Cold Email InfrastructureFeatured

    Cold Email Deliverability: The Complete Guide to Inbox Placement

    Cold email that lands in spam makes every other decision irrelevant. The technical foundation, the sending discipline, and the order to work in when placement breaks.

    Email deliverability infographic showing the flow from email server through DNS authentication to inbox placement
    September 17, 202511 min read
    Share:
    The short answer

    Cold email deliverability depends on authentication that resolves, separate sending domains aged about 30 days, four to six weeks of warming, and volume held far below the provider ceiling at roughly 20 sends per mailbox per day. When placement breaks, work the diagnostic order from authentication down to content rather than rewriting copy first.

    Key takeaways

    • Cold email runs on separate sending domains, never the primary one, because a flagged domain takes transactional mail and the team's ordinary correspondence down with it.
    • Volume per mailbox decides more than the provider ceiling does. At roughly 20 sends per mailbox per day across two mailboxes, a domain sits near 40, so 1,000 sends a day means about 50 mailboxes across 25 domains.
    • When placement is already broken, the order is authentication, then blocklists, then list quality, then sending pattern, then complaint rate, with content last, because each step is faster to rule out than the one after it.
    • One message per campaign. Adding follow-ups multiplies the volume sent to a given audience roughly fivefold, and every one of those extra sends goes to somebody who has already declined to engage once.

    Reviewed and updated September 17, 2025

    The Complete Guide to Cold Email Deliverability

    A campaign goes out to two thousand people and returns four replies. The copy gets rewritten, the list gets rebuilt, the offer gets sharpened, and the next campaign returns three. Nothing in that loop touches the actual problem, which is that most of those messages were filed as junk before anyone read a word of them.

    Placement sits underneath everything else. A subject line only competes against other subject lines once it is in the same folder as them.

    This guide covers the technical foundation, the sending discipline that keeps it standing, and the order to work in when placement has already gone wrong.

    Most advice on how to avoid spam filters starts with words to remove from the subject line, which is the last thing that decides placement and the first thing people change.

    What Deliverability Actually Means

    Delivery and deliverability are two different measurements, and mixing them up is why so many senders believe a campaign went fine.

    Delivery means the receiving server accepted the message. Deliverability means it landed in the primary inbox rather than the junk folder. A campaign can report 99% delivery and still be almost entirely unread, because a message filed as spam was accepted before it was filed.

    When you send a cold email, three things can happen:

    1. It lands in the primary inbox, where a person may see it.
    2. It is delivered and filed as spam, which is invisible and looks like success in your reporting.
    3. It is rejected outright, which at least tells you something is wrong.

    The second outcome is the one that costs money, because nothing in your sending platform reports it. Placement is not directly observable from the sending side at all. What you can do is estimate it with seed testing, which inbox placement testing covers, and read the receiver's own view of your sending in Google Postmaster Tools.

    We plan cold programmes against a working target of roughly 70% to 85% inbox placement. That is a planning figure rather than a measured guarantee, and any provider quoting you a placement percentage as a promise is quoting something they cannot observe either.

    Cold email is harder than transactional or marketing mail for three structural reasons. New domains carry no history. Recipients have no prior relationship, so early engagement is thin. Volume arrives in patterns that look nothing like a person typing. You are asking a filter to trust an unknown sender, and the filter's default answer is no.

    The Diagnostic Order

    A frequent starting point is that previous lead generation efforts never solved the email delivery problem, and the diagnostic order below is why: a programme that changed the copy or the list while leaving authentication, domains and warming untouched was working on the layer that was not broken.

    When placement is broken, the expensive mistake is starting with the copy. Work in this order instead, because each step is cheaper and faster to check than the one after it, and because a problem found at step one makes every later step meaningless.

    1. Step 1Authentication

      SPF, DKIM and DMARC resolving correctly for the exact sending domain. Minutes to check, hours to fix.

    2. Step 2Blocklists

      Check whether the domain or its IP is listed. A listing explains sudden, total failure better than anything else.

    3. Step 3List quality

      Bounce rate is the fastest read on whether the addresses exist and belong to people.

    4. Step 4Sending pattern

      Volume per mailbox, ramp speed, and how long the domain has existed.

    5. Step 5Complaints

      Spam complaint rate against the receiver's published threshold.

    6. Step 6Content

      Last, and usually least. Rewriting copy is the most attempted fix and among the least effective.

    The order to work in when placement is already broken. Each step is cheaper to check than the one after it.

