Recap
- Buy a separate sending domain (not your main one) and redirect it to your real site so cold-email risk never touches your core brand.
- Create two or three mailboxes per domain, then set SPF, DKIM, and DMARC correctly. All three, or you land in spam.
- Warm each mailbox for two to four weeks before real sends. New inboxes have no reputation and providers watch them.
- Cap each mailbox near 20 to 50 sends a day. Scale by adding mailboxes, not by pushing one harder.
Cold email infrastructure is the boring plumbing that decides whether your emails reach the inbox or rot in spam. At its core it is four things: a separate sending domain that redirects to your real site, a few mailboxes, the three authentication records (SPF, DKIM, DMARC), and a strict per-mailbox daily limit. You can stand all of it up in an afternoon. Here is the order to do it in.
Why do you need separate infrastructure at all?
Because cold email and your real business email carry different risk. Cold outreach goes to people who never asked to hear from you, so some will mark it as spam no matter how good the copy is. If that reputation damage lands on the domain that runs your billing, your password resets, and your customer support, one bad week can knock your whole company offline. Separation contains the blast radius.
What sending domain should you buy?
Buy a domain close to your real one, then point it at your main site with a redirect. If your company lives at acme.com, register something like getacme.com or tryacme.com. Set up a 301 redirect so anyone who types it lands on acme.com. This keeps the brand consistent while keeping the sending reputation walled off from your primary domain.
Do not run cold campaigns from your bare primary domain even if it feels simpler. The redirect domain is cheap insurance, and you can retire and replace it if it ever gets burned.
How many mailboxes, and on which provider?
Create two or three mailboxes per sending domain, using real human names that match the people on your team. Google Workspace and Microsoft 365 are the two providers with the strongest inbox reputation, and most cold-email tools connect to either one cleanly. More mailboxes means more daily capacity without pushing any single inbox past a safe limit.
| Daily target | Mailboxes needed | Per-mailbox sends |
|---|---|---|
| 40 | 2 | 20 |
| 90 | 3 | 30 |
| 150 | 3 | 50 |
| 300 | 6 | 50 |
Notice the pattern. To go bigger, you add inboxes (and sometimes a second domain), you do not crank one mailbox to 200 a day. That is the fastest way to get flagged.
What are SPF, DKIM, and DMARC, and how do you set them?
These three DNS records prove you are allowed to send for your domain. Skip any one of them and modern mailbox providers will treat your mail as suspect. Add all three to your sending domain's DNS before you send a single message.
- SPF. A TXT record listing the servers permitted to send for your domain. When you connect Google or Microsoft, they give you the exact value to paste in. One SPF record per domain, no more.
- DKIM. A cryptographic signature added to every message so the receiver can confirm nobody altered it in transit. Your provider generates a key and gives you a record to publish. Turn it on in the admin console, then add the record.
- DMARC. A policy that tells receivers what to do when a message fails SPF or DKIM, and where to send reports. Start with a relaxed policy (p=none) so you can watch the reports, then tighten to quarantine once you confirm legitimate mail passes.
The 2024 bulk-sender rules from Google and Yahoo made all three effectively mandatory for anyone sending at volume. This is no longer optional hygiene.
What does warmup do, and how do you run it?
Warmup builds a sending reputation from zero by gradually increasing volume and generating positive engagement (opens and replies) before you send anything cold. A brand-new mailbox has no history, so providers are cautious. Most cold-email platforms include automated warmup that has your mailboxes exchange friendly messages with a pool of other inboxes. Turn it on the day you create the mailbox.
Give it two to four weeks. Start at a trickle, climb slowly, and only layer real campaigns on top once the mailbox has been warming steadily and your early replies look healthy. Rushing this step is the single most common reason new founders end up in spam.
What is the afternoon checklist?
Here is the whole thing in order. Work top to bottom and you will have a clean foundation by the end of the day.
- Register a sending domain close to your brand and set a 301 redirect to your main site.
- Create two or three mailboxes with real human names on Google Workspace or Microsoft 365.
- Publish SPF, DKIM, and DMARC records on the sending domain. Verify each one resolves.
- Enable automated warmup on every mailbox immediately.
- Set a per-mailbox daily cap (start near 20) and an automatic stop on bounces and complaints.
- Wait two to four weeks, watch your DMARC reports, then begin real sends.
That last waiting period is the part you cannot shortcut. Everything else is a few hours of clicking. If you would rather not babysit domains, warmup timers, and complaint thresholds by hand, an autonomous operator like LaunchSurface keeps the authentication, warmup, and per-mailbox limits in line on every send so you can stay focused on the conversations that come back.
