
Cold email infrastructure is the set of domains, mailboxes and DNS records you send outbound email from, kept separate from the domain your company runs on. Done properly, it means a prospect's mail provider can verify who you are, your sending volume stays inside what each mailbox can carry, and a bad week of outreach can't damage the email your team and customers rely on.
This guide walks through the whole setup in the order we do it, with the rules quoted from Google, Yahoo and Microsoft rather than from the companies that sell mailboxes.
What is cold email infrastructure?
It's four things: sending domains, mailboxes on those domains, the DNS records that authenticate them, and a sending tool that spreads volume across them. Everything else, the list, the copy, the follow-ups, sits on top.
People usually start with the copy. We'd start here, because a good email from a domain nobody trusts goes to spam, and you never find out whether the copy was any good.
Why not send cold email from your main domain?
Because sender reputation belongs to the domain, and you only have one main domain. If a campaign draws spam complaints, the damage follows the domain it was sent from. On your main domain, that means invoices, password resets and replies to customers start landing in junk too.
Separate sending domains put a wall between the two. If one gets into trouble you can rest it or retire it, and the company's everyday email carries on untouched.
How do you choose and register sending domains?
Pick names a prospect would recognise as yours at a glance. If the company is acme.com, then getacme.com, tryacme.com or acmehq.com all work. Avoid hyphens, numbers and odd endings. A .com that reads naturally is worth the extra few dollars.
Three things to do with every domain once it's registered:
- Forward it to your main website, so anyone who types it in lands somewhere real.
- Register it under the company's own registrar account, not an agency's and not a mailbox reseller's. A warmed domain is an asset and should stay with you.
- Write down the registration date. A domain with a few weeks of history behaves better than one bought yesterday.
How many you need follows from volume, which we'll get to. Most teams start with three or four.
Google Workspace or Microsoft 365 for the mailboxes?
Either works, and plenty of teams run both so they aren't dependent on one provider. What matters is that they're real mailboxes from a mainstream provider, set up the way a new employee's would be.
The providers' own ceilings are far higher than anything you should send. Google's documentation gives a paid Google Workspace account 2,000 messages a day, with a cap of 3,000 external recipients, and only 500 a day on a trial account. Microsoft's Exchange Online limits allow 10,000 recipients a day per mailbox and 30 messages a minute.
Two Microsoft details catch people out. A trial tenant is capped at 5,000 external recipients a day across the whole organisation. And mail sent from the default onmicrosoft.com address is limited to 100 external recipients a day for the whole organisation, so connect your sending domain and send from that.
Give each mailbox a real person's name, a photo and a signature. A mailbox called sales1 looks like what it is.
Which DNS records does each sending domain need?
Three: SPF, DKIM and DMARC. Each sending domain needs its own set, and they go in the DNS settings at your registrar.
SPF lists which servers are allowed to send mail for the domain. For Google Workspace the record is a TXT record with the value v=spf1 include:_spf.google.com ~all. For Microsoft 365 it's v=spf1 include:spf.protection.outlook.com -all. Keep it to one SPF record per domain. If you add tools that send on your behalf, add them to the same record, and watch the count: the SPF standard allows at most 10 DNS lookups, and a record that goes over fails outright with an error.
DKIM signs each message so the receiver can check it wasn't changed on the way. You don't write this one by hand. Google's admin console generates a key that you publish as a TXT record, and Microsoft gives you two CNAME records to add. After publishing, go back and switch signing on. It's an easy step to miss, and DKIM stays off until you do it.
DMARC tells receivers what to do when a message fails both checks, and where to send reports. Start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com as a TXT record on _dmarc. The p=none setting means "report, but don't block", which lets you read the reports and fix anything that's failing before you tighten it.
One more rule sits across all three. The domain in your From address has to match the domain that passed SPF or DKIM. This is called alignment, and it's why the records go on the sending domain itself, not only on your main one.
What do Gmail, Yahoo and Outlook check before delivering?
Whether you are who you say you are, and whether people complain about your mail.
Google's sender guidelines ask every sender, at any volume, for SPF or DKIM, a TLS connection, and a spam rate under 0.3% in Postmaster Tools. Google's own advice is to stay under 0.10%. Once a domain sends more than 5,000 messages a day to Gmail, it also needs SPF and DKIM together, a DMARC record (which can be p=none), and one-click unsubscribe on marketing and subscribed messages.
Yahoo's requirements are close to identical, with one extra number: unsubscribe requests have to be honoured within two days. Microsoft applies the same 5,000-a-day threshold to Outlook.com addresses.
A well-run outbound setup never gets near 5,000 a day from one domain. Set up all three records anyway. It costs nothing, and mail that passes all three gets the benefit of the doubt that mail passing one doesn't.
How long should you warm up a new mailbox?
We allow at least two weeks, and usually three, before a mailbox carries real campaign volume. No provider publishes an official number. What they do is treat a brand-new sender with suspicion and relax as ordinary mail flows without complaints.
