Email deliverability
SPF, DKIM, DMARC, warmup, spam triggers, and domain setup — the technical foundation every cold-email sender needs before the first message goes out.
What this hub covers
Deliverability is whether your email lands in the inbox, the promotions tab, the spam folder, or nowhere at all. This hub is about deliverability for cold outreach. The rules for transactional mail (password resets, receipts) and newsletter mail (consented subscribers) overlap, but the bar for cold senders is meaningfully higher in 2026.
If you are sending to people who never signed up, every part of the system is scoring you. The DNS records on your domain. The IP address you send from. The ratio of opens to deletes to spam reports on your last 100 messages. The content of the email itself. Get any one of those wrong and the rest stop mattering.
Read top to bottom if you are setting up a new sending domain. Jump to the section you need if you are debugging an existing one.
The 4 layers of deliverability
Every email you send is judged at four independent layers. They stack. A passing score at one layer cannot rescue a failing score at another. Think of it like a checkpoint sequence at an airport. You either clear all four or you do not get on the plane.
| Layer | What gets checked | Who controls it |
|---|---|---|
| 1. DNS authentication | SPF, DKIM, DMARC records on your domain | You, once, at the DNS provider |
| 2. Sending reputation | Domain + IP history at Gmail, Outlook, Yahoo | You, every day, over months |
| 3. Content scoring | Subject, body, links, images, HTML structure | You, per email |
| 4. Engagement signals | Opens, replies, deletes, spam reports, marks as read | Your recipients |
Layer 1 is a one-time setup. Layer 2 is a six-to-eight-week project. Layer 3 is per message. Layer 4 is the recipient's verdict and you can only influence it by sending to the right people. We will work through each in order.
DNS auth deep dive
SPF, DKIM, and DMARC are the three DNS records that tell receiving mail servers your domain is a real sender and not a forgery. Without all three set correctly, Gmail and Outlook will quietly route most of your mail to spam. With them set, you have cleared the first checkpoint.
The full walkthrough is at SPF, DKIM, DMARC explained. The short version of each follows.
SPF (Sender Policy Framework)
SPF is a list of servers allowed to send mail on behalf of your domain. It is a single TXT record at the root of your domain. When Gmail receives a message claiming to be from you, it checks this list. If the sending server is not on the list, the message looks like a forgery.
A working SPF record for a Google Workspace mailbox looks like this:
v=spf1 include:_spf.google.com ~all
If you send through multiple providers (Workspace plus Resend plus a sequencing tool), each one needs an include. SPF allows a maximum of 10 DNS lookups per check, and going over that flips your record into a permanent fail. Audit it whenever you add a new sender.
DKIM (DomainKeys Identified Mail)
DKIM is a cryptographic signature on every message you send. Your mail provider holds a private key. The matching public key lives on a DNS record. The receiving server verifies the signature against the public key to confirm the message was not tampered with in transit and really came from your domain.
Google Workspace generates the key for you at admin.google.com under Apps then Google Workspace then Gmail then Authenticate email. Copy the resulting TXT record into your DNS at the host name shown (usually google._domainkey) and turn on signing. Most people skip this step and wonder why their mail is in spam.
DMARC (Domain-based Message Authentication)
DMARC tells receiving servers what to do when SPF or DKIM fails. It also asks for aggregate reports so you can see who is sending mail claiming to be you. A working starter DMARC record looks like this:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; pct=100
Start with p=none. You are just collecting data at first. After two weeks of clean reports, move to p=quarantine. After two more weeks, move to p=reject. The 30-day plan is laid out further down this page.
Domain warmup: how it actually works
A brand new domain has no reputation. Send 500 messages on day one and Gmail assumes you are a spammer warming up to blast a list. Send 5 messages on day one, then 7, then 10, climbing slowly over six weeks, and Gmail watches the engagement pattern and builds a profile of you as a normal sender.
The trap is that warmup is not just about volume. The recipients matter. Sending 30 cold messages on day three to a scraped list of strangers is not warmup. That is a spam campaign with a small list. Real warmup means a mix of real conversations, replies you get back, and at least some traffic to addresses you control.
