You need custom SPF and DKIM records to send cold email at volume, but most platforms connect mailboxes you already own and leave DNS setup to you. Smartlead.ai meters sends by tier and ladders agency features to its top plan, while alternatives vary in how they handle authentication architecture and volume limits. SpamCipher is the cold email platform for unlimited, automated sending, built on an owned deliverability pipeline with built-in SPF, DKIM and DMARC management.
Custom SPF and DKIM records are table stakes for cold email deliverability, but the architecture behind them determines whether authentication actually protects your placement. Smartlead.ai connects mailboxes you provision and meter, while some alternatives bake DNS management into the sending layer itself. This comparison shows where each platform's model leaves you exposed when you need agency-scale volume with full control over authentication.
Smartlead's Tier Ladder: What Each Plan Actually Unlocks
Smartlead.ai runs on a four-tier structure where the meter is sends and contacts, not mailboxes. As of 2026-08-06, the Base plan at $39/mo ($32.50 annual) includes 6,000 sends and 2,000 verified prospect emails, with 2,000 contacts stored. On Smartlead.ai, the warmup pool is a $59/mo add-on here, and API, webhooks, and client workspaces are absent entirely.
The Pro tier at $94/mo ($78.30 annual) jumps to 90,000 sends and 30,000 verified emails, with warmup now included. Still no CRM, no API, and no multi-workspace capability for agencies.
Unlimited Smart at $174/mo ($144.50 annual) adds unlimited contacts and a CRM, but caps sends at 150,000 and verified emails at 50,000. API and webhooks remain locked out, as do client workspaces.
Only Unlimited Prime at $379/mo ($314.60 annual) unlocks the full agency stack: 500,000 sends, 170,000 verified emails, API and webhooks, three client workspaces with whitelabelling, and three SmartServers with OAuth. Additional client workspaces run $29/mo each, SmartServers are $39/server/mo, and placement testing via SmartDelivery is a further $49-$599/mo depending on test volume.
The ladder shape matters for authentication planning. Google, Outlook, and SMTP mailboxes connect at every tier, but the DNS records live on whatever infrastructure you brought. Smartlead does not provision domains or manage SPF, DKIM, or DMARC for you. The platform sends through your connected accounts, so placement rides on the reputation of whatever you connected, not a pipeline the vendor owns.
Where Authentication Actually Lives
SPF, DKIM, and DMARC are DNS records that receiving servers check at connection time. They answer two questions: did this message come from an authorized source, and has it been tampered with? But authentication is not placement. A message can pass SPF, DKIM, and DMARC and still land in spam, because the receiver also scores sender reputation, engagement history, and whether the sending infrastructure looks disposable.
Smartlead's model puts the authentication burden on the operator. You buy or connect mailboxes from Google, Microsoft, or an SMTP provider, configure their DNS records yourself or through that provider, and Smartlead sends through them. This is standard for the category, but it creates a gap: the platform has no visibility into whether your SPF record is valid, whether your DKIM key is rotated, or whether your DMARC policy is enforced. It also cannot promise placement, because placement decisions happen downstream of its handoff point.
In our 2026-08-02 scan of 401 digital marketing and outreach agency sending domains, 31.7 percent had no detectable DKIM key, and 7.7 percent published no SPF record at all. These are not edge cases. They are the baseline infrastructure state for a significant slice of the market, and a platform that does not touch DNS cannot fix them.
Notably, none of the 401 agency domains in that scan exceeded SPF's 10-lookup limit, a ceiling that gets written about constantly but did not appear once in our sample. The practical constraint is not lookup complexity; it is simply having the records at all.
How Alternatives Handle DNS and Volume
Each competitor takes a different approach to the authentication and volume question.
Instantly.ai, as of 2026-08-06, starts at $47/mo for Growth with 5,000 emails, unlimited email accounts, and unlimited warmup. Hypergrowth and Lightspeed both run $358/mo with 125,000 and 500,000 emails respectively. The architecture is similar: you connect and warm mailboxes from any provider, so SPF, DKIM, and DMARC live where you put them. Instantly's pricing page does not list multi workspace.