    The order is not a ranking of how interesting each layer is. It is a ranking of how likely each one is to be the actual cause, weighted by how quickly you can rule it out. Broken authentication and a blocklist listing produce symptoms that look identical to a content problem from the sending side, and both are fixed in hours rather than weeks.

    Authentication: SPF, DKIM and DMARC

    DNS email authentication showing SPF, DKIM and DMARC records

    Three DNS records establish that mail claiming to come from your domain actually did. Skip any of them and receiving systems have no basis for trusting the message at all.

    SPF publishes which servers are allowed to send for your domain. It is a single TXT record, and the most common failure is having two of them, which invalidates both. One record, checked after every change.

    DKIM attaches a cryptographic signature to outbound mail, proving it was not altered in transit and that it came from a server holding your key. The key is generated at your mailbox provider, in the Google Workspace admin console or the Microsoft 365 admin centre, and the public half goes into DNS as a TXT record. This is worth stating plainly because a lot of guidance tells you to generate DKIM keys inside your sending platform. The sending platform relays mail through the mailbox provider; the signing identity belongs to the provider that hosts the mailbox.

    DMARC tells receiving systems what to do when SPF or DKIM fail, and asks them to report back. Start at p=none, which monitors without affecting delivery, read the reports until you are confident nothing legitimate is failing, then move to p=quarantine and eventually p=reject.

    The record syntax, the per-provider setup steps and the common misconfigurations are covered in full in SPF, DKIM and DMARC for cold email. Two points that belong here rather than there: authentication must resolve for the exact domain in the From header rather than a parent domain, and a custom tracking domain needs its own DNS entries. Shared tracking domains put your click links on a hostname whose reputation is set by every other user of that platform.

    Domains and Mailboxes

    This is also the answer to the objection that cold email uses mismatched domains which hurts credibility: the sending domain is deliberately not the company domain, and the identity the recipient checks lives in the sender name and the signature, which is why those three have to agree with each other.

    Never send cold email from your primary domain. If the domain gets into trouble, the damage is not confined to the campaign. Invoices, password resets and your team's ordinary mail all inherit the same reputation. Cold outreach runs on separate sending domains that are treated as consumable.

    That word is the important one. A sending domain is inventory with a working life, not a permanent asset, and the operating posture that follows from it is to replace a domain that develops a problem rather than nurse it back. We maintain considerably more sending capacity than a campaign consumes for exactly this reason.

    On the domains themselves, RevenueFlow runs generic sending domains from our own pre-warmed inventory as a matter of policy, and never registers client-branded or lookalike domains for a campaign. The client's identity lives in the sender display name and the signature, which is where a recipient actually reads it. A lookalike domain buys nothing a display name does not already provide, and it puts a brand's name on infrastructure that is designed to be discarded.

    Volume per mailbox is the number that matters most, and it is far lower than the provider ceiling. Google Workspace and Microsoft 365 both permit daily volumes in the thousands, and those published limits are the point at which the provider stops you rather than the point at which filters stop trusting you. The per-provider figures are collected in email sending limits by provider.

    Our operating policy is roughly 20 sends per mailbox per day, with two mailboxes on a domain, which puts a domain at about 40 sends a day. Working out the inventory from there is arithmetic rather than judgement:

    Daily sendsMailboxes at 20/dayDomains at 2 mailboxes
    200105
    5002513
    1,0005025

    Those are worked from the policy figures above rather than from any measured result. The shape of the answer is what matters: reaching real volume means many mailboxes each doing very little, distributed by the sending platform, which is what inbox rotation describes. A programme that hits its number through a handful of hard-pushed mailboxes is carrying a risk it has not priced.

    Finally, let a new domain exist for about 30 days before it sends anything cold. Registration date is visible to receiving systems and a domain registered this week sending outreach next week is a recognisable pattern.

    Warming

    You cannot take a new mailbox from zero to full volume. Warming means raising volume gradually while positive engagement accumulates against the domain, and it takes four to six weeks.

    1. Week 15 to 10 per day

      Warmup traffic only. The domain is establishing that it exists and behaves.

    2. Week 210 to 15 per day

      Still warmup traffic. Watch for anything landing in junk at this stage.

    3. Week 315 to 20 per day

      First real sends can begin alongside warmup, in small volumes.

    4. Weeks 4 to 6About 20 per day

      Steady state. The mailbox stays here rather than climbing further.

    An illustrative warming ramp for a single mailbox, ending at the roughly 20 sends per day this guide plans against. The figures describe a schedule shape, not a measured result.