Warm-up means sending a small amount of normal mail and getting normal replies. Start with a handful of messages a day and raise it every few days. Send to people who will open and answer: colleagues, partners, your own other mailboxes. Subscribe the address to a newsletter or two so mail arrives as well as leaves.
This is also why setup and list building run side by side. The clock on a domain starts the day it's registered and authenticated, so we set up infrastructure first and build the list and the copy while it ages.
How many emails can each mailbox send a day?
We hold each mailbox to roughly 20 to 30 cold emails a day once it's warmed, and run two or three mailboxes per sending domain.
That is a long way under the provider limits above, and it's lower than the 30 to 50 you'll see in most guides from sending-tool vendors. The provider limit tells you when Google or Microsoft will stop you sending. It says nothing about when a recipient's filter starts to distrust you, and that arrives much sooner. A real person rarely sends more than a few dozen new conversations a day, so that's the pattern to look like.
The arithmetic is simple. Reaching 1,000 new contacts a week takes something like ten mailboxes across four domains. If your plan needs far more than that, the better fix is usually a tighter list.
How do you monitor deliverability once you're sending?
Watch three numbers every week, per domain.
Spam rate comes from Google Postmaster Tools, which is free and takes a DNS record to verify. Keep it under 0.10%. Bounce rate comes from your sending tool, and a rise means the list needs verifying again before you send more. Reply rate is the one that tells you whether anything upstream has gone wrong. When it drops across every campaign at once, the cause is usually placement and not the copy. Pulling the three numbers into one weekly report is easy to automate, and it's a typical job for our AI automation service.
When a number moves the wrong way, cut volume first and investigate second. A domain that rests for a couple of weeks often recovers. One that keeps sending at full volume while its reputation falls rarely does.
What does US law require in a cold email?
In the United States, the CAN-SPAM Act covers commercial email, and the FTC's guidance is direct about scope: the law makes no exception for business-to-business email.
In practice that means four things in every message. The header and subject line have to be accurate. The message needs your valid physical postal address. There has to be a clear way to opt out, and it must keep working for at least 30 days after you send. And an opt-out has to be honoured within 10 business days. Penalties run up to $53,088 for each email in violation.
Other countries are stricter, and the rules for the UK and the EU are different again. We aren't lawyers. If you send across borders, get advice on the countries you send to before the first campaign.
A setup checklist
- Register three or four sending domains under your own registrar account and forward each to your main site.
- Create two or three named mailboxes per domain on Google Workspace or Microsoft 365.
- Publish one SPF record per domain and check it stays under 10 lookups.
- Generate DKIM keys, publish them, then switch signing on.
- Publish a DMARC record at
p=nonewith a reporting address you actually read. - Verify each domain in Google Postmaster Tools.
- Warm each mailbox for two to three weeks with real, low-volume mail.
- Cap each mailbox at 20 to 30 cold emails a day and spread sends through working hours.
- Put a postal address and a working opt-out in every email.
- Review spam rate, bounce rate and reply rate every week, and cut volume when one slips.
Setting this up is half of an outbound system. The other half is the list, the offer and what happens to replies, which is the work our GTM and lead generation service covers end to end. If you'd rather automate the repetitive parts yourself, our n8n LinkedIn post generator shows the same approach on the content side, with the workflow file included.
Common questions
Do I need a separate domain for cold email?
Yes. Sender reputation is tied to the domain, so complaints about a cold campaign sent from your main domain also hurt the email your customers and team depend on. A separate sending domain keeps the two apart. If it runs into trouble you can rest or replace it without touching company email.
Can I use a subdomain instead of a new domain?
You can, but it protects you less. A subdomain like mail.acme.com builds some reputation of its own, yet receivers still connect it to acme.com, so serious problems can spread to the main domain. A separate domain that forwards to your website gives a cleaner separation, and domains are cheap.
What is the difference between SPF, DKIM and DMARC?
SPF lists the servers allowed to send mail for your domain. DKIM adds a signature to each message so the receiver can confirm it wasn't altered. DMARC tells the receiver what to do when a message fails those checks and where to send reports. You need all three, published on every sending domain.
Should DMARC be set to none, quarantine or reject?
Start at none. It asks receivers to report failures without blocking anything, so you can find and fix a misconfigured tool first. Once the reports show your legitimate mail passing for a few weeks, move to quarantine, which sends failures to spam. Reject is the strictest setting and suits a domain whose sending sources are fully known.
Does a cold email need an unsubscribe link?
It needs a clear way to opt out. Under CAN-SPAM that can be a link or a reply address, as long as it's easy and is honoured within 10 business days. Google and Yahoo require a one-click unsubscribe header only for bulk senders of marketing mail, above 5,000 messages a day. We include a plain opt-out line in every email.
What should I do if a sending domain gets flagged?
Stop cold sending from it straight away and keep only light, normal mail flowing. Check the SPF, DKIM and DMARC records, re-verify the list you were using, and look at what changed just before the drop. Give it two or three quiet weeks before you judge it. If it hasn't recovered by then, retire it and bring a warmed spare into rotation.
Want something like this built and run in your own accounts? That's what our GTM & Lead Generation service does. You can also see everything we build or look through our case studies.


