Cold email infrastructure is the difference between landing in the inbox and landing in spam - before you've even written a word of copy. Getting it right requires configuring domains, authenticating sending identities, warming up accounts, and monitoring deliverability signals. This guide gives you the actual configs and timelines, not a vague overview. Follow it step by step and your sending accounts will have a solid foundation before the first cold email goes out.
What you need for a cold email infrastructure: (1) Dedicated sending domains separate from your main domain, (2) SPF, DKIM, and DMARC records correctly configured on each domain, (3) A 4-5 week inbox warmup before sending at volume, (4) Multiple sender accounts rotating across your send volume to stay within per-account limits, (5) Ongoing deliverability monitoring via inbox placement tests and bounce rate tracking. None of this is optional - skip any of these and you'll eventually hit deliverability problems that are hard to recover from.
What You Actually Need Before Sending
Before any cold email goes out, you need these components in place. This is not a list of nice-to-haves - missing any of these will cause deliverability problems at scale:
- Sending domains: Dedicated subdomains or domains separate from your primary business domain (e.g., outbound.yourdomain.com or yourdomain-hq.com)
- Email accounts on those domains: One or more Google Workspace or Microsoft 365 accounts on each sending domain
- DNS authentication records: SPF, DKIM, and DMARC configured and verified on each sending domain
- Warmup period: 4-5 weeks, the first two pool-only, before ramping to target volume
- Sending platform: A tool that handles sequences, reply detection, and unsubscribe compliance (ACA, Instantly, Apollo.io, etc.)
- Monitoring: A way to track inbox placement, bounce rates, and domain reputation
The setup time for a new sending infrastructure from scratch is typically 2-3 hours of configuration work followed by 4-5 weeks of warmup time. You cannot shortcut the warmup - sending high volumes from freshly created accounts is the fastest way to get those accounts flagged or suspended.
Step 1: Domain Strategy - How Many Domains
Never send cold email from your primary business domain (the one used for your main website, company email, and customer communications). If that domain gets flagged for spam, it affects your entire business email deliverability - customer replies, invoices, support - everything.
Use dedicated sending domains instead. These are domains you purchase specifically for outreach. They're related to your brand but separate from it. Common patterns:
- Subdomain approach: outbound.yourdomain.com, go.yourdomain.com, mail.yourdomain.com
- Variant domain approach: yourdomain-hq.com, getyourdomain.com, tryyourdomain.com, yourdomain.io
- Abbreviation approach: ydmhq.com (for a brand called "Your Domain Message")
How many sending domains? The math is straightforward:
- Each email account should send no more than 30 emails per day on a standard provider mailbox, or 5 per day on a bulk-provisioned Microsoft 365 mailbox
- Each domain hosts 2 email accounts on the standard model, or up to 50 on the bulk-provisioned Microsoft 365 model (where one domain lives in its own tenant)
- So each domain supports 60 emails per day on the standard model, or 250 per tenant on the bulk-provisioned model
- For 500 emails/day: about 9 sending domains with 2 accounts each on the standard model, or 2 bulk-provisioned tenants
- For 1,000 emails/day: about 17 sending domains on the standard model, or 4 bulk-provisioned tenants
Register your sending domains 4-5 weeks before you plan to start sending - you need this lead time for DNS propagation and warmup. Buy them from a reputable registrar (Namecheap, Cloudflare, Google Domains). Avoid registrars known for cheap bulk domain sales, as those registrar ranges are sometimes pre-flagged by spam filters.
Step 2: DNS Authentication - SPF, DKIM, DMARC
Email authentication records are DNS TXT records that prove your emails are authorized to be sent from your domain. SPF defines which mail servers can send on behalf of your domain. DKIM adds a cryptographic signature to each email proving it wasn't tampered with in transit. DMARC tells receiving mail servers what to do when an email fails SPF or DKIM, and requests reporting on who is sending mail from your domain. All three are required for reliable inbox placement at modern mail providers.
SPF Record
SPF (Sender Policy Framework) is a TXT record at your domain root that lists which mail servers are authorized to send email for your domain.
For Google Workspace:
Add this TXT record to your domain's DNS at the root (@):
v=spf1 include:_spf.google.com ~all
For Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
The ~all at the end means "soft fail" - emails from unlisted servers are accepted but marked as suspicious. Use -all (hard fail) only after verifying all your legitimate sending sources are covered. Do not have more than one SPF record per domain - multiple SPF records break SPF validation.
DKIM Record
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to emails. The setup process varies by email provider:
For Google Workspace: Go to Admin Console - Apps - Google Workspace - Gmail - Authenticate email. Generate a DKIM key. Google provides a TXT record to add to your DNS. It looks like:
Name: google._domainkey
Value: v=DKIM1; k=rsa; p=[your-public-key]
For Microsoft 365: Go to Security Center - Email & Collaboration - Policies & Rules - DKIM. Enable DKIM signing for your domain. Microsoft will provide two CNAME records to add to your DNS.
