What decides whether a cold email reaches the inbox?
Deliverability is the share of your emails that land in the inbox rather than the spam folder or a rejection. It is not the same as "delivered": a receiving server can accept a message and still file it as spam, and most sending tools count it as sent anyway.
Gmail, Yahoo and Outlook decide where a message goes from a few groups of evidence: whether the sender proves who it is (authentication), how the domain and inbox behaved before (reputation), how recipients react (replies, deletions, spam reports) and, to a lesser degree, the content. Nobody asked for a cold email, so every weak point costs more.
Work in order. Fix authentication and domain setup first, then warm-up and volume, then list quality, then content. A better subject line does nothing for an inbox that fails DMARC.
How do I set up SPF, DKIM and DMARC?
These three DNS records tell receiving servers that you are allowed to send for your domain. Publish them on every sending domain before the first email, and recheck them whenever you add a sending service. Google Workspace and Microsoft 365 also handle reverse DNS and encrypted (TLS) delivery for you; on your own mail server, those are on you.
| Record | What it proves | Where it lives |
|---|---|---|
| SPF | Which servers may send mail for the domain | One TXT record on the domain |
| DKIM | That the domain signed the message and nobody changed it | A public key in a TXT record; signing switched on in your provider |
| DMARC | What receivers do when checks fail, and where reports go | A TXT record at _dmarc.yourdomain.com |
SPF: the two rules that break most records
Defined in RFC 7208, SPF checks the envelope sender, the bounce address used during delivery, not the From address your reader sees. Two rules cause most failures: evaluating a record may take no more than 10 DNS lookups in total (every include, a, mx, ptr, exists and redirect counts, nested ones too), and a domain with two SPF records gets a permanent error. Audit the record whenever you add or drop a sending tool.
DKIM: keys and selectors
Defined in RFC 6376, DKIM has your provider sign each message with a private key and name the signing domain (d=) and a selector (s=). Receivers fetch the public key at selector._domainkey.yourdomain.com. Selectors let one domain hold several keys, so you can add a sending service or rotate a key without a gap. Use a 2048-bit key if your DNS host supports it.
DMARC: alignment, policy and reports
Defined in RFC 7489, DMARC passes when SPF or DKIM passes and the domain it checked aligns with the From domain; relaxed alignment, the default, accepts subdomains of the same organizational domain. The p tag sets what receivers do with failures (none, quarantine or reject) and the rua tag names where aggregate reports go. Start at p=none, read the reports, and tighten once all your legitimate mail passes.
A sample record set for one sending domain
- SPF (TXT on getacme.com): v=spf1 include:_spf.google.com ~all, if the domain sends only through Google Workspace.
- DKIM (TXT on google._domainkey.getacme.com): the public key from your admin console; "google" is the selector Google Workspace proposes by default.
- DMARC (TXT on _dmarc.getacme.com): v=DMARC1; p=none; rua=mailto:dmarc@acme.com. Reports sent to another domain need its consent, so acme.com also publishes v=DMARC1 at getacme.com._report._dmarc.acme.com.
- MX records so replies arrive, and a redirect to acme.com so a curious prospect finds your real website.
How should I set up sending domains, warm-up and daily volume?
Your main domain carries customer email, invoices, password resets and support replies. If cold outreach hurts its reputation, all of that starts landing in spam. Separate sending domains put a firewall between prospecting and the rest of the business.
Register a few close variants of your brand (getacme.com or acmehq.com for acme.com), redirect each to your website, and create two or three inboxes per domain under real people's names. When one domain has a bad week, you rest it and the others keep running. Use a few domains to isolate risk, not dozens to spread complaints thin; M3AAWG's sending domains practices give the industry view.
Email warm-up builds a sending history before an inbox carries cold volume. Warm-up tools exchange messages with other inboxes and open, answer and rescue them from spam; both products in Instantly vs Smartlead bundle one. Real conversations with customers and partners build an even stronger history. Plan two to four weeks before a new inbox runs at full cold volume. Warm-up cannot rescue a stale list or an unwanted offer: if a cleanly warmed inbox lands in spam once cold sends begin, check the list and the copy first.
Keep daily volume per inbox modest: a few dozen emails a day, follow-ups included, rather than hundreds from one address. A worked example: to reach 600 new people a month with a three-step sequence, you send about 1,800 emails, or 90 per working day over 20 days. At 30 per inbox per day, that is three inboxes on one or two domains, plus a spare domain so you can rest one without stopping.
| Week | Cold emails per day | What to watch |
|---|---|---|
| 1 | Warm-up only | All DNS records pass; no bounces from warm-up traffic |
| 2 | 5–10 | Bounces and placement in a few test inboxes |
| 3 | 15–20 | First replies; spam reports stay at zero |
| 4 and after | 25–40 | Bounce rate, spam reports and reply rate for this inbox |
What is a good cold email bounce rate, and how do I reduce it?
A bounce is an email the receiving server refuses. Hard bounces (the address does not exist) are the ones that hurt: a high share tells providers you are mailing a bought or stale list. Soft bounces (full mailbox, temporary error) usually clear on their own.
