Cold email deliverability: a working guide
SPF, DKIM, DMARC, warm-up and sending caps, explained as an engineering problem rather than a checklist. Plus how to diagnose a drop that has already happened.
Deliverability is treated as a dark art largely because the feedback loop is broken. You send a thousand emails, you get twelve replies, and nothing anywhere tells you that four hundred of them went to spam. The absence of a signal reads as a copywriting problem.
It is not a dark art. It is an engineering problem with a small number of inputs, most of which are one-time setup and the rest of which are volume discipline.
Start with authentication
Three DNS records decide whether a receiving server believes you are who you say you are.
SPF lists the servers permitted to send for your domain. One record, and only one — two SPF records is a permanent fail, and it is the single most common misconfiguration.
v=spf1 include:_spf.google.com include:sendgrid.net ~all
DKIM signs each message with a private key whose public half is in DNS. It survives forwarding, which SPF does not. Use a 2048-bit key.
DMARC ties the two together and tells receivers what to do when both fail. Start at p=none with reporting on, read the reports for two weeks, then tighten.
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100; adkim=s; aspf=s
If you are sending outbound from your primary domain, stop. Use a dedicated sending domain — get.yourdomain.com or a separate registration — so that a reputation problem in outbound never touches the invoices and password resets going out from the company domain.
Warm-up is a rate limit, not a ritual
A new mailbox with no history that sends two hundred messages on day one looks exactly like a compromised account, because that is what compromised accounts do. Warm-up is not a magic trick; it is establishing a sending pattern that a reputation system can model.
A workable ramp for a new mailbox:
- Week 1: 10–20 messages a day
- Week 2: 30–40
- Week 3: 50–70
- Week 4 onwards: hold at 80–120 and stay there
That ceiling is not conservative, it is correct. A mailbox sending more than roughly 150 cold messages a day is outside the range that a human sender occupies, and everything downstream is a consequence of that. Volume comes from more mailboxes, not from pushing one harder.
The signals that actually cost you
Ranked roughly by damage:
- Spam complaints. Above 0.3% and you are in trouble; above 0.5% and Google will act. This is the only metric with a cliff.
- Hard bounces. Above 3% signals a list you did not verify. Verify before you send; it is cheap and it is the highest-leverage single change available.
- Sustained non-engagement. Thousands of messages that are never opened, replied to or moved is itself a signal.
- Spam-trap hits. Recycled addresses on a purchased list. One hit can cost a domain.
- Content signals. Real but overstated relative to the four above. Link shorteners, tracking pixels on every message, image-heavy HTML, and a first-touch email with three links all hurt at the margin.
Almost every "our copy got flagged" story is really a list-hygiene story. Content matters, but it matters last.
Diagnosing a drop
When reply rate falls off a cliff, work in this order and stop when you find it.
- Is it delivery or engagement? Check the delivery rate per mailbox. If delivery is 99% and replies fell, this is not a deliverability problem — something changed in targeting or copy.
- Is it one mailbox or all of them? One mailbox means a per-account reputation problem: check its complaint rate and its recent volume ramp.
- Did authentication break? DNS changes are made by people who do not know you send from that domain. Re-check SPF, DKIM and DMARC before anything else.
- Did volume jump? A step change in daily volume, especially after a new hire imported a list, is the most common cause.
- Did list quality change? Bounce rate over the last 7 days versus the previous 30 tells you immediately.
- Is the domain listed? Check the major blocklists. A listing is a symptom, not the disease — find what caused it before requesting delisting.
The discipline
Deliverability is not a project you complete. It is a set of limits you keep: verify before sending, cap per-mailbox volume, honour unsubscribes at send time rather than in a spreadsheet, and stop sequences the moment someone replies.
None of that is clever. All of it is the difference between an outbound programme and a burned domain.