Cold email that lands, from a domain you just bought
Your cold email probably isn't failing because of the writing. It's failing because a domain you bought last month has no reputation, three DNS records are missing, and you sent forty on the first day. This page has SPF, DKIM and DMARC in plain words, what Google and Microsoft actually require now, a week-by-week warm-up and send-cap planner, three sequences that work, and the reason a reply has to stop everything.
Here is the sequence of events that produces almost every "cold email doesn't work" conclusion. A founder buys a domain on Monday, sets up a mailbox on Tuesday, exports two hundred addresses on Wednesday and sends them all on Thursday. Nothing comes back. There is no error, no bounce, no warning — a large share of those emails were quietly filed in spam folders, and spam folders are not a place anyone looks. The founder concludes the message was wrong and rewrites it. The message was never read.
Mailbox providers decide where your email goes largely on the reputation of the domain it came from, and a domain nobody has ever received mail from has no reputation at all. It isn't trusted and it isn't distrusted — it's unknown, and unknown plus two hundred messages in one afternoon looks exactly like the thing spam filters were built to catch. The fix is not better copy. It's three DNS records, three weeks of patience and a daily number small enough to look like a person.
The rest of this page is that, in order, checked against Google's and Microsoft's own published requirements rather than against other people's summaries of them. That matters more than usual here: the rules changed in February 2024, changed again for Outlook in May 2025, and Gmail moved from delaying non-compliant mail to permanently rejecting it in November 2025. A guide written before any of those is not slightly out of date; it is describing a system that no longer exists.
SPF, DKIM and DMARC, in plain words
Email was designed without any way of proving who sent a message. Anyone can put anything in the From: line — that's not a bug being fixed, it's how SMTP works. The three records below are the layer bolted on top to answer three different questions, and they only work together. All three are free, all three are DNS entries you add once at your registrar, and all three take about fifteen minutes.
SPF — which servers are allowed to send as you
A public list of the servers permitted to send mail using your domain. The receiving server looks at where the message actually came from and checks it against that list. It is one TXT record on the domain itself, and it looks like this for Google Workspace:
v=spf1 include:_spf.google.com ~allEvery service that sends on your behalf needs to be in it — your mailbox provider, your sending tool, your invoicing software. Three things break SPF and all three are common: having two SPF records (that fails outright — merge them into one), exceeding ten DNS lookups (each
include:costs at least one, and going over produces a permanent error that fails the check), and forgetting a service, so half your legitimate mail fails. The ending is either~all(softfail — everything else is suspicious) or-all(hardfail — reject everything else). Start with~alland tighten to-allonce you're certain the list is complete.SPF's weakness: it checks the invisible envelope sender, not the From: address a human reads. On its own it proves very little, which is why DMARC exists.
DKIM — a signature that proves the message wasn't altered
Your sending server signs each message with a private key; the matching public key sits in DNS, and the receiver verifies the signature. If it verifies, the message genuinely came from something holding your key and hasn't been changed in transit.
You generate it in your mail provider's admin console rather than writing it by hand. Google Workspace publishes it at the selector
google._domainkey.yourdomain.com. Use a 2048-bit key — 1024 is still offered in places and is no longer considered adequate. The one thing people get wrong is generating the key and never switching signing on, which leaves a valid public key in DNS and unsigned mail going out.DKIM survives forwarding, which SPF does not, so it's the stronger of the two and the one worth getting right first.
DMARC — what to do when the first two fail, and who to tell
DMARC ties SPF and DKIM to the From: address a human actually sees. That link is called alignment: it isn't enough for SPF or DKIM to pass, they have to pass for the domain in the From: header. Without alignment, a spammer can pass SPF for their own domain while writing your name in the From: line. DMARC closes that.
One TXT record at
_dmarc.yourdomain.com:v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comThe
p=policy tells receivers what to do with mail that fails:nonemeans deliver it anyway but report,quarantinemeans put it in spam,rejectmeans refuse it at the door.rua=is where the daily aggregate reports go — XML files from every major provider telling you exactly what is being sent using your domain, including by people who aren't you.Start at
p=none. It is the minimum every provider now asks for and it is genuinely a monitoring mode — it changes nothing about delivery while you find out whether your own mail passes. Read the reports for a month, fix whatever fails, then move toquarantineand eventuallyreject. Going straight top=rejectbefore you know what sends as your domain is how a business discovers it has been silently destroying its own invoice emails.