The full guide is at the email warmup guide. The week-by-week schedule we use:
| Week | Daily volume | Mix | What to watch |
|---|---|---|---|
| 1 | 5 per day | All to known contacts | Set up DKIM, confirm SPF and DMARC working |
| 2 | 10 per day | Mostly known, a few cold sends | Confirm zero spam complaints in Postmaster Tools |
| 3 | 15 per day | Half known, half cold | Reply rate above 2% on the cold half |
| 4 | 20 per day | Mostly cold, named contacts only | Bounce rate under 2%, no Outlook hard bounces |
| 5 | 25 per day | Cold campaign mode | Move DMARC from p=none to p=quarantine |
| 6 | 30 to 40 per day | Full cold sending | Domain reputation green in Postmaster Tools |
After week 6, do not push past 50 per day on a single mailbox without a hard reason. The volume is not the bottleneck. The list quality and the reply rate are. If you need more volume, add a second mailbox on the same domain and warm that one too.
New domains fail in predictable ways. The four most common are documented at cold email new domain mistakes. Read that before you send your first message.
Sending reputation: what providers see
Gmail and Microsoft both publish your sending reputation to you for free. Most senders have never logged in to check. If you are doing cold email and you cannot tell us your Gmail Postmaster reputation off the top of your head, you are flying blind.
Google Postmaster Tools
Sign up at postmaster.google.com with the same Google account that owns the domain. Verify by adding a TXT record. After 7 days of sending, you will see daily charts for IP reputation, domain reputation, spam rate, feedback loop complaints, and DMARC compliance. Check it weekly.
The reputation buckets Google uses are High, Medium, Low, and Bad. High and Medium will land in the inbox. Low means most messages go to spam. Bad is effectively a ban. The single fastest way to fall from High to Low is a spam complaint rate above 0.1%.
Microsoft SNDS
Microsoft runs Smart Network Data Services at sendersupport.olc.protection.outlook.com. It is uglier than Postmaster but more detailed. You see per-IP filter result counts (Green, Yellow, Red), spam trap hits, and complaint rate. Yellow means warning. Red means most mail to Outlook addresses is in junk.
Outlook is harsher than Gmail on new domains. A clean Gmail Postmaster score does not guarantee Outlook delivery. If half your list is on outlook.com, hotmail.com, or live.com domains, you need to monitor SNDS just as carefully as Postmaster.
What the scores actually mean
Reputation is a moving 30-day window. A perfect week does not save you from a bad previous month. The fix when reputation drops is not to stop sending and wait. It is to keep sending lower volumes to your best, most-engaged contacts until the rolling window recovers. We will cover that playbook in the recovery section below.
Spam triggers in 2026
The spam-trigger word lists from 2015 are mostly noise in 2026. Modern filters lean on engagement patterns, link analysis, and HTML structure. That said, certain content still nudges you toward the spam folder regardless of the rest.
| Trigger category | Examples | Severity |
|---|---|---|
| Spammy phrasing | "Act now", "Limited time", "Free trial", "Guarantee" | Medium |
| ALL CAPS subject or body | "URGENT!!", "READ THIS NOW" | High |
| Excess punctuation | "Hey!!!", "Quick question???" | High |
| Faked threading | Subject starting with "Re:" when no reply happened | Very high |
| Image-only emails | A single attached graphic, no real text | High |
| URL shorteners | bit.ly, tinyurl, t.co inside cold email | Very high |
| Mismatched From and Reply-To | From mike@domain1, Reply-To mike@domain2 | High |
| Too many links | More than 2 links in a 100-word email | Medium |
| Heavy HTML | Tables, inline CSS, tracking pixels, custom fonts | Medium |
| Unsubscribe link missing on bulk | No List-Unsubscribe header on sequences over 50 | High under 2024 Gmail rules |
The single biggest content change for 2026 is the Gmail and Yahoo bulk sender rules rolled out in early 2024. Senders mailing over 5,000 a day to a single provider must publish a DMARC record, sign with DKIM, include a one-click List-Unsubscribe header, and keep spam complaint rates below 0.3%. According to Google's official guidance, consistent breach of these rules now results in rejected mail, not just spam-folder routing.
For service-business senders mailing 30 a day, those volume thresholds do not apply. The structural rules (DMARC, DKIM, working unsubscribe) do, because Gmail's filters check them regardless of volume. Full breakdown at why cold emails land in spam and the deliverability mistakes audit.
When you get flagged: a playbook
Sooner or later something goes wrong. Bounce rate spikes. A list had bad addresses. Postmaster reputation drops from High to Low overnight. Outlook starts filtering everything you send to junk. Here is the actual recovery sequence we run, in order.
