7 min readDan Mercer

    Setting Up Your Cold Email Infrastructure From Scratch

    Cold email infrastructure is a separate sending domain, a handful of warmed mailboxes, correct SPF, DKIM, and DMARC records, and a tight daily send limit per inbox. Here is the exact setup a founder can finish in an afternoon.

    Recap

    • Buy a separate sending domain (not your main one) and redirect it to your real site so cold-email risk never touches your core brand.
    • Create two or three mailboxes per domain, then set SPF, DKIM, and DMARC correctly. All three, or you land in spam.
    • Warm each mailbox for two to four weeks before real sends. New inboxes have no reputation and providers watch them.
    • Cap each mailbox near 20 to 50 sends a day. Scale by adding mailboxes, not by pushing one harder.

    Cold email infrastructure is the boring plumbing that decides whether your emails reach the inbox or rot in spam. At its core it is four things: a separate sending domain that redirects to your real site, a few mailboxes, the three authentication records (SPF, DKIM, DMARC), and a strict per-mailbox daily limit. You can stand all of it up in an afternoon. Here is the order to do it in.

    Why do you need separate infrastructure at all?

    Because cold email and your real business email carry different risk. Cold outreach goes to people who never asked to hear from you, so some will mark it as spam no matter how good the copy is. If that reputation damage lands on the domain that runs your billing, your password resets, and your customer support, one bad week can knock your whole company offline. Separation contains the blast radius.

    What sending domain should you buy?

    Buy a domain close to your real one, then point it at your main site with a redirect. If your company lives at acme.com, register something like getacme.com or tryacme.com. Set up a 301 redirect so anyone who types it lands on acme.com. This keeps the brand consistent while keeping the sending reputation walled off from your primary domain.

    Do not run cold campaigns from your bare primary domain even if it feels simpler. The redirect domain is cheap insurance, and you can retire and replace it if it ever gets burned.

    How many mailboxes, and on which provider?

    Create two or three mailboxes per sending domain, using real human names that match the people on your team. Google Workspace and Microsoft 365 are the two providers with the strongest inbox reputation, and most cold-email tools connect to either one cleanly. More mailboxes means more daily capacity without pushing any single inbox past a safe limit.

    Daily targetMailboxes neededPer-mailbox sends
    40220
    90330
    150350
    300650

    Notice the pattern. To go bigger, you add inboxes (and sometimes a second domain), you do not crank one mailbox to 200 a day. That is the fastest way to get flagged.

    What are SPF, DKIM, and DMARC, and how do you set them?

    These three DNS records prove you are allowed to send for your domain. Skip any one of them and modern mailbox providers will treat your mail as suspect. Add all three to your sending domain's DNS before you send a single message.

    • SPF. A TXT record listing the servers permitted to send for your domain. When you connect Google or Microsoft, they give you the exact value to paste in. One SPF record per domain, no more.
    • DKIM. A cryptographic signature added to every message so the receiver can confirm nobody altered it in transit. Your provider generates a key and gives you a record to publish. Turn it on in the admin console, then add the record.
    • DMARC. A policy that tells receivers what to do when a message fails SPF or DKIM, and where to send reports. Start with a relaxed policy (p=none) so you can watch the reports, then tighten to quarantine once you confirm legitimate mail passes.

    The 2024 bulk-sender rules from Google and Yahoo made all three effectively mandatory for anyone sending at volume. This is no longer optional hygiene.

    What does warmup do, and how do you run it?

    Warmup builds a sending reputation from zero by gradually increasing volume and generating positive engagement (opens and replies) before you send anything cold. A brand-new mailbox has no history, so providers are cautious. Most cold-email platforms include automated warmup that has your mailboxes exchange friendly messages with a pool of other inboxes. Turn it on the day you create the mailbox.

    Give it two to four weeks. Start at a trickle, climb slowly, and only layer real campaigns on top once the mailbox has been warming steadily and your early replies look healthy. Rushing this step is the single most common reason new founders end up in spam.

    What is the afternoon checklist?

    Here is the whole thing in order. Work top to bottom and you will have a clean foundation by the end of the day.

    • Register a sending domain close to your brand and set a 301 redirect to your main site.
    • Create two or three mailboxes with real human names on Google Workspace or Microsoft 365.
    • Publish SPF, DKIM, and DMARC records on the sending domain. Verify each one resolves.
    • Enable automated warmup on every mailbox immediately.
    • Set a per-mailbox daily cap (start near 20) and an automatic stop on bounces and complaints.
    • Wait two to four weeks, watch your DMARC reports, then begin real sends.

    That last waiting period is the part you cannot shortcut. Everything else is a few hours of clicking. If you would rather not babysit domains, warmup timers, and complaint thresholds by hand, an autonomous operator like LaunchSurface keeps the authentication, warmup, and per-mailbox limits in line on every send so you can stay focused on the conversations that come back.

    Frequently asked questions

    Why send from a separate domain instead of my main one?
    Cold email carries reputation risk. If a campaign draws spam complaints, you do not want that landing on the domain your invoices, support, and signed-in users depend on. A separate sending domain that redirects to your main site keeps the brand intact and quarantines the risk.
    How long does warmup actually take?
    Plan on two to four weeks before a fresh mailbox is ready for real volume. New domains and inboxes have no history, so mailbox providers watch them closely. Ramp slowly, keep early replies positive, and resist the urge to blast on day three.
    What is the difference between SPF, DKIM, and DMARC?
    SPF lists which servers are allowed to send for your domain. DKIM signs each message so the receiver can confirm it was not tampered with. DMARC ties the two together and tells receivers what to do when a message fails. You need all three.
    How many emails per mailbox per day is safe?
    Start near 20 and climb toward 30 to 50 once the mailbox is warm and complaints stay near zero. Scale by adding mailboxes, not by overloading one. The 2024 Google and Yahoo rules also cap bulk senders at a 0.3 percent spam complaint rate.
    Do I really need this if I am only sending a few emails a day?
    If you send a handful of genuinely personal emails from your normal inbox, you can skip most of this. The moment you run sequences or send to people who never asked to hear from you, the infrastructure is what keeps you out of the spam folder.

    Dan Mercer writes about outbound and go-to-market at LaunchSurface.

    DeliverabilityInfrastructureCold email