Most cold email failures are not writing failures. The message never got read because it never reached an inbox — and by the time you notice, the damage to your domain is already done. This is the full checklist, ordered by how much each item actually affects whether you land.
Before you send anything
1
Use a separate sending domain. Not your main company domain. Something like yourcompany-outreach.com, about $12 a year. If deliverability ever degrades, your invoices, your client threads and your password resets are untouched. This single decision protects everything else you do by email.
2
Set up SPF, DKIM and DMARC on that domain. Three DNS records your sending provider gives you. They prove the mail genuinely comes from you. Without them, a large share of what you send is filtered before a human sees it — and no amount of good writing compensates. See
SPF, DKIM and DMARC explained.
3
Warm the domain up. A brand-new domain sending fifty messages on day one looks exactly like a spammer, because that is what spammers do. Start at a handful a day and climb over two to four weeks. See
email warm-up explained.
4
Verify your list. Sending to dead addresses produces bounces, and a high bounce rate is one of the fastest ways to get a domain flagged. Remove anything that does not resolve before the first send.
While you are sending
- Keep the volume low and the pace slow. Twenty or so a day, spaced twenty to thirty minutes apart, inside working hours. Bursts are the signature of automation.
- Send on weekdays only. Weekend sending hurts reply rates and reads as machine-driven.
- One message per company. Emailing three people at the same business in the same week is how you get reported rather than answered.
- Honour opt-outs immediately and permanently. Not just for this campaign — forever, across every campaign. This is both a legal obligation in most countries and a reputation protection.
- Watch bounces in real time. A sudden rise means your list has gone stale or something broke. Stop and fix it rather than pushing through.
What is in the message itself
- A real, working reply address that a human monitors.
- Your actual identity — name, business, and a way to verify you exist. Anonymous cold email is both less effective and, in most jurisdictions, unlawful.
- A plain way to opt out. One clear sentence beats a styled unsubscribe button that looks like bulk mail.
- No link shorteners, no tracking pixels, minimal links. Every one of those is a spam signal, and open-tracking pixels in particular are increasingly worthless since mail clients started pre-fetching them.
- Plain text, or as close as you can get. Heavy HTML templates are what marketing blasts look like. A cold email should look like a person wrote it, because one should have.
The order is the point
If you only do three things, do the first three: separate domain, authenticated records, slow warm-up. They account for most of the difference between landing and disappearing. Clever subject lines matter far less than people think, and matter not at all if the mail is filtered before delivery.
A useful mental model: deliverability is a reputation score attached to your domain, built slowly and lost quickly. Everything on this list either builds it or protects it. Nothing on this list is about persuasion — that comes after you have earned the right to arrive.
Common questions
How long before a new sending domain is ready for full volume?
Plan for two to four weeks of gradual increase. Start with a handful of messages a day and roughly double every few days, watching bounces and replies. Rushing this is the most common self-inflicted deliverability wound, and recovering a flagged domain takes far longer than warming one up properly.
Do I really need a separate domain, or is a subdomain enough?
A subdomain of your main domain shares some reputation with the parent, so problems can bleed across. A genuinely separate domain is the safer choice and costs about $12 a year. If you already send transactional mail from your main domain — invoices, receipts, password resets — treat that domain as something to protect rather than something to experiment with.
Why do my emails land in spam even though SPF and DKIM pass?
Authentication proves who sent the message, not that anyone wants it. If records pass and mail still lands in spam, the usual causes are: a cold domain with no sending history, volume that climbed too fast, a list with dead addresses producing bounces, content that looks like a marketing blast, or recipients marking earlier messages as spam. Work through those in that order.
Does open tracking hurt deliverability?
It can, and it has become close to useless anyway. Tracking pixels are an extra remote image request, some filters treat them as a signal, and privacy features in modern mail clients pre-fetch images automatically — which inflates open rates until they mean nothing. Replies are the only metric worth optimising for in cold outreach.