Cold email is the hardest deliverability problem you can have, because you are sending to people who have never heard of you, at volume, from domains that most receiving providers have no history with. Gmail and Microsoft treat that combination as high-risk by default. The senders who land in the primary inbox are not using better copy or more magic. They have a boring, repeatable setup. Here is that setup, in the order it matters.
The single biggest mistake is sending cold outreach from your primary domain (the one on your website, your invoices, and your support mailbox). Cold email generates spam complaints and hard bounces by nature. If that happens on your main domain, you drag down the reputation of the domain your real business email lives on, and your transactional and support mail starts landing in spam too. The standard practice is a separate domain, usually a subdomain like outreach.yourdomain.com or a second-level domain you own, used only for cold sends. It can take the hits without endangering the rest of your email.
Every cold sending domain needs all three records, and they must align. SPF says which servers may send for the domain; DKIM signs each message so the receiver can verify it came from you; DMARC tells receivers what to do when SPF or DKIM fails. For cold email you want DMARC at p=none while you are learning, so you get reports without rejecting anything, and you want the From domain to match the domain that passes SPF or DKIM. A missing -all on SPF, or a DKIM signature on a different domain than the From header, are the two most common reasons an otherwise-correct setup still gets filtered. The free cold email deliverability checker confirms all of this in seconds.
This is the factor that separates senders who land in primary from senders who burn their domain in a week. A new sending domain has zero reputation. If you blast 500 cold emails on day one, Gmail and Microsoft will route most of it to spam or hold it, and the resulting complaints will poison the domain for weeks. The correct pattern is a warmup: start at a few dozen emails per day and increase gradually over two to four weeks, mixing in real engagement (replies, opens) so the receiving providers learn to trust you. Most cold email tools build this in. If you are sending manually, the rule is simple: never jump volume faster than the domain's reputation can absorb it. Use our free warm-up calculator to generate a day-by-day ramp for your target volume.
Cold lists are full of dead addresses, role addresses, and domains that no longer accept mail. Every hard bounce and every "report spam" click is a direct vote against your domain. The math is unforgiving: Gmail will start filtering you at a complaint rate around 0.1% and will throttle you hard above 0.2%. Practical levers: verify every address before it goes on the list, remove anyone who has not engaged in a while, keep a hard cap on daily volume per mailbox, and make the unsubscribe link one click. A clean list is worth more than any amount of copywriting.
Receiving providers read the message. Triggers that hurt cold email specifically: a subject line that does not match the body, too many images relative to text, tracking links that look like phishing, all-caps words, and a missing or broken List-Unsubscribe header. The one-click unsubscribe header is now a hard requirement for bulk senders at Gmail and Microsoft, and a broken one is a spam signal on its own. Keep the email short, mostly text, one clear link, and a working one-click unsubscribe.
Cold email domains are fragile. A DNS record that expires, an SPF that silently loses its -all, or a blocklist hit from a single bad day can drop your deliverability overnight, and you will not notice from inside your ESP until the reply rate has already collapsed. The fix is to check the sending domain's SPF, DKIM, DMARC, MX, and blocklist status daily and get alerted the moment something changes. That is exactly what Inboxproof Pro does: it monitors your sending domain around the clock and tells you the instant a record breaks or your IP gets listed, so a deliverability incident is a five-minute fix instead of a week of lost pipeline.
1. Dedicated sending domain that is not your primary business domain.
2. SPF, DKIM, and DMARC all present and aligned on that domain (run the free checker).
3. Slow warmup over two to four weeks before real volume.
4. Verified, clean lists with bounce and complaint rates near zero.
5. Short, text-heavy copy with a working one-click unsubscribe.
6. Daily monitoring of the sending domain so a broken record is caught in hours, not weeks.
Related: Transactional email deliverability · Why email lands in spam · SPF vs DKIM vs DMARC · p=none vs quarantine vs reject · Is my domain blacklisted? · What is a good deliverability score?
The free cold email deliverability checker tests SPF, DKIM, DMARC, IP reputation, TLS and routing for your sending domain and scores its readiness for cold email. No signup.
Check my sending domain now