No mailbox provider publishes a bounce threshold. As an operating rule, stop any list that produces more than about 2% hard bounces and re-verify it, and treat a sudden spike on one inbox as an alarm. Most bounce problems start at the source: see how to find B2B leads, and keep a narrow ideal customer profile so you need fewer guessed addresses.
List hygiene also covers the people who asked you to stop. Keep one suppression list for unsubscribes, hard bounces and clear "no" replies, and apply it to every campaign and every list you import.
- Verify each address right before you send to it, not when the list was exported months ago, and never send to a pattern guess (first.last@) that has not passed verification.
- Be careful with catch-all domains, which accept any address at first and may bounce later. Send to them in small batches or skip them.
- Skip role addresses such as info@ or sales@: they rarely reach the person who decides.
- Suppress a hard-bounced address across all campaigns at once, and pause an inbox automatically when its bounce rate jumps.
What do the Gmail and Yahoo bulk sender requirements mean for cold email?
Since February 2024, Gmail and Yahoo enforce stricter rules for anyone sending to their users. Google defines a bulk sender as one that sends close to 5,000 or more messages to personal Gmail accounts in 24 hours, counting all mail from the same primary domain. Many cold programs stay below that, but the rules show what providers expect from everyone: treat them as your baseline.
Read the sources themselves: Google's email sender guidelines, the sender guidelines FAQ and Yahoo's sender best practices.
- Authentication: every sender needs SPF or DKIM. Bulk senders need SPF, DKIM and a DMARC record (a policy of none is accepted), with the From domain aligned.
- Spam complaint rate: keep the rate shown in Google Postmaster Tools below 0.3%, roughly three spam reports per 1,000 emails delivered to the inbox. Google advises staying under 0.1%. Yahoo uses the same 0.3% ceiling.
- Unsubscribe: bulk senders must offer one-click unsubscribe on marketing messages, using the List-Unsubscribe and List-Unsubscribe-Post headers defined in RFC 8058, show a visible unsubscribe link in the body, and honor requests within two days.
- Technical basics: valid forward and reverse DNS for the sending servers, TLS for transmission, and messages formatted to the internet mail standards.
Reach companies with a reason to buy this week
Startories finds the buying signal, verifies the decision-maker and runs the outreach until they book a call.
What does US law require of a cold email?
The CAN-SPAM Act covers commercial email, and the FTC compliance guide says it makes no exception for business-to-business email. It does not require consent before the first message; it sets rules for how each message is built and how opt-outs are handled. The guide lists seven requirements:
- No false or misleading header information. From, To, Reply-To and routing details must identify the sender.
- No deceptive subject lines. A fake "Re:" on a first email fails this test.
- Identify the message as an ad. The law leaves room for how, but the disclosure must be clear.
- Say where you are located. A valid postal address: street address, registered post office box or registered private mailbox.
- Tell recipients how to opt out. A reply address or a simple web page both work.
- Honor opt-outs promptly. Within 10 business days, with a mechanism that works for at least 30 days after sending, no fee, and nothing asked beyond an email address.
- Monitor anyone who sends for you. The company promoted and the company sending can both be held responsible.
What this means for a cold sequence
A real person's name in From, a subject that describes the email, a body that is open about selling something, your postal address in the signature and one plain opt-out line. A "no" in one campaign must stop every campaign, which is what the shared suppression list is for. If you send to Gmail or Yahoo users in bulk, add the one-click headers too: providers ask for more than the law.
Outside the US, and the industry view
In the EU, GDPR applies to the personal data in your lists; B2B prospecting usually relies on legitimate interest, which needs a documented balancing test, and national e-marketing rules vary. M3AAWG, the anti-abuse group whose members include major mailbox providers, urges opt-in only mailing. Cold outreach does not meet that bar, which is one more reason to keep it narrow, relevant and easy to stop.
Does email content still affect deliverability?
Less than setup and reputation, but yes. The strongest content signal is relevance: people rarely report an email that is clearly about something they posted or announced last week. This is one reason signal-based outbound is easier on domains than mass lists: fewer sends, each chosen for a reason, such as a public complaint about a competitor. The cold email templates guide shows that approach email by email.
- Write plain text that reads like one person writing to another. Heavy HTML, images and banner signatures look like marketing.
- Use one link or none in the first email, and never a link shortener: shortened links are a classic spam pattern.
- Consider switching off open tracking. It adds a hidden image and a tracking domain to every message, and privacy features such as Apple Mail Privacy Protection make open data unreliable anyway. If you track clicks, use a custom tracking domain tied to your sending domain.
- Vary the email by recipient. A hundred identical bodies sent within an hour is a pattern filters notice.
What an inbox-friendly first email looks like
Plain text, no link, and the reason for writing in the first line, where the preview shows it. The opt-out line meets the law and gives an uninterested reader an easier option than the spam button.
- From: Maya Chen (maya@getacme.com), the same person who signs the email.