What Google and Microsoft actually require now
Both have published sender requirements with two tiers: things every sender must do, and extra things demanded of high-volume senders. The threshold in both cases is 5,000 messages a day — to personal Gmail accounts for Google, to Outlook.com, Hotmail.com and Live.com addresses for Microsoft. A one-person business sending thirty a day is nowhere near it, which leads to the most common misreading of these rules: that they don't apply to you. The requirements don't; the filters absolutely do, and the requirements are simply the published version of what the filters were already rewarding.
| Requirement | Every sender | 5,000+ a day | Detail |
|---|---|---|---|
| SPF or DKIM | Required | Both required | Google has required at least one of the two from every sender since 1 Feb 2024. |
| DMARC record | Recommended | Required, minimum p=none | Google and Microsoft both accept p=none as the floor. Neither yet demands enforcement. |
| From: alignment | — | Required | The From: domain must align with the SPF domain or the DKIM domain. |
| Forward and reverse DNS | Required | Required | Your sending IP needs a valid PTR record that resolves back. Your provider handles this on shared infrastructure. |
| TLS in transit | Required | Required | Every sending service does this by default now. |
| RFC 5322 message format | Required | Required | Standard headers, a real Message-ID, no impersonating gmail.com in From:. |
| One-click unsubscribe | — | Required (marketing) | Google: List-Unsubscribe plus List-Unsubscribe-Post: List-Unsubscribe=One-Click (RFC 8058), honoured within two days. Microsoft asks for a visible, working opt-out but has not mandated the one-click header. |
| Spam rate | Below 0.30% | Below 0.10% | Google's wording: keep it below 0.10% and never let it reach 0.30% or higher. Measured daily in Postmaster Tools. Microsoft has published no equivalent number. |
Three things about that table matter more than the rest, and none of them is in most guides.
Gmail now permanently rejects, not just delays
Google's own FAQ: "Starting November 2025, Gmail is ramping up its enforcement on non-compliant traffic. Messages that fail to meet the email sender requirements will experience disruptions, including temporary and permanent rejections." The distinction is the whole game. A temporary failure — a 4.x.x code — means your sending tool retries and the message eventually arrives. A permanent one — 5.x.x — means it is gone, and unless you read your bounce log you will never know. Microsoft went the same way from 5 May 2025, starting by routing non-compliant mail from high-volume senders to Junk, with outright rejection promised for persistent offenders and a specific error waiting for them: 550 5.7.515 Access denied, sending domain does not meet the required authentication level.
Bulk sender status, once earned, never expires
Also from Google's FAQ: "Bulk sender status doesn't have an expiration date. Email senders that have been classified as bulk senders are permanently classified as such." One enthusiastic afternoon over the threshold and the stricter tier applies to your domain for good. For a small business this is an argument for never testing the ceiling — there is no route back.
The rules mostly don't apply to the people you're emailing
This is the one worth sitting with if you sell B2B. Google states plainly that the sender guidelines "don't apply to messages sent to Google Workspace accounts" — enforcement covers personal Gmail addresses only. Almost every business you cold-email is on Workspace or Microsoft 365, so the published rules technically govern very little of your outbound. What governs it instead is the ordinary spam filtering on those tenants, which is if anything stricter, less predictable, and configured by an IT person who doesn't like you. Meeting the bulk-sender requirements is still the right thing to do; it just isn't why. You do it because passing authentication is the price of being considered at all.
Warm-up and send-cap planner
Tell it how old the sending domain is and how big the list is, and it lays out the weeks: when to send nothing, when to warm up, what the daily cap is on each rung, and the date the last person on the list gets their last email. The caps are the ones that keep a small sender under the filters, not the published provider limits — Google Workspace allows 2,000 external recipients a day on a paid account and 500 on a trial, and neither number is remotely relevant, because filtering engages long before either.
- First live send
- Week 4 Week beginning Mon, Oct 26, 2026. Everything before it is warm-up, and warm-up means real messages to people who reply.
- Whole list contacted
- Week 7 Last first-email lands the week ending Fri, Nov 20, 2026. The final follow-up in the sequence goes out around Wed, Dec 2, 2026.