    Automated warmup tools exchange mail between participating accounts and mark it as read, replied to and not spam. They generate engagement signals cheaply, and they are worth running. They also do less than the category implies, because the engagement is synthetic and receiving systems are not obliged to weigh it the same way they weigh a real conversation. What warmup tools actually do works through the gap between the claim and the mechanism.

    The one thing warming cannot do is repair a domain that has already been burned. Warming prepares a clean domain for volume, and a burned one needs the recovery path further down this page.

    One Message Per Campaign

    Standard practice across the industry is a sequence: an initial email, then three, five or seven follow-ups to anyone who did not reply.

    We do not run follow-up sequences. Every campaign carries exactly one message, and a prospect who does not reply is approached later in a separate campaign with a genuinely different angle, never as a bump underneath the message they already ignored.

    The reasoning is partly about response and partly about deliverability, and both point the same way.

    The response side of the argument, and the reasoning that produced the policy, is set out in the case for dropping follow-up sequences entirely.

    The deliverability side is arithmetic, and it is unforgiving. A five-touch sequence multiplies the send volume for a given audience by roughly five, and every one of those extra sends goes to somebody who has already declined to engage with you once. Non-engagement is one of the signals filters weigh most heavily, so a sequence concentrates your worst engagement signal into most of your volume. You are spending five times the sending capacity to accumulate a reputation problem.

    It also makes capacity planning honest. When a campaign of 2,000 leads means 2,000 sends, the inventory arithmetic above is the whole calculation. Cold email infrastructure works through what that means when you are sizing a programme.

    Content, and the Trigger-Word Question

    Two rules get bundled together here and only one of them is firm: domains are warmed before they send, and hyperlinks are worth being sparing with in a first message for the way they read rather than because a link is itself a deliverability fault.

    Lists of forbidden spam words circulate endlessly, and rewriting copy to avoid them is the most commonly attempted deliverability fix. It is also among the least effective.

    Those lists are a relic of rule-based filtering. Modern filters weigh authentication, domain history, sending pattern and recipient behaviour far more heavily than vocabulary, which is why the same message lands in the inbox from one domain and in junk from another. A message can be filed as spam without containing a single word from any of those lists, and a message full of them can land perfectly well from a domain with history behind it. What a spam filter actually weighs and how Gmail's filtering works both go through this in detail.

    None of which makes content irrelevant. A few structural things genuinely matter, and they are about shape rather than vocabulary:

    • Links. One or two, on a tracking domain you control.
    • Attachments. None, in a first cold message.
    • Format. Plain text or close to it. Image-heavy HTML in a cold message is a pattern in itself.
    • Relevance. The signal that outranks everything on this list. Messages people find relevant get engagement, and engagement is what a filter is trying to predict.

    Write like a person writing to one other person, and the vocabulary question stops being interesting.

    Monitoring

    Inbox versus spam placement

    Four numbers tell you whether the foundation is holding.

    Bounce rate should sit under 5%. Above 8% the list is the problem, and no amount of infrastructure work will compensate. Verifying addresses before upload is cheaper than every remedy downstream of a bad list.

    Spam complaint rate should sit well under 0.1%. Google publishes 0.3% as the level at which senders should expect consequences, so 0.1% is the number to run against rather than the number to approach.

    Reply rate is the closest thing to a direct read on whether recipients want the mail. It is also the input filters care about most, which makes it a deliverability metric as much as a performance one.

    Placement, estimated by seed testing, since it cannot be measured directly.

    Content-scoring tools return a number for a single message against the older, rule-based layer of filtering. That number is worth reading and is not worth optimising, for the same reason the trigger-word lists are not: it scores the layer that decides the least. Spam score covers what those readings do and do not represent.

    If You Are Already Flagged

    Recovery, in order
    • Yes: Stop sending from the affected domains immediately
    • Yes: Check blocklists for the domain and the sending IP
    • Yes: Request delisting through each blocklist's own process
    • Yes: Re-verify authentication end to end before resuming anything
    • Yes: Re-verify the list that was sending when the problem started
    • Yes: Resume at warming volumes, not at previous volumes
    • No: Keep sending while you investigate
    • No: Rewrite the copy first
    The recovery sequence when placement has already collapsed. Order matters more than speed.

    The blocklist branch has its own procedure, including which listings matter and which are noise, in blacklist check and recovery.

    One judgement call sits at the end of this. A domain that has been genuinely burned can take months to recover, and replacement inventory costs the price of a domain plus a warming cycle. Rebuilding a burned domain is frequently the more expensive option, and treating domains as consumable from the start is what makes that an easy decision rather than a painful one.