- Stop the sequencing tool immediately. Pause every active campaign. Do not send another cold message until you know what broke. Continuing to send into a flagged state digs a deeper hole.
- Pull the last 30 days of Postmaster data. What date did the reputation drop happen? What did you change on or before that day? New list, new copy, new sending domain, new volume. The trigger is almost always a change.
- Run the list through a verifier. Bounce rate is the most common cause. Take whatever you have not yet sent through ZeroBounce or Mailcheck and drop anything that comes back invalid, catch-all, or unknown.
- Switch to known-good recipients for 5 days. Send only to people you have replied with in the last 90 days. Volume drops to 5-10 per day. The goal is to get the rolling reputation window healthier with real engagement.
- Audit your DNS records. Run mxtoolbox.com against your domain. Make sure SPF is valid, DKIM is signing every message, DMARC is aligned. A broken DKIM key after a Workspace setting change is invisible until you go look.
- Resume warmup at week 2 volumes. Do not pick up where you left off. Go back to 10 per day, climb 5 per week, and watch Postmaster daily. Most domains recover from Low to Medium in 2-3 weeks.
- If reputation is Bad: retire the domain. A Bad rating almost never recovers. Buy a fresh near-match domain, set up DNS auth, and start warmup. The flagged domain becomes the cautionary tale, not the rescue project.
Most of the recovery work is patience. There is no inbox-placement button you can press. Lower the volume, raise the engagement ratio, wait out the 30-day window. Senders who panic and keep blasting always end up retiring the domain.
Dedicated IPs vs. shared: who should care
Email sending platforms offer dedicated IP addresses as a premium feature. The pitch is that you control your own reputation instead of inheriting whatever the shared pool is doing. The reality, for most service businesses, is that a dedicated IP is the wrong purchase.
A dedicated IP needs warmup the same way a domain does, and the warmup is harder because you cannot piggyback on the existing reputation of a shared pool. For a sender doing 30 emails a day, a dedicated IP will sit underused and never accrue enough positive signal to outperform a well-run shared pool. The minimum sustained volume where a dedicated IP makes sense is roughly 50,000 messages per month.
Our opinion: if you are reading a cold-email deliverability hub, you almost certainly do not need a dedicated IP. Spend the money on a good list verifier and a separate sending domain instead. Dedicated IPs matter for ESPs and enterprise senders, not operators booking five jobs a month.
The exception is if you are running outbound across a large agency or a multi-client platform. At that point the math flips and dedicated IPs per client become the cleaner setup. The volume threshold is what gates it.
DMARC enforcement: a 30-day plan
DMARC works in three policy modes. p=none reports failures but lets them through. p=quarantine routes failures to spam. p=reject blocks them. New senders should ramp through all three over 30 days. Skipping straight to reject on a fresh domain will block your own mail when DKIM has a hiccup.
| Week | DMARC policy | What you do |
|---|---|---|
| 1 | p=none; rua=mailto:you@domain.com | Collect aggregate reports daily, watch SPF and DKIM pass rates |
| 2 | p=none; pct=100 | Confirm 95%+ DMARC alignment on your own sends, fix any sender missing |
| 3 | p=quarantine; pct=25 | Quarantine a quarter of failures, watch for friendly-fire on your real mail |
| 4 | p=quarantine; pct=100 | Quarantine all failures, run for a week with zero alignment incidents |
| 5+ | p=reject; pct=100 | Reject all failures, the strongest signal to receiving servers |
Most cold senders never make it past p=none. That works for the first few months but caps your deliverability ceiling. The big inbox providers reward senders who reach p=reject with better default placement on borderline messages.
If you send through three different platforms (your inbox, a sequencing tool, and Resend for transactional), all three must DKIM-sign and SPF-align before you can safely move to reject. The aggregate reports will show you which provider is falling out of alignment. Fix that before tightening the policy.