- Emails in total
- 360 120 companies × 3 emails. Every follow-up costs a send, which is the arithmetic people forget when they plan a list against a daily cap.
| Week | Phase | Daily cap | Sends | New companies | What you're doing |
|---|---|---|---|---|---|
| 1 Oct 5–Oct 9 | Rest | 0 | 0 | — | SPF, DKIM and DMARC in. Mailbox created, signature and a real reply-to. Send nothing at all. |
| 2 Oct 12–Oct 16 | Warm-up | 5/day | 25 | — | Warm-up only — real messages to people who will reply. Suppliers, your accountant, your own other accounts. |
| 3 Oct 19–Oct 23 | Warm-up | 15/day | 75 | — | More of the same, plus a placement test: send to a Gmail and an Outlook address you own and check where it lands. |
| 4 Oct 26–Oct 30 | Live | 8/day | 39 | 13 | First live sends. Hot leads only — the ones most likely to reply, because replies are the signal that builds reputation. |
| 5 Nov 2–Nov 6 | Live | 16/day | 78 | 26 | Ramping. Check bounces before increasing again; stop here if they're over 2%. |
| 6 Nov 9–Nov 13 | Live | 24/day | 120 | 40 | Ramping. Watch for anything that looks like a complaint — an unsubscribe is fine, a 'stop emailing me' is a warning. |
| 7 Nov 16–Nov 20 | Live | 30/day | 123 | 41 | Cruising speed. Thirty a day per mailbox is the practical cold ceiling for a small sender; going past it buys risk, not leads. |
Weekdays only, five sending days a week, spread through the working day rather than fired at 9am. The caps are per mailbox and are what keeps a small sender under the filters — not the published limits, which are far higher (Google Workspace allows 2,000 external recipients a day on a paid account) and irrelevant, because filtering engages long before them. Three numbers override every row of this table: bounces over 2%, any complaint at all, or a placement test landing in spam. Any of those and you stop, fix the list, and restart a rung lower. Nothing typed here leaves your browser.
The ramp is deliberately conservative and the arithmetic includes follow-ups, which is the part most plans miss: a list of 120 with a three-email sequence is 360 sends, not 120. If the planner says the list takes longer than you'd like, the fix is a shorter list or a shorter sequence — not a higher daily number.
Three sequences that work, and the email inside them
Follow-ups are not optional and they are not nagging. In the 2026 analysis of 53 million cold emails, 44% of all positive replies came from follow-ups rather than the first message, and the first follow-up alone accounted for about a quarter of every positive reply received. A founder who sends one email and stops throws away roughly half of what the list was worth. Four to seven touches is the range that keeps paying; past seven, you're annoying people for a rounding error.
Three shapes cover almost everything a small business needs. Pick by what you know about the company, not by what you're selling.
- The partner sequence · 4 touches, 18 days
- For companies you researched and scored warm or hot, where the ask is an ongoing relationship rather than a sale. Days 0, 4, 11, 18. Each email adds something new; the last one closes the loop politely and stops.
- The trigger sequence · 2 touches, 7 days
- For a company where something just happened publicly — a vacancy posted, a second location, an award, a review complaining about the exact thing you fix. Send within a week of noticing it, reference it in the first line, and stop after one follow-up. The trigger is the whole permission.
- The one-shot · 1 touch, no follow-up
- For the tail of the list, and for anyone you couldn't research. Three sentences, sent once, never followed up. Low expectations and near-zero risk. If you can't write a specific first line, this is the honest version of what you were going to send anyway.
Northline Bike Repair runs the partner sequence at thirty-five Denver bike shops. Here is the whole thing for one of them — the shop from the qualification example, which has had a mechanic vacancy open since July.
Day 0 · the first email
Subject: your mechanic vacancy
Dana — you've had a bike mechanic role open since July. I'm a mobile one you don't have to hire.
I'm Sam, I run Northline Bike Repair: a van, a full workstand, tune-ups at people's homes across Denver. When April hits and your bench is three weeks deep, I can take the overflow — you book it, I do it, the customer stays yours and so does the margin.
Worth ten minutes on the phone this week?
Sam
Northline Bike Repair · 720 555 0148
Seventy-four words. The subject is three, one shorter than the four-to-five that tests best, and it earns the exception by being entirely about them and containing no pitch. The first line is a fact about their business that could not have been written to anyone else — that sentence is the whole reason this gets read. One question, no attachment, no calendar link, one phone number, no tracking pixel.
