Resource

Cold email infrastructure checklist

Use this checklist to plan authentication, mailbox configuration, recipient hygiene and monitoring before launch. Timing depends on access, provider requirements and observed sending health; no warm-up duration guarantees inbox placement.

Editorial update:

Setup order
5 stages
Monitor before increasing volume
Gradual ramp
No form, no gate
Free

Work through it in order, not by priority

Infrastructure fails in sequence. Authentication that is published after warm-up starts means you warmed up an unauthenticated domain. A list verified after the first send means the bounce rate already happened. The order below is the order that avoids redoing work.

The three failures that account for most dead domains

Sending from your corporate domain, so one bad campaign damages company mail. Skipping or rushing warm-up, so volume arrives before reputation. And sending unverified lists, where bounce rate destroys placement faster than any content problem. Everything else on this checklist is a smaller margin than these three.

What to check after launch, not just before

Infrastructure is not a one-time build. Placement drifts, mailboxes degrade, and a provider changes something without telling you. Read your DMARC reports, watch bounce and reply rates per mailbox rather than per campaign, and rotate a mailbox out at the first sign of trouble instead of the third.

If you would rather not run this yourself

Use the linked service and pricing guides below to compare managed setup with doing the work in-house.

  • Email infrastructure setup: the service that delivers everything on this list, with domains registered in your name.
  • Cold email agency pricing: what managed sending costs, what is bundled and what is billed separately, with an editable cost model.

Action checklist

1. Domains

  • Use dedicated sending domains, never your corporate domain

    A reputation problem on a sending domain is replaceable; one on your company domain stops internal and customer mail.

  • Pick domains that look like your brand, not like spam

    Recipients check the sender domain, and a plausible variant of your brand survives that check.

  • Set up a real, minimal website on each sending domain

    A domain with no site attached is a weak signal to both filters and recipients.

  • Add a redirect or landing page to your main site

    Anyone who does look you up should reach something legitimate.

  • Record the registrar and renewal date somewhere shared

    An expired sending domain kills live campaigns silently.

2. Authentication

  • Publish SPF and keep it within the DNS lookup limit

    Too many includes make SPF fail even though the record looks correct.

  • Publish DKIM for every sending domain and every provider

    A domain that signs some mail and not the rest sends mixed signals.

  • Publish DMARC, starting at p=none with a reporting address

    You need the reports before you enforce, or you will block your own legitimate mail.

  • Actually read the DMARC reports

    Reports help identify authentication failures and unauthorized sending, alongside provider logs and delivery metrics.

  • Set up a custom tracking domain per sender pool

    Shared tracking hosts carry every other sender's reputation, including the bad ones.

  • Verify each record with a lookup tool before sending

    Typos in DNS are silent until deliverability collapses.

3. Mailboxes and warm-up

  • Derive mailbox count from target volume and a safe per-mailbox cap

    Two mailboxes carrying a whole campaign is the most common structural mistake.

  • Complete each mailbox's profile: name, photo, signature

    Empty profiles read as automation to both filters and humans.

  • Warm up on a ramp curve, not a flat daily number

    Reputation is built by a pattern, and a sudden jump looks like a compromised account.

  • Check inbox placement during warm-up

    A mailbox that warms into the spam folder is not warmed.

  • Keep per-mailbox daily volume deliberately conservative

    Headroom is what lets you absorb a bad week without losing the domain.

  • Keep a spare, warmed mailbox pool ready

    Rotation only works if there is somewhere to rotate to.

4. List hygiene

  • Verify every address before it enters a sequence

    Bounce rate damages placement faster and more durably than any copy choice.

  • Route catch-all domains to a separate, slower sequence

    Catch-alls accept everything, so they hide bounces you cannot see.

  • Dedupe against your CRM and existing conversations

    Contacting an open opportunity through a cold sequence costs more than the send.

  • Apply suppression and unsubscribe lists before every send

    Honor opt-outs consistently and confirm the requirements that apply to your recipients.

  • Include a working unsubscribe path

    Recipients who cannot leave report you instead.

  • Record where each row came from

    When a segment underperforms you need to know which source produced it.

5. Content and monitoring

  • Write plain-text-first email, one link at most

    Image-heavy, link-heavy templates trip filters and read like marketing.

  • Keep the first email short enough to read on a phone

    Most first reads happen on mobile, in a few seconds.

  • Watch bounce, reply and spam signals per mailbox, not per campaign

    Campaign averages hide the one mailbox that is failing.

  • Rotate a degrading mailbox out early

    Recovery is much cheaper than replacement.

  • Re-audit authentication after any provider change

    Changing mailbox or sending provider frequently invalidates DKIM or SPF.

  • Document the whole setup where the next person will find it

    Undocumented infrastructure becomes unmaintainable the moment someone leaves.

Who this helps

  • Founders setting up outbound email for the first time
  • SDR or growth leads inheriting infrastructure nobody documented
  • RevOps teams auditing why placement dropped
  • Agencies standardising setup across clients

Work through the process

  1. 01

    Plan volume first

    Mailbox and domain count follow your target volume and safe per-mailbox limits — decide volume before buying anything.

  2. 02

    Provision and authenticate

    Domains, mailboxes, SPF, DKIM, DMARC and a custom tracking domain, all validated before any sending.

  3. 03

    Warm up

    Ramp each mailbox on a schedule and check placement rather than assuming it.

  4. 04

    Clean the list

    Verify, separate catch-alls, dedupe against CRM and suppression lists.

  5. 05

    Launch small, then read

    First sequence at low volume, placement and bounce read, then increase.

  6. 06

    Monitor and rotate

    Per-mailbox metrics, DMARC reports and a rotation plan you use early.

Tools for this workflow

Questions and answers

How long does this take end to end?
Timing depends on DNS access, verification and provider requirements. Validate authentication before sending and increase volume gradually while monitoring errors and complaints. There is no universal two-week readiness rule.
How many domains and mailboxes do I need?
It follows your volume target divided by a conservative per-mailbox daily cap, not a fixed rule. Decide the volume first; the counts fall out of that.
Do I need a paid warm-up tool?
Not necessarily. What matters is a gradual ramp, genuine engagement and placement checks. Tools automate that; discipline is the actual requirement.
Can I run cold email from my main domain if volume is low?
You can, and we would still advise against it. The downside is asymmetric: a small gain in setup time against the risk of damaging the domain your business runs on.
What should I check first if placement has already dropped?
Authentication records, bounce rate per mailbox and whether volume increased recently. Those three explain most sudden drops before content is worth examining.
Do you set this up for clients?
Yes — it is our email infrastructure setup service, and the domains are registered in your name so you keep them.

Sources and editorial notes

Editorial checklist with illustrative operating guidance. Read the linked provider requirements for current authentication and sender rules; this page does not guarantee deliverability.

Keep reading