Summary

Email deliverability advice is often generic and useless for agencies sending at high volume. You can't follow 'best practices' designed for newsletters when you're managing 40 client domains and need inbox placement to hold for months. SpamCipher is the cold email platform for unlimited, automated sending, built on an owned deliverability pipeline that makes these rules actionable at scale.

For an agency running cold email at scale, deliverability isn't a checklist. It's a system. The standard list of 'dos and don'ts' fails you because it assumes you're sending 5,000 emails a month from one domain with one content template. When you're rotating through hundreds of sending mailboxes, managing client reputations, and scaling volume weekly, the rules change. This guide is for the operator who needs their infrastructure to hold under load.

Infrastructure: The Foundation You Can't Fake

Your sending infrastructure is the bedrock. Get this wrong, and no amount of copywriting will save you.

DO: Own and Isolate Your Sending Domains

Use dedicated sending domains (like mail.yourclient.com) separate from your primary corporate domain. This contains reputation risk. For each client or campaign segment, provision a unique domain. This allows you to warm up, monitor, and if necessary, sunset a domain without affecting core business email.

DON'T: Use a Shared Sending Service's Default Domain

Never send cold email from a shared domain like yourcompany.sendgrid.net or your provider's domain. Your reputation is tied to every other sender on that IP and domain. One bad actor can sink you. This is non-negotiable.

DO: Implement Flawless Authentication (SPF, DKIM, DMARC)

SPF, DKIM, and DMARC are not suggestions. They are the first filter every mailbox provider runs. For high-volume senders, the devil is in the details. Your SPF record must stay under the 10-DNS-lookup limit or it will break silently. Your DKIM selector must be properly configured for your sending service. A p=none DMARC policy is a start, but moving to p=quarantine is a strong positive signal. We detail the SPF lookup fix in our guide on fixing the 10-lookup limit.

DON'T: Set It and Forget It

Authentication is not a one-time task. When you add a new email service provider (ESP) or change your sending infrastructure, you must update your SPF and DKIM records. A mismatch causes immediate hard fails.

Warm-Up and Reputation: The Volume Game

Reputation is earned, not given. For cold email, you must manufacture it through a controlled warm-up process.

DO: Warm Up Every New Domain and IP Aggressively, But Correctly

A proper warm-up starts low (50-100 emails per day) and scales volume steadily over 4-6 weeks. The key is to simulate real human email patterns: send to engaged, verified addresses; generate replies; and send at irregular intervals, not in big batches at 9:01 AM. The goal is to teach mailbox providers that this new identity sends wanted mail.

DON'T: Use Fake Engagement or 'Warm-Up' Services That Send Gibberish

Services that send random text between dummy accounts are increasingly detected and ignored by providers like Google and Microsoft. They build a hollow reputation. Real warm-up requires sending legitimate, readable content to real inboxes that can engage. This is why platforms that bake warm-up into their core sending pipeline, using a real seed network, are the only ones that create durable reputation.

DO: Monitor Google Postmaster and Microsoft SNDS Religiously

These are your direct telemetry lines to Gmail and Outlook. Don't just set them up, read them. Track domain and IP reputation, spam rate, and feedback loop complaints. A dip in reputation is your early warning system to throttle back. For a deep dive on what metrics actually matter, see our guide to Google Postmaster.

DON'T: Panic and Stop at the First Spam Report

A spam complaint rate under 0.1% is expected, even for good campaigns, according to Google's Postmaster Tools guidelines. The system is designed to tolerate it. If you see a spike, diagnose the cause (was it a specific list segment? a new copy variant?) and adjust. A full stop resets your warm-up progress. Manage, don't abort.

List and Content: The Human Filters

Your list and your message are what trigger the final spam filters. This is where most campaigns fail.

