How to Set Up Cold Email Infrastructure So You Don't Get Flagged in Week One

A domain that gets flagged in week one is almost never a bad email. It's a skipped setup step. Here's the full sequence, built as a checklist you rerun for every new domain.

Anshul
Anshul Bhatia
Founder
July 14, 2026 · 6 min read

A domain that gets flagged in its first week almost never got flagged because of the email. It got flagged because a setup step got skipped. Bad reputation is an infrastructure problem wearing a copywriting costume.

So this is the full sequence, in order, from buying domains to the go/no-go test that decides whether you're allowed to send anything real yet. Every section maps to one line of a checklist. Save it, because you don't run this once. You rerun it for every new domain and every new client you launch.

Buy separate sending domains, never your main one

The first rule is the one people break because it feels paranoid. Never send cold email from your primary domain. If cold outreach damages a domain's reputation, and early on it sometimes will, you do not want that domain to be the one your invoices and your team's real email run on.

Buy separate domains for sending. Close variants of your brand work well, the kind a recipient still recognizes as you. Point each one at your real site with a redirect so it isn't a dead address. Then treat these as what they are: disposable infrastructure you can burn and replace without touching the domain your business actually depends on.

Set up the DNS records before a single send

Three records decide whether mailbox providers trust you: SPF, DKIM, and DMARC. Skip any of them and you're telling Google and Microsoft you didn't bother to introduce yourself.

SPF says which servers are allowed to send for your domain. DKIM signs your mail so the receiver can confirm it wasn't tampered with. DMARC tells the receiver what to do when a message fails those checks, and it's the one people set wrong. Publish DMARC at p=none to start. That's the monitoring setting: it asks receivers to report on your mail without punishing anything yet. You tighten it later, on evidence, not on day one. Getting all three right before your first send is the difference between arriving as a known sender and arriving as a stranger.

Create mailboxes, and keep the count per domain sane

Each sending domain holds a small number of mailboxes, not a pile of them. Stacking a dozen mailboxes onto one domain and blasting from all of them is the pattern spam filters were built to catch. A handful per domain, each a real-looking human address, is the shape of legitimate mail.

Set a display name and a signature on every mailbox. An empty, nameless inbox reads as automation, and automation is what you're trying not to look like. This is also where the multi-client math shows up for agencies: more clients means more domains, not more mailboxes crammed onto the domains you already have. Spread the load. Density is the tell.

Warm up before you send anything real

A brand new mailbox that sends fifty cold emails on its first morning is a mailbox asking to be flagged. Reputation is built by behaving like a real person before you behave like a campaign.

Warmup means starting with a trickle, a few sends a day of low-stakes mail that gets opened and replied to, and ramping the volume gradually over a couple of weeks. The exact ramp matters less than the principle: slow, consistent, and boring. You're teaching the mailbox providers that this address sends mail people want. Rush it and you've taught them the opposite, which is a lesson they remember far longer than it took you to skip.

Tighten DMARC only after you've read the reports

Remember p=none. Now it earns its keep. With DMARC in monitoring mode, receivers send you aggregate reports on what's passing and failing under your domain. Read them. Watch for a stretch, roughly a month, where your legitimate mail is authenticating cleanly and nothing surprising is failing.

Only then do you tighten. Move to p=quarantine, which sends failing mail to spam rather than rejecting it, and watch again. When that's clean, move to p=reject. Tightening the policy before you've watched the reports is how people accidentally send their own legitimate mail to spam and spend a week wondering why replies dried up. The policy progression is a decision you earn with data, in that order.

Run a go/no-go test, and rerun it every launch

Before real prospects see anything, run one deliverability test: send to a set of seed inboxes across the major providers and confirm you're landing in the inbox, not spam or promotions. This is your gate. Inbox placement is go. Anything else is no-go, and no-go means you fix the setup and test again, not send anyway and hope.

The part everyone treats as optional: this isn't a one-time check. It's a repeatable gate you rerun before every new domain and every new client goes live. The domain you warmed correctly last quarter tells you nothing about the one you spun up yesterday. Same gate, every launch.

The checklist

This is the artifact. Run it top to bottom for every new sending domain.