Day 4 · the follow-up that adds something
Forgot to say: I did 41 tune-ups in April last year and turned six of them around same-day. Happy to do a trial week in March so it isn't a leap of faith in April.
Sam
Two sentences, new information, no "just bumping this to the top of your inbox". A follow-up that adds nothing is a reminder that you want something.
Day 11 · the different angle
Dana — different thought. If overflow isn't the problem, house calls might be: I do the ones customers won't bring in — the bike in the garage with a seized cassette. I'd pay you a referral on those rather than the other way round.
Sam
Changes what's being offered instead of repeating it. If the first premise was wrong, this is the email that finds out.
Day 18 · the close
No reply needed — I'll assume the timing's wrong and stop here. If spring gets away from you, my number's below and I'll pick up.
Sam
Northline Bike Repair · 720 555 0148
Says it's the last one and means it. This email reliably produces replies — partly because people respond to a door closing, and mostly because it's the only one in the sequence that asks for nothing.
The specifics that the data supports, briefly: under 80 words for a first email; a four- or five-word subject; a soft ask ("worth ten minutes?") rather than a hard one ("book here") — soft calls to action produced 78% more positive replies in the same 2026 analysis. Plain text, no images, no tracking pixel, at most one link, and never a link in the first email if you can avoid it. Everything you add to make it look professional makes it look like marketing, and marketing is what the filter is looking for.
A reply has to stop the sequence
This is the single rule most likely to be broken by a founder doing outreach by hand, and it does more damage than any DNS mistake. Someone answers your first email — "thanks, not right now" — and four days later your scheduled follow-up arrives asking whether they saw the last one. You have now proved, in writing, that nobody read their reply. That is worse than never having emailed them, because it converts a polite no into a person who tells other people about you.
Every reply stops everything, regardless of what it says. Interested, not now, wrong person, or a flat no — all four remove that address from every remaining touch in the sequence, immediately, and add it to a suppression list that every future campaign checks before it sends. So does an out-of-office, until the date it says they're back. So does a bounce, permanently and after a single occurrence.
- Any reply
- Out of the sequence at once, into a human conversation. The whole point of the sequence was to start one; continuing it afterwards is a machine talking over a person.
- An unsubscribe or a 'stop'
- Suppressed permanently, across every list you will ever build. In the US, CAN-SPAM gives you ten business days; there is no reason to use nine of them, and a second email after a stop is the one people report.
- A hard bounce
- Removed after one. Repeatedly sending to a dead address is the clearest possible signal that you didn't verify your list, and it's the cheapest signal for a provider to act on.
- An out-of-office
- Paused until the return date, then resumed. Treating an auto-reply as engagement is how people end up with a follow-up that references a conversation that never happened.
- Someone else replying for them
- Suppress the original address, start again with the person who wrote — as a new first email, not as touch three of a sequence they've never seen.
The mechanical version of this is a suppression list that is checked at send time, not at list-build time, and that is global rather than per-campaign. The manual version is a spreadsheet column you update the same day. Either works; what doesn't work is intending to remember.
Cold email is regulated, and the rules differ by who you're writing to
Cold email is legal in the US and, to businesses, largely legal in the UK and EU. It is not unregulated in either, and the two regimes are built on opposite defaults: the US says you may email until told to stop, Europe says it depends entirely on whether the recipient is a company or a person. None of what follows is legal advice — it's the shape of the thing, and the shape is worth knowing before you send a thousand of anything.
- US · CAN-SPAM
- No opt-in required, and it explicitly covers B2B. What it does require: honest headers and From: line, a subject that reflects the message, a valid physical postal address in the email, a working opt-out, and that opt-out honoured within ten business days and never sold on. Penalties are assessed per email and the FTC's inflation-adjusted maximum is over $50,000 each, which is why the phrase 'per email' does the work in that sentence.
- UK & EU · PECR and GDPR
- PECR's electronic mail marketing rule doesn't apply to corporate subscribers — limited companies, LLPs and public bodies — so B2B cold email to them is permitted. It does apply to individual subscribers, and sole traders and unincorporated partnerships count as individuals, so they need consent or a soft opt-in. Either way you must not disguise your identity and must give a valid address to opt out.
