warmup completely once you go live.

Automated warmup has a ceiling

Tools like Instantly, Lemwarm, and Mailreach warm mailboxes by exchanging emails within their own user pools. Mailbox providers have identified these patterns. Automated warmup helps establish a baseline, but it does not replace genuine engagement history. Treat it as a starting point, not a complete solution.

Generate a warmup email sequence

Claude / GPT-4
Write 10 short, natural-sounding email exchanges for warming up a new B2B sales mailbox. Each exchange should look like a real back-and-forth between two colleagues or business contacts. Vary the topics: scheduling a call, following up on a document, confirming a meeting time, asking a quick question. Keep each email under 80 words. Do not use sales language, calls to action, or links. The goal is to generate genuine-looking engagement signals, not to sell anything.
The numbers

Sending limits that keep you out of spam

Concrete daily and hourly caps for every stage of your domain's life.

Most deliverability failures at the sending limit stage come from one mistake: treating a warmed domain like a fully established one. A domain that completed warmup 10 days ago is not the same as a domain with 6 months of clean sending history. The limits below reflect that difference.

These numbers apply per mailbox, not per domain. If you have 3 mailboxes on a domain, multiply accordingly, but stay within the domain-level caps to avoid triggering pattern detection.

Safe sending limits by domain age

10–20

Emails per mailbox per day

▲ Weeks 1–2 of warmup

50–80

Emails per mailbox per day

▲ Weeks 4–6 of warmup

100–150

Emails per mailbox per day

▲ Fully warmed domain (6+ weeks)

200–300

Emails per domain per day

Max recommended across 2–3 mailboxes

The 100 to 150 emails per mailbox per day figure is the practical ceiling for Google Workspace and Microsoft 365 accounts used for cold outreach. Both platforms set their technical limits higher, but staying below 150 keeps your sending pattern within ranges that filters treat as normal human behavior.

Hourly distribution matters as much as daily totals. Sending all 150 emails in a 30-minute window looks like automation even if the daily total is within limits. Spread sends across business hours with randomized delays between messages. Most cold email tools have a throttle setting for this. Use it.

New domain (0–6 weeks)

Daily limit per mailbox

10–50 emails

Recommended domains

2–3 secondary

Warmup required

Yes, mandatory

Cold sends allowed

No — warmup only

DNS records

Must be set day 1

Warmed domain (6–12 weeks)

Daily limit per mailbox

50–150 emails

Recommended domains

3–5 secondary

Warmup required

Ongoing in parallel

Cold sends allowed

Yes, at 50–60% of max

DNS records

Monitor weekly

Established domain (6+ months)

Daily limit per mailbox

100–200 emails

Recommended domains

Scale as needed

Warmup required

Maintenance only

Cold sends allowed

Yes, at full volume

DNS records

Rotate DKIM keys every 6 months

Volume math

Calculating your total sending capacity

The formula is straightforward. Take your number of active mailboxes, multiply by your per-mailbox daily limit, then apply a 20 percent buffer to stay away from the ceiling.

Example: 6 mailboxes across 3 domains, each sending 100 emails per day, gives you 600 emails per day before the buffer. Apply the 20 percent buffer and your working capacity is 480 emails per day. That is enough for a focused outreach campaign without pushing limits that trigger filtering.

If you need more volume, add domains and mailboxes rather than pushing existing mailboxes harder. The risk of burning a domain is higher than the cost of registering another one.

Sending more than 200 emails per day from a single mailbox on any provider
Starting cold sends on a domain less than 3 weeks old
Running 10 or more mailboxes on a single secondary domain
Turning off warmup emails completely once cold sends begin
Sending all daily emails within a 1 to 2 hour window
Using the same email template for more than 200 sends without variation
Ignoring Google Postmaster Tools domain reputation scores
Setting DMARC to p=none and never moving to p=quarantine or p=reject
Ongoing monitoring

Monitoring deliverability after you go live

The checks that catch problems before they become blacklistings.

Deliverability is not a one-time setup. Domain reputation shifts over time based on engagement, complaint rates, and sending patterns. You need a short list of checks you run weekly, not just when something breaks.

Google Postmaster Tools is free and shows domain reputation, spam rate, and authentication pass rates for mail sent to Gmail. Set it up for every sending domain on day one. A reputation drop from high to medium is a warning. Medium to low means you stop sending from that domain immediately and investigate.

Weekly deliverability monitoring checklist

33
key insight

Spam complaint rate is the fastest reputation killer

Google's bulk sender guidelines set a spam complaint rate threshold of 0.10 percent. Above 0.30 percent, your mail starts getting blocked. One complaint per 300 emails sent puts you at the threshold. Clean your lists before you send, not after.

Helpful?

Blacklist monitoring catches a different problem than Postmaster Tools. A domain can have good reputation with Google but appear on a third-party blacklist that affects other providers. MXToolbox checks over 100 blacklists in one query. Run it weekly for each sending domain.

If a domain appears on a blacklist, stop sending from it immediately. Submit a delisting request to the specific blacklist provider. Most major blacklists (Spamhaus, Barracuda, SORBS) have a delisting form. Expect 24 to 72 hours for removal. Do not resume sending until the domain is clean.

How to recover a flagged sending domain

Stop all cold sends from the flagged domain first. Do not reduce volume. Stop completely.

Run a full diagnostic: check DMARC reports for unauthorized sends, verify all DNS records are still correct, check if the domain appears on any blacklists, and review your recent campaign reply and complaint rates.

If the domain is on a blacklist, submit delisting requests and wait for removal. If reputation dropped due to low engagement, run warmup-only traffic for 2 to 3 weeks before resuming cold sends at a lower volume.

If the domain is unrecoverable (persistent blacklistings or very low reputation scores), retire it. Register a new secondary domain, age it for 3 to 4 weeks, and start the warmup process from the beginning. The cost of a new domain is lower than the cost of continued poor deliverability.

Cold email deliverability checklist (2026)

A one-page reference covering DNS record setup, warmup milestones, daily sending limits, and weekly monitoring checks. Print it or keep it open during your infrastructure setup.