  1. Separate sending domains bought, none of them your primary domain.
  2. Each sending domain redirects to your real site.
  3. SPF record published and correct.
  4. DKIM signing enabled and verified.
  5. DMARC published at p=none to start.
  6. A sane number of mailboxes per domain, each with a display name and signature.
  7. Every mailbox warmed with a slow, consistent ramp before real sending.
  8. DMARC aggregate reports read across a clean monitoring window.
  9. DMARC tightened to p=quarantine, then p=reject, only after the reports were clean.
  10. Go/no-go seed test passed, landing in the inbox, before any real prospect is emailed.
  11. The whole gate rerun for the next domain, not assumed from the last one.

If you can't tick every line, you're not flagged yet because you haven't sent yet. That's the only good time to find out.

Frequently asked questions

Why can't I send cold email from my main domain?

Because if cold outreach damages reputation, and early on it can, you don't want that to hit the domain running your invoices and internal email. Separate sending domains are disposable infrastructure you can replace without touching the domain your business depends on.

What DMARC policy should I start with?

Start at p=none, the monitoring setting, so receivers report on your mail without punishing failures. Read those reports across a clean window, then tighten to p=quarantine and finally p=reject. Setting reject on day one risks sending your own legitimate mail to spam.

How long does cold email infrastructure setup take?

There's no single number because two clocks run for most of it: warmup, which takes a couple of weeks of gradually ramping volume, and DMARC monitoring, which needs roughly a month of clean reports before you tighten the policy. Since the go/no-go test only runs after both finish, budget close to a month before your first real prospect gets an email.

How many mailboxes do I need for cold email?

There's no fixed number, because the right count depends on your volume and how many domains you're running. The rule that matters more: keep it a handful per domain, never a pile. Stacking many mailboxes onto one domain is the exact density pattern spam filters are built to catch. Running multiple clients or campaigns means adding more domains, not cramming more mailboxes onto the ones you already have.

Can I skip warmup if I'm using a warm list?

No. Warmup builds the mailbox's own reputation with providers like Google and Microsoft, and that reputation is judged by how the sending address behaves, not by who is on your list. A brand new mailbox blasting fifty emails on day one looks the same to a spam filter whether the recipients are cold strangers or an engaged, opted-in audience. The address still has to earn trust first.

What happens if my domain gets flagged anyway?

You retire it. Sending domains are built to be disposable specifically so a bad reputation doesn't become a permanent problem: buy a new one, run through the same setup sequence, DNS through warmup through the go/no-go test, and don't skip a line this time. A flagged domain isn't a crisis if it was never your primary domain in the first place. It's the exact scenario separate sending domains exist to absorb.

Supporting

  1. Cold Email Infrastructure Setup: How to Build a Deliverability-First Sending System in 2026 (Cleverly)
  2. Domain Warmup Guide 2026: Prepare New Domains for Cold Email (Modern Inbound)
  3. How Long to Warm Up a Cold Email Domain: The 2026 Operator Answer (Reachly)
  4. Email Warmup Guide: How to Warm Up Accounts Before Cold Outreach (Built For B2B)
Written by
Anshul

Anshul Bhatia

Founder
IIT Kharagpur. Builds GTM systems for B2B SaaS.

Anshul builds the outbound systems behind Lead Line Partners. Clay workflows, AI enrichment, and research-first sequencing for teams that want more with less.

More posts
GTM ToolkitListicle · 17 min read

Cold Email Deliverability FAQ: The Questions Every Outbound Team Asks

A working FAQ pulled from the deliverability questions outbound teams actually ask mid-campaign: authentication, warm-up, spam triggers, list hygiene, and blacklist recovery, with the honest gaps left honest.

By Anshul Bhatia
GTM ToolkitGuide · 13 min read

What Belongs in a Cold Outbound Data Stack (And What's Redundant)

Most 'what's in your stack' content is written by someone selling a piece of it. Here's the four-job test for what belongs in a cold outbound data stack, and the layers most teams keep paying for twice.

By Anshul Bhatia
GTM ToolkitPricing · 16 min read

What a Real Cold Outbound Stack Costs in 2026 (Full Line-Item Breakdown)

Every cold outbound cost breakdown online prices one layer of the stack. This one prices all four, including the labor that actually runs it, sourced from vendor pricing pages and one disclosed survey.

By Anshul Bhatia

Ready to engineer your GTM motion?

Tell us how your motion runs today. We'll show you what we'd engineer.

Contact us