- The bit people miss
- UK GDPR still applies to a named person at a company, because dave@company.com is personal data. You need a lawful basis (usually legitimate interests, which requires a documented balancing test), and you must be able to say where you got the address and honour a request to stop. The company being fair game under PECR doesn't make the person exempt from GDPR.
- Canada · CASL
- The strict one, and the reason to check before emailing north of the border: CASL requires express or implied consent before a commercial message, with real penalties. If Canadian companies are on your list, that's a conversation to have with a lawyer rather than a paragraph on a web page.
In practice, a small business writing to forty researched companies with a real name, a real address, an easy way to say stop and an actual reason for writing sits comfortably inside all of it. The businesses that get into trouble are the ones sending to bought lists at volume, and the legal exposure tends to arrive at the same time as the deliverability collapse, for the same underlying reason: nobody asked to hear from them and the sender didn't care.
Common questions
How long should I warm up a new domain?
Let it sit about a week after registration doing nothing, then two to three weeks of genuine low-volume conversation — five a day rising to fifteen — to people who will actually reply. Three to four weeks from buying the domain to the first cold send is the normal timeline. The signal that builds a domain's reputation is replies, not sends, so warm-up traffic that nobody answers achieves very little.
How many cold emails can I send a day?
Twenty to thirty a day per mailbox once the domain is warm, and eight to ten a day when you first go live. Google Workspace's published limit is 2,000 external recipients a day on a paid account and 500 on a trial, but that number is irrelevant — filtering engages long before it, and a small sender who reaches for the published ceiling finds out about it in a spam folder rather than a bounce message.
Do I need SPF, DKIM and DMARC if I only send thirty emails a day?
Yes. Google's and Microsoft's stricter requirements start at 5,000 messages a day, but SPF or DKIM has been required of every sender to Gmail since February 2024, and the filters that decide where a small sender's mail goes were rewarding all three long before either company wrote them down. All three are free, take about fifteen minutes, and are the cheapest thing you can do for deliverability by a wide margin.
Should I use a separate domain for cold email?
Probably not, at small volume. At twenty to thirty a day to companies you have actually researched, sending from your real domain is better: recipients can verify you exist, and the reputation you build is on the domain that matters. A separate domain is what agencies use because they send thousands and expect to burn domains periodically. The honest test is this — if your volume is low enough that your real domain is safe, you don't need a second one; if it's high enough to need one, you're doing the thing that burns domains.
What reply rate is normal for cold email?
Three to four per cent across all campaigns — two independent 2026 analyses put the average at 3.4% and 3.7%. Small hand-researched lists do considerably better, and 10–20% is achievable when every first line is specific to the company. Top campaigns book two to three meetings per hundred emails sent. If you're under 1%, the list is wrong before the copy is.
Why do my emails go to spam even though SPF and DKIM pass?
Authentication gets you considered, not delivered. After that it's domain reputation (new domains have none), volume patterns (forty on the first day looks automated), engagement (nobody replying is itself a negative signal), bounces (over 2% and you look careless), complaints, and content — images, multiple links, a tracking pixel and marketing language all push a message towards the promotions tab or worse. The most common cause for a small sender is simply that the domain is new and sent too much too soon.
Do I need an unsubscribe link on a cold email?
One-click unsubscribe is formally required for marketing mail from senders over 5,000 messages a day, so a small business isn't covered by that rule — but you must give people a way to stop under CAN-SPAM in the US and PECR in the UK, and it's in your interest anyway, because the alternative to an unsubscribe is a spam complaint and complaints do far more damage. A plain line at the bottom — 'reply stop and I won't write again' — reads better in a one-to-one email than a marketing footer, and works.
Is it worth using a cold email tool, or should I send by hand?
By hand, up to about thirty a day, is genuinely fine and produces better email — you write differently when you're looking at the person's website. A tool earns its place when you need scheduled follow-ups that stop on a reply, a suppression list that's checked at send time, and a record of who was touched when. That's the point at which manual sending starts failing quietly, usually somewhere past a hundred and fifty active names.
Paced, capped, and stopped by a reply.
Velofound sets up your business inbox, drafts outreach from leads it has already researched and scored, and sends it paced and capped so it doesn't land in spam. Anyone who replies drops out of the sequence automatically. Nothing sends without your approval. Free to start.
Start free →