- Subject: your post about month-end close
- Body: "Hi Sam, you wrote on Tuesday that month-end close at Brightloop takes a week because supplier invoices arrive as PDFs. Acme pulls those invoices into your ledger automatically. Would a two-minute video on a sample like yours be useful?"
- Signature: name, title, company and postal address. No logo or banner.
- Opt-out: "Not relevant? Reply no and I will not write again."
Why did my cold emails suddenly stop landing?
First locate the drop: one inbox, one domain, one list or everything at once. Then read the bounce messages. Under RFC 5321, the mail transfer standard, reply codes starting with 4 are temporary failures and codes starting with 5 are permanent. Providers add their own explanation; Google lists its codes in Gmail SMTP errors and codes.
| What you see | Likely cause | What to do |
|---|---|---|
| Replies drop on one inbox while others hold | That inbox or its domain lost reputation | Check its authentication and recent volume; pause a few days, restart at half volume |
| Hard bounces jump on one campaign | A stale or unverified list segment | Stop the campaign, re-verify, suppress every bounce |
| Permanent rejections that mention authentication | SPF, DKIM or DMARC failing or not aligned | Fix the DNS records and send a test before resuming |
| Temporary deferrals that mention rate or volume | Too much mail too fast from one inbox or domain | Lower the cap and spread volume across inboxes |
| Every inbox drops at once | Something shared: list, copy, link or tracking domain | Roll back this week's change; test a batch without links or tracking |
| Spam reports rise while bounces stay low | The targeting or the message does not fit the reader | Narrow the segment and rewrite the opening line |
How do I monitor deliverability week by week?
Add each sending domain to Google Postmaster Tools; its dashboards show the spam rate Gmail users report for your domain, plus authentication and delivery data, once the domain sends enough daily mail to Gmail users. A low-volume cold domain may show empty charts. Check these as well every week:
- Hard bounce rate per inbox and per list source.
- Reply rate per inbox: a drop on one inbox while the others hold steady usually means that inbox is landing in spam.
- Spam reports and unsubscribe requests, read one by one.
- DMARC aggregate reports, to spot unknown services sending as your domain.
- Placement tests with a few seed accounts at Gmail, Outlook and Yahoo before a new campaign starts.
How to start: a checklist before the first send
If you run outbound yourself, tick every line below before a new domain sends its first cold email, and use the warm-up weeks to build the list and the sequence, as the outbound sales strategy guide suggests.
- Domains redirected to your website, with MX records, SPF, DKIM and DMARC, and a test email showing all three passing and aligned.
- Inboxes under real names, with a plain signature that includes your postal address.
- Two to four weeks of warm-up behind each inbox, and a daily cap set in your sending tool.
- Addresses verified within days of the send, and the suppression list applied.
- An opt-out line in every email, and a weekly slot to read bounces, replies and spam reports.
Or let Startories run the sending side
Startories handles this as part of its AI outbound engine: dedicated inboxes on separate domains, warmed up before use, capped daily volume per inbox, verified business emails only, sequences that stop on reply, automatic pauses when bounces rise, and an opt-out in every email with suppression across campaigns. Its AI SDR writes each email from a real event. Plans start at $99 a month; see plans and pricing. If you want the domains and inboxes set up for you, the done-for-you option covers it.
Frequently asked questions
What is a good bounce rate for cold email?
Keep hard bounces well under 2% of sends on any list. Above that, stop the campaign and re-verify the list. Verify addresses right before sending, handle catch-all domains with care, and suppress every hard bounce across all campaigns.
How long does email warm-up take?
Plan two to four weeks before a new inbox on a new domain carries full cold volume. Start with warm-up only, add a few real sends in week two, and raise volume step by step while bounces and spam reports stay low.
Do the Gmail and Yahoo sender rules apply to cold email?
Yes. They apply to all mail sent to Gmail and Yahoo users. The strictest parts target bulk senders (for Google, close to 5,000 messages a day to personal Gmail accounts), but authentication and a low spam rate are expected from everyone.
Do I need DMARC on a cold email domain?
Yes. Gmail and Yahoo require a DMARC record from bulk senders, and it costs nothing to publish. Start with p=none and a reporting address, confirm in the reports that your mail passes and aligns, then tighten the policy.
How many cold emails can one inbox send per day?
Providers publish no fixed limit for cold email. A few dozen new emails per inbox a day, follow-ups included, is a safe working range. To send more, add inboxes and domains instead of raising the cap on one address.
Sources
- Google: Email sender guidelines
- Google: Email sender guidelines FAQ
- Google: Postmaster Tools dashboards
- Google: Gmail SMTP errors and codes
- Yahoo: Sender best practices
- IETF RFC 7208: Sender Policy Framework (SPF)
- IETF RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
- IETF RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- IETF RFC 8058: Signaling one-click functionality for list email headers
- IETF RFC 5321: Simple Mail Transfer Protocol
- FTC: CAN-SPAM Act compliance guide for business
- M3AAWG: Updated best practices for senders urge opt-in only mailings
- M3AAWG: Sending Domains Best Common Practices
- European Commission: What does "legitimate interest" mean?