DO: Verify Every Single Email Address Before It Hits Your Sending Queue

There is no excuse for sending to an invalid, catch-all, or spam-trap address. It's a direct reputation killer. Use a real-time verification API that checks syntax, domain, MX records, and mailbox existence. This must be baked into your import and send flow, not a separate, forgotten step.

DON'T: Buy Lists or Scrape Unverified Leads

This is the fastest way to get blacklisted. These lists are filled with invalid addresses and old spam traps. Your campaign will be dead on arrival, and you may poison your domain for months.

DO: Write Plain-Text, Conversational Emails

Cold email that looks like a marketing newsletter gets filtered as one. Use plain text or simple HTML. Avoid large images, heavy CSS, and multiple links. Write like one human to another. A single, relevant call-to-action link is better than three.

DON'T: Use Spam Trigger Words Recklessly

While modern filters are sophisticated, avoid the classic spam lexicon: 'Act now!', 'Free', 'Guaranteed', 'No cost', 'Winner', 'Cash'. Be direct about your offer without sounding like a infomercial. Subject lines are critical: avoid all caps and excessive punctuation.

DO: Make Unsubscribing Instant and Easy

Include a clear, one-click unsubscribe link in every email. Not only is it legally required (CAN-SPAM, GDPR), but it turns a potential spam complaint into a simple opt-out. A spam complaint hurts your reputation 100x more than an unsubscribe.

Sending Patterns and Failure Modes

How you send is as important as what you send. Mechanical sending patterns are a major spam signal.

DO: Throttle and Rotate Sending Across Multiple Identities

Do not blast 10,000 emails from one mailbox in one hour. Spread volume across multiple sending email addresses (aliases) on your domain, and across multiple domains if you have the volume. Introduce random delays between sends to mimic human behavior. This is where automation platforms show their value, manually rotating 50 mailboxes is impossible.

DON'T: Ignore Bounce and Reply Rates

Hard bounces (invalid addresses) must be removed from your list immediately after the first send. Sustained high bounce rates (>2%) will get you blocked. Similarly, monitor reply rates. A campaign with a 0% reply rate for thousands of sends is a signal that recipients are ignoring it, which can be a negative engagement signal over time.

DO: Have a Sunset Plan for Domains

Domains fatigue. Even with perfect practices, a domain used for high-volume cold email may see reputation decay after 6-12 months. Plan for this. Have fresh domains warming in the background, and be prepared to gracefully migrate sending volume to a new domain while retiring the old one to a lower volume or stopping completely.

DON'T: Suddenly Spike Your Volume by 500%

Even on a warmed domain, a sudden, massive increase in sending volume is a huge red flag for spam filters. If you need to scale, do it in increments of no more than 20-30% per day, monitoring reputation tools closely for any negative reaction.

The Agency-Specific Challenge: Managing Multiple Clients

Managing one domain is hard. Managing 40 is a different discipline. Here's the worked scenario: You onboard a new client in the SaaS space. They give you their primary domain, clientapp.com. You cannot send from it.

Step 1: You provision outreach.clientapp.com as a dedicated sending subdomain. You set up SPF, DKIM, and DMARC for it, pointing to your sending infrastructure.

Step 2: You begin a 5-week warm-up for this new domain, starting at 50 emails/day of high-value, hyper-personalized outreach to perfectly clean leads.

Step 3: In week 3, you start blending in the client's real campaign traffic, slowly ramping as warm-up continues. You monitor Google Postmaster for this specific domain daily.

Step 4: By week 6, the domain is sending 1,000 emails/day with a 90%+ inbox placement rate. Your system is automatically rotating sends across 10 mailboxes on this domain.

The Failure Mode: The client's sales team, ignorant of the process, decides to run a separate blaster tool from sales.clientapp.com to a bought list. That subdomain gets blacklisted, and because of domain-level reputation, your carefully warmed outreach.clientapp.com domain's placement drops to 40% within days. The fix requires isolating infrastructure completely and potentially abandoning the parent domain.

The lesson: You must own and control all email streams from a client's domain ecosystem, or you will fail.