After adding the DKIM record, return to the admin console and click "Start authentication." Verification typically takes 15-60 minutes after DNS propagation.
DMARC Record
DMARC tells receiving servers what to do with emails that fail SPF or DKIM, and sets up reporting so you can see who is sending mail from your domain.
Add this TXT record at _dmarc.yourdomain.com:
Start with a monitoring-only policy:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-reports@yourdomain.com; fo=1
The p=none means emails that fail DMARC are still delivered - this is for monitoring only. After reviewing DMARC reports for 2-4 weeks and confirming all legitimate mail is passing, upgrade to:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100
And eventually to p=reject once you're confident in your SPF/DKIM setup. Use a DMARC report parser (dmarcian, Postmark's DMARC analyzer) to read the XML reports that arrive at your designated email.
Verifying your setup
Use MXToolbox (mxtoolbox.com) to verify all three records. Run the SPF check, DKIM check (you'll need to specify the selector - "google" for Google Workspace), and DMARC check on each sending domain before moving to warmup. All three should show green before you proceed.
Step 3: Inbox Warmup Schedule
Inbox warmup is the process of gradually increasing sending volume from a new email account over 4-5 weeks. Mail providers track sending patterns - a new account that immediately starts sending cold traffic looks like a spammer. An account that opens with pool sends only and eases into its target volume over a month looks like a legitimate business.
Warmup timeline benchmark: Most warmup tools and deliverability experts recommend 3-4 weeks of warmup before ramping to target send volume; we run 4-5, with the first two weeks pool-only. Google Workspace accounts typically build reputation faster than accounts on cheaper or newer mail providers. Accounts that skip warmup or compress it to under 2 weeks frequently experience sudden inbox placement drops after 2-4 weeks of production sending - right when they've built up a prospect list. The warmup cost is patience; the alternative cost is starting over with new accounts.
Week-by-week warmup schedule (per account):
- Weeks 1-2: warmup pool sends only, no cold prospects. These should be real back-and-forth exchanges - warmup tools that send emails between accounts in a network and auto-reply work well here. Tools: Instantly warmup, Lemwarm, Mailreach, or the built-in warmup in your outreach platform.
- Week 3: introduce cold sends at about a third of target - roughly 10 per day on a standard provider mailbox, 2 on a bulk-provisioned one - with warmup pool sends continuing underneath.
- Week 4: raise to about two thirds of target - roughly 20 per day standard, 3-4 bulk-provisioned - if inbox placement testing is clean.
- Week 5: steady state at target and no higher - 30 per day on a standard provider mailbox, 5 per day on a bulk-provisioned Microsoft 365 mailbox. There is no later stage where these go up.
Never turn off warmup entirely once you start production sending. Keep warmup sends running in the background - the positive engagement signals from warmup network replies help maintain sender reputation over time.
Step 4: Sender Account Rotation
Sender rotation distributes your total daily send volume across multiple email accounts to keep each individual account within safe limits. This is not optional at scale - it's the core architecture of a healthy cold email infrastructure.
The rotation math:
- Target volume: 500 emails/day
- Safe per-account limit: 30 emails/day on a standard provider mailbox, 5 on a bulk-provisioned one
- Accounts needed: 500 / 45 = ~11 accounts
- Domains needed (3 accounts per domain): 4 domains
How to set up rotation in your outreach platform: In ACA, Instantly, or Apollo.io, you add multiple sender accounts to a campaign and set the sending distribution - either even rotation (each account sends the same number) or weighted rotation (accounts with longer warmup history send more). The platform handles the routing automatically.
Rotation best practices:
- Don't add brand-new accounts to production rotation - they need their full warmup period first
- Retire accounts that show spam rate spikes rather than trying to recover them (Google Postmaster Tools shows domain-level complaint rates)
- Keep a reserve of warmed-up accounts (2-3 extras) so you can rotate in replacements without interrupting campaigns
- Spread accounts across 2-3 different domains rather than loading many accounts onto one domain - domain-level reputation matters independently of account-level reputation
Step 5: Deliverability Monitoring
Setting up infrastructure correctly once is not enough - deliverability is an ongoing signal you need to monitor. The following signals indicate developing problems before they become serious inbox placement issues:
Google Postmaster Tools
Free tool from Google that shows spam rate, domain reputation, and IP reputation for mail flowing to Gmail from your sending domains. You must verify each sending domain with Google's postmaster tools to see its data. A healthy domain shows "High" or "Medium" reputation and a spam rate under 0.10%. Above 0.10% is concerning; above 0.30% triggers algorithmic filtering that's difficult to recover from without resting the domain.