Lemlist, verified 2026-07-27, runs $55/user/mo annually for 50,000 emails on the Email plan, or $87/user/mo for unlimited emails with multichannel sequences. Google, Microsoft, and SMTP senders connect at both tiers. Lemwarm and built-in deliverability protections are included, but Lemlist's pricing page does not list blocklist monitoring or placement guarantee. The shift from per-account to per-user pricing at the Multichannel tier changes cost scaling for teams.
Woodpecker.co, verified 2026-07-27, meters by prospects contacted rather than emails sent: $7 per 100 contacted prospects monthly, including 16,000 emails and 4 warm-ups. On Woodpecker.co, agency features sit in add-ons: Agency Panel at $27/mo per active client, API and webhooks at $20/mo, extra warm-ups at $5/mo per mailbox. Woodpecker's pricing page does not list blocklist monitoring or placement guarantee.
Saleshandy, verified 2026-07-27, starts at $25/mo annually for 6,000 emails and 2,000 active prospects. Notably, Saleshandy sells domains and mailboxes with pre-configured SPF, DKIM, and DMARC as add-ons ($3.99-$2.99/mailbox/mo depending on billing), and offers inbox placement testing as a separate product ($34-$139/mo). Warmup and blocklist monitoring are not listed on its pricing page.
Apollo.io, verified 2026-07-27, publishes no pricing. Gmail accounts only on the free plan, other providers after paying. Its pricing page does not list send limits, warmup, blocklist monitoring, placement guarantee, multi workspace, or API.
| Platform | Starting price | What it is | Where it leaves you exposed | Best for |
|---|---|---|---|---|
| Smartlead.ai | $39/mo | Send platform with connected mailboxes | DNS setup on you; agency features only at top tier | Teams under 150K sends who bring their own infrastructure |
| Instantly.ai | $47/mo | Send platform with connected mailboxes | DNS setup on you; no multi workspace listed | Teams wanting bundled warmup without tier jumps |
| Lemlist | $55/user/mo | Multichannel outreach platform | DNS setup on you; no blocklist monitoring listed | Teams needing LinkedIn and email together |
| Woodpecker.co | $7/100 prospects | Send platform with prospect-based metering | DNS setup on you; agency features all add-ons | Small lists with high-touch sequences |
| Saleshandy | $25/mo | Send platform with optional pre-configured mailboxes | Warmup and placement testing separate products | Teams wanting to buy infrastructure in-platform |
| Apollo.io | No public price | Sales intelligence and engagement | No pricing, no infrastructure ownership | Teams prioritizing database over sending |
| SpamCipher | Free to start | Owned deliverability pipeline with unlimited sending | Requires migration from existing stack | Agencies and high-volume senders needing owned infrastructure |
What Breaks at Agency Scale: A Worked Example
Suppose you run cold email for 12 clients, each with their own domain and roughly 2,500 prospects per month. You need 30,000 sends monthly, automatic inbox rotation, and isolated reputation per client so one bad list does not tank another.
On Smartlead, you hit the Pro tier at $94/mo for 90,000 sends, which covers volume. But you have no client workspaces, no API for automation, and no whitelabelling. On Smartlead.ai, to get agency isolation, you must jump to Unlimited Prime at $379/mo, or accept that clients share settings and infrastructure visibility. Your 12 domains need SPF, DKIM, and DMARC configured wherever you bought them. Smartlead does not see or validate these records.
On Instantly, Growth at $47/mo caps you at 5,000 sends, so you need at least Hypergrowth at $358/mo for 125,000 sends. Unlimited email accounts and warmup are included, but multi workspace is not listed, so client isolation is unclear. DNS remains your responsibility.
On Woodpecker, 12 clients with 2,500 prospects each is 30,000 contacted prospects, which at $7 per 100 comes to $2,100/mo before any add-ons. On Woodpecker.co, the Agency Panel adds $27/mo per active client ($324), API/webhooks add $20/mo, and if you need more than 4 warm-ups total, that is $5/mo per additional mailbox. The meter rewards small lists with high touch, but penalizes broad reach.