Tools we actually use
You do not need a deliverability suite. You need four tools that cost almost nothing. Here is what is actually on the list.
| Tool | What it does | Cost |
|---|---|---|
| MXToolbox | DNS record lookups, blacklist checks, SMTP test | Free |
| Postmark | Transactional sending with strong reputation, useful as a clean baseline | $15+/month |
| Resend | Modern transactional API, easy DNS setup, good for app mail | Free under 3K/month |
| Mailcheck or ZeroBounce | List verification, catch-all detection, syntax cleanup | $10-30 per list |
| Google Postmaster Tools | Daily reputation, complaint rate, DMARC compliance for Gmail | Free |
| Microsoft SNDS | Per-IP filter results for Outlook, Hotmail, Live | Free |
Quick reviews. Postmark is the highest-reputation transactional ESP we have used and the support is excellent, but it bans cold outreach in its terms. Use it for password resets and receipts, not sequences. Resend is the modern alternative with a cleaner DX and works similarly well for app mail.
Mailcheck is the cheapest list verifier we trust. ZeroBounce is a bit more accurate on edge cases like role addresses and disposables, and it integrates directly with the LeadClaw agent for preflight verification. MXToolbox is the swiss-army-knife you open every time something looks off. Bookmark it.
A quick word on compliance
Deliverability is the technical layer. Compliance is the legal layer. They are related but not the same. CAN-SPAM in the US, CASL in Canada, and GDPR in the EU each impose rules on commercial email beyond what spam filters check. The short version is: identify yourself honestly, include a physical address, honor opt-outs within 10 days.
The full breakdown for small senders is at CAN-SPAM for small business. Read it once and bookmark the checklist. Most cold-email programs comply by default if the copy is short and the unsubscribe is real, but the few that do not get compliance complaints that hurt reputation worse than any spam filter would.
Where to go next
If you came here to set up a new sending domain, do these in order. SPF, DKIM, and DMARC first. Then warmup for six weeks. Then start cold sending. Then check Postmaster weekly. Most senders skip steps 1 and 2 and wonder why nothing is landing. Do not be most senders.
- Set up auth → SPF, DKIM, DMARC explained
- Run the warmup → the email warmup guide
- Avoid the new-domain traps → cold email new domain mistakes
- Audit a stalled campaign → the deliverability mistakes audit
- Understand spam routing → why cold emails land in spam
- Stay legal → CAN-SPAM for small business
Neighboring hubs that build on this foundation:
- Cold email for service businesses for what to send once the domain is healthy.
- Outreach scale playbooks for running at volume without breaking reputation.
- AI sales agents 101 for when an autonomous agent is doing the sending and you still own the deliverability.
Deliverability is unsexy. It is also the difference between a 0% reply rate and a 6% reply rate on the same copy. Get the foundation right once and you can spend the rest of your time on the list and the message. Skip it and nothing else matters.
Want the agent to handle DNS validation, warmup pacing, and Postmaster monitoring for you? That is what LeadClaw does in the background while you focus on which property managers to email this week. Set up an account and the deliverability checklist runs itself.
All posts in this cluster
6 guides on email deliverability.
7 Cold Email Mistakes That Will Destroy Your Deliverability
The seven most common cold email mistakes that tank inbox placement — and exactly how to fix each one before your domain gets blacklisted.
What Happens When You Send 100 Cold Emails a Day From a New Domain
Sending cold emails from a brand-new domain without warmup destroys your deliverability fast. Here's exactly what happens — and the right way to ramp up.
SPF, DKIM, DMARC Explained for People Who Aren't IT Admins
What SPF, DKIM, and DMARC actually are, why they matter for cold email deliverability, and how to set them up in under 15 minutes.
Why Your Cold Emails Land in Spam (And How to Fix It in 15 Minutes)
The most common reasons cold emails land in spam — and the 15-minute SPF, DKIM, and warmup fix that gets you back in the inbox.
CAN-SPAM for Small Business Owners: What You Actually Need to Know
CAN-SPAM compliance explained without the legalese. What contractors and service businesses actually need to do — and what's optional.
The Complete Guide to Email Warmup for Cold Outreach
What email warmup is, why it matters for deliverability, how long it takes, and best practices to protect your sender reputation.
Related topic hubs
Cold email for service businesses
Templates, sequences, subject lines, and timing playbooks for plumbers, roofers, HVAC, cleaning, landscaping, and other local service businesses sending outreach.
Outreach scale playbooks
Seasonal campaigns, vertical-specific playbooks, qualification systems, and operational tactics for running outreach at volume without losing reply quality.
AI sales agents 101
What an AI sales agent actually does, where it beats a sales rep, where it falls short, and how service businesses are getting real ROI from autonomous outreach.
Run outreach without the busywork
LeadClaw's AI agent finds leads, writes personalized cold emails, and follows up on autopilot. Start free.