Inbox placement testing
Tools like GlockApps and MailReach send test emails from your accounts to a seed list of inboxes across providers (Gmail, Outlook, Yahoo, others) and report what percentage land in inbox vs. spam folder. Run inbox placement tests before launching a new campaign and weekly during active campaigns. A drop from 90% inbox placement to 70% is a warning sign that needs investigation before it gets worse.
Bounce rate monitoring
Hard bounces (addresses that don't exist) and soft bounces (temporary delivery failures) are tracked in your outreach platform. Keep hard bounce rate below 2% - lists with higher hard bounce rates indicate poor list hygiene and will hurt sender reputation. Run contact lists through an email verification tool (NeverBounce, ZeroBounce, Hunter verifier) before enrolling in campaigns.
Reply rate as a deliverability signal
A sudden drop in reply rate on a campaign that was previously performing - with no change to copy or targeting - often indicates a deliverability problem. If inbox placement and reply rates both drop simultaneously, check Postmaster Tools for reputation signals and pause campaigns from affected accounts while investigating. For a comprehensive deliverability guide, see our cold email deliverability guide.
Common Infrastructure Mistakes
- Using your primary domain for cold outreach: If the outreach domain gets flagged, your primary domain reputation can suffer. Always use dedicated sending domains.
- Skipping or rushing warmup: Warmup is time-consuming but non-negotiable. Accounts without proper warmup history fail under production volume.
- Putting too many accounts on one domain: More than 3 accounts per domain concentrates risk - one domain issue takes down all accounts on it.
- Not monitoring Postmaster Tools: Problems visible in Postmaster data can be addressed before they become permanent deliverability damage. Teams that don't monitor often discover issues only after replies dry up completely.
- Incorrect DMARC policy too early: Setting
p=rejectbefore all legitimate mail is covered can reject your own emails. Start withp=noneand verify reports first. - Buying cheap domains in bulk from the same registrar: Registrar IP ranges matter. Large batches of domains from certain registrars are pre-flagged. Spread domain purchases across 2-3 reputable registrars.
- Not verifying DNS with testing tools: SPF, DKIM, and DMARC records are often misconfigured on the first attempt. Always run MXToolbox checks before starting warmup.
Frequently Asked Questions
How long does cold email infrastructure setup take?
Configuration time is 2-3 hours: buying domains, setting up email accounts, configuring DNS records, verifying with MXToolbox, and enrolling accounts in warmup. The warmup period itself takes 4-5 weeks. Plan for 4-5 weeks from "starting from scratch" to "ready to send at production volume."
Do I really need separate domains for cold email?
Yes. Your primary domain is too valuable to risk on cold outreach. If your cold email domain gets flagged for spam, dedicated sending domains protect your main domain from collateral damage. The cost is low (a few dollars per domain per year) and the protection is significant. Every serious outbound team uses sending-specific domains.
What is the daily sending limit for cold email?
Safe per-account limits: 30 emails per day maximum on a standard provider mailbox (Google Workspace, or properly licensed Microsoft 365), with no more than 2 mailboxes per domain. Bulk-provisioned Microsoft 365 mailboxes carry far less sender trust and cap at 5 per day, though you can run up to 50 of them per domain with one domain per tenant. Gmail's own limit is 500/day, but reaching that on a cold email account will trigger spam detection well before the hard limit. Use rotation across multiple accounts to reach higher total daily volumes safely.
Should I use Google Workspace or Microsoft 365 for cold email accounts?
Both work. Google Workspace inboxes have slightly better deliverability to Gmail recipients (which make up a large share of B2B contacts). Microsoft 365 accounts tend to deliver better to Outlook/Microsoft business inboxes. For maximum coverage, use a mix: primarily Google Workspace accounts with a minority of Microsoft 365 accounts in your rotation. Google Workspace starts at $6/user/month, Microsoft 365 Business Basic at $6/user/month.
One caveat if you use Microsoft 365: Basic authentication for SMTP AUTH is being retired. It still works today and behavior is unchanged through December 2026, when it becomes disabled by default for existing tenants. Connect M365 mailboxes via OAuth or Microsoft Graph rather than a password, and see what actually changed with Microsoft 365 SMTP basic auth for the full timeline.
What SPF, DKIM, and DMARC records do I need?
You need all three on every sending domain. SPF tells receivers which servers can send for your domain. DKIM cryptographically signs each email. DMARC tells receivers what to do when SPF or DKIM fails and sends you reports. Omitting any of them leaves your sending reputation vulnerable - modern mail filters treat missing authentication records as a spam signal. See the DNS setup section above for specific record values.
How do I know if my emails are landing in spam?
Three signals: (1) Inbox placement testing with GlockApps or MailReach, (2) Google Postmaster Tools showing your domain's spam rate and reputation, (3) reply rate - a sudden unexplained drop on an active campaign often indicates inbox placement problems. Run inbox placement tests before new campaigns and after any infrastructure change.