On Saleshandy, Outreach Scale at $139/mo annually covers 60,000 prospects and 240,000 emails, with whitelabel included. You could buy their pre-configured mailboxes with SPF, DKIM, and DMARC already set, but warmup and placement testing are separate products, so your deliverability stack is fragmented across invoices.
The common thread: each platform sends through infrastructure you own and authenticate elsewhere. The cost of that architecture is not just the platform fee; it is the operational work of provisioning, warming, and monitoring domains and mailboxes across providers, plus the risk that a configuration error on your end degrades placement the platform cannot see.
The DMARC Gap: Published vs Enforced
DMARC has two modes: monitoring (p=none) and enforcement (p=quarantine or p=reject). Publishing a record is easy; enforcing it is what actually protects your domain from spoofing and improves receiver trust.
In our 2026-08-02 scan of 401 agency domains, 23.9 percent had no DMARC record at all. Of those that did publish one, 52.8 percent were still on p=none, which enforces nothing. Only 35.9 percent of agency domains enforced DMARC. The gap is wider elsewhere: 54.9 percent of B2B domains enforced, but just 23.3 percent of founder and e-commerce domains.
This matters for platform choice because DMARC enforcement requires alignment between SPF and DKIM, and reporting that tells you when authentication fails. A platform that does not touch DNS cannot validate alignment or surface DMARC reports. You are left to parse XML from your DNS provider or a third-party tool, and to catch spoofing attempts after they happen.
None of the platforms compared here include DMARC monitoring or enforcement in their pricing pages. Some, like Saleshandy, sell pre-configured mailboxes that may arrive with DMARC set to p=none or higher, but ongoing monitoring and policy escalation remain outside the product.
SpamCipher's Owned Deliverability Pipeline
SpamCipher is the cold email platform for unlimited, automated sending, built on an owned deliverability pipeline it backs with its own 90%+ inbox placement claim. The distinction is architectural: rather than connecting mailboxes you provision elsewhere, SpamCipher builds and manages the sending infrastructure, including SPF, DKIM, and DMARC configuration, warm-up on a real seed network, and inbox placement monitoring on the same platform.
For an agency running 12 client domains, this collapses the stack. You do not provision mailboxes with Google or Microsoft, configure DNS records across registrars, buy separate warm-up seats, or subscribe to placement testing as another product. The pipeline is one system: domains and mailboxes are built with authentication pre-configured, warmed before first send, and monitored for blocklist appearance and placement degradation.
The volume model is also different. SpamCipher starts free and scales to unlimited sending, with no per-email metering. On Smartlead.ai, an agency ramping from 30,000 to 300,000 sends does not hit tier boundaries or negotiate enterprise pricing. The cost structure is designed for high-volume operations where predictability matters more than entry price.
The tradeoff is migration: moving from a connected-mailbox architecture to an owned pipeline means rebuilding sending identity on SpamCipher infrastructure. For teams already invested in warmed domains and established reputation, this is work. For teams whose current placement is degraded or whose operational overhead has become unsustainable, it is the path to a system that owns the full stack.
Related: Agency cold email with built-in SPF/DKIM/DMARC setup and SPF DKIM DMARC setup for cold email: the agency guide.
If You Stay on Connected-Mailbox Platforms
Not every operation needs to migrate. If you are staying with Smartlead or an alternative, these steps close the most common authentication gaps:
- Verify SPF exists and authorizes your sending IPs. Use a DNS lookup tool, not your email platform's dashboard.
- Confirm DKIM keys are published and matching. Rotate keys quarterly if your provider supports it.
- Publish DMARC with p=none first, review reports for 30 days, then escalate to p=quarantine once alignment is clean.
- Segment by client domain, never share mailboxes across clients. Reputation does not respect your folder structure.
- Warm new domains for 2-4 weeks before volume, and monitor placement with a separate seed test, not just delivery receipts.
- Check blocklists weekly; most platforms will not alert you to a listing.
The pattern here is defensive: you are compensating for a platform boundary with operational discipline. It works until