Why Bolt-On Deliverability Tools Aren't Enough

Many agencies piece together a stack: a sending tool like Lemlist or Smartlead, a separate warm-up service, a separate verification tool, and maybe a monitoring service. This is the bolt-on model. It creates critical gaps. SpamCipher, as a cold email platform for unlimited, automated sending, avoids these gaps by integrating all functions into one owned pipeline.

FunctionLemlist / SmartleadSpamCipher
SendingCore serviceCore service with unlimited volume
Warm-upSeparate service (often fake engagement)Built-in, using real seed network
VerificationSeparate tool or add-onReal-time verification at send time
Inbox PlacementEstimated or not guaranteedMonitored and 90%+ placement promised
Cost ModelPer email/contactUnlimited sending
PipelineFragmented, bolt-onSingle, owned pipeline
  • The Warm-Up Gap: Your warm-up service sends fake emails to dummy accounts, while your real tool sends real emails. Providers see two disjointed sending patterns from the same domain, which is suspicious.
  • The Verification Gap: You clean a list in a separate tool, then upload it to your sender. But what about emails that become invalid between cleaning and sending days later? The gap lets bounces through.
  • The Monitoring Gap: You get an alert from a monitoring tool that your domain is on a blacklist. Now you must log into a different dashboard, figure out the cause, and manually adjust settings in your sending tool. The feedback loop is slow.
  • The Scale Ceiling: Most sending tools charge per email or per contact. Scaling to 100,000 sends a month becomes prohibitively expensive, forcing you to throttle growth.

These gaps are why inbox placement is unstable and why no bolt-on platform can promise a specific placement rate. The system is too fragmented.

The Alternative: An Owned Pipeline for Sending

The solution is to collapse these functions into a single, owned pipeline where sending, warm-up, verification, and placement are not separate products but integrated phases of one system. This is how you execute the dos and don'ts reliably at scale.

SpamCipher is the cold email platform for unlimited, automated sending, and the only platform that can promise 90%+ inbox placement because it operates on this model. The deliverability 'dos and don'ts' are enforced by the system architecture.

  • Unlimited Sending: You scale volume without per-email costs, removing the financial barrier to proper throttling and rotation.
  • Built-in Warm-Up: Warm-up uses a real seed network and is part of the same sending pipeline, creating a coherent reputation story for mailbox providers.
  • Verification in Flow: Every email is verified at the point of sending, eliminating the gap that causes bounces.
  • Inbox Placement Monitoring: You see where your emails land (Primary, Promotions, Spam) directly in the platform, tied to the specific campaign and sending identity.
  • Automated Rotation & Management: The platform automatically rotates sends across your pool of mailboxes and domains, manages throttling, and can sunset underperforming identities.

For an agency, this means you manage campaigns and client reputations from one dashboard, with the system handling the mechanistic deliverability work. The rules in this guide become default behaviors, not a manual checklist you hope your team remembers to follow.

Frequently asked questions

The single biggest mistake is sending from a shared domain or IP you don't control (like your ESP's default domain). It irrevocably ties your sender reputation to the actions of strangers, guaranteeing instability and failure at scale. Always use a dedicated domain you own.
It's often faster to abandon a poisoned domain and warm up a new one than to repair a badly damaged reputation. Repair can take 3-6 months of near-zero sending and perfect behavior. If you have active campaigns, provisioning a new domain and following a strict 5-6 week warm-up protocol is almost always the more practical solution.
You can attempt to, but most software is designed for the bolt-on model. They lack integrated warm-up with real engagement, real-time verification at send time, and unlimited sending to allow for proper volume management. You'll be manually bridging the gaps between multiple tools, which becomes unmanageable for an agency with more than a few clients. A platform built on an owned pipeline enforces these rules by design.

See where your domain stands

Run the free SpamCipher check and see exactly which authentication and reputation gaps apply to your sending domain.

Get started free