    The Audit Checklist

    Run this before launching and again whenever placement moves:

    Authentication. One SPF record, resolving. DKIM signing and verifying at the mailbox provider. DMARC published, at minimum p=none. Custom tracking domain configured.

    Domains. At least 30 days old. Not on a blocklist. Separate from your primary domain. Generic rather than brand-lookalike.

    Sending. Warming completed. About 20 sends per mailbox per day. Enough mailboxes that no single one is pushed. One message per campaign.

    List. Verified before upload. Bounce rate under 5%. Targeting that makes the message plausibly relevant.

    Content. One or two links. No attachments. Plain text or close to it.

    The checklist version of this, run as a standalone exercise, is the deliverability audit.

    The Bottom Line

    Deliverability is a small number of unglamorous decisions, made early and then held. Authentication that resolves. Domains that are separate, aged and treated as consumable. Volume per mailbox far below the ceiling. One message per campaign rather than a sequence that multiplies your worst engagement signal. A list of addresses that exist.

    Get those right and the content question becomes a writing question, which is a much better problem to have. Get them wrong and the best campaign you will ever write goes into a folder nobody opens.

    Deliverability is the infrastructure layer underneath every other cold email decision. It comes first because everything above it depends on it.

    Provider limits and platform behaviour change. Verify current terms with the provider before relying on them.

    Want this handled for you? See if you qualify for our done-for-you service, where the infrastructure work above is ours rather than yours.

    Questions

    Frequently asked questions.

    Frequently asked questions
    What is the difference between email delivery and email deliverability?
    Delivery means the receiving server accepted the message. Deliverability means it landed in the primary inbox rather than the junk folder. A campaign can report 99% delivery and still be almost entirely unread, because a message filed as spam was accepted before it was filed, and nothing in the sending platform reports that outcome.
    How long does it take to warm up a new domain for cold email?
    Four to six weeks, and separately a new domain should exist for about 30 days before it sends anything cold, because registration date is visible to receiving systems. Warming raises volume gradually while engagement accumulates. It prepares a clean domain for sending and cannot repair one that has already been burned.
    How many cold emails should you send per mailbox per day?
    Roughly 20, which is far below what Google Workspace or Microsoft 365 permit. Published provider limits mark the point at which the provider stops you rather than the point at which filters stop trusting you. Volume comes from many mailboxes each doing very little, distributed by the sending platform, rather than from a few pushed hard.
    Do spam trigger words actually matter for cold email?
    Much less than the lists suggest. Those lists are a relic of rule-based filtering, and modern filters weigh authentication, domain history, sending pattern and recipient behaviour far more heavily than vocabulary. A message can be filed as junk containing none of those words, and land cleanly containing several, depending on the domain that sent it.
    Email DeliverabilityCold EmailTechnical SetupSPF DKIM DMARCEmail InfrastructureB2B Sales
    Byline

    About the author.

    Tim Carden

    Tim Carden is CMO / CTO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Studied at McGill University.

    Tim Carden · CMO / CTO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    Cold Email Infrastructure

    SMTP Ports: What 25, 465, 587 and 2525 Are Actually Registered For

    Three of the four ports in circulation are registered to mail and one is not. What the IANA registry and the RFCs say, and why none of it moves placement.

    8 min readRead →
    Cold Email Infrastructure

    Email Deliverability Services: What They Fix and What They Can't

    Deliverability services fix authentication, reputation and infrastructure. They cannot fix a bad list or an offer nobody wants, which is the usual real problem.

    8 min readRead →
    Cold Email Infrastructure

    Spam Filter Test: What Actually Triggers It

    Two different products are sold as a spam filter test. One scores a message, one samples a seed panel, and neither can see the layer that usually decides B2B placement.

    8 min readRead →
    Cold Email Infrastructure

    Reading MXToolbox Like a Deliverability Engineer

    What each MXToolbox check actually inspects, what a failure implies, and which findings are urgent versus cosmetic for a cold email sender specifically.

    7 min readRead →
    Cold Email Infrastructure

    Instantly.ai Pricing: What Each Tier Costs and What Actually Caps You

    Adding inboxes to Instantly costs nothing on any plan. What you pay for is contacts and monthly send volume, and here is where each tier actually runs out.

    7 min readRead →
    Cold Email Infrastructure

    Email Warmup Tools: What They Do and What Actually Moves Placement

    Warmup pools are now free in every major sending tool. What the mechanism actually is, why nobody publishes controlled placement data, and the levers that do work.

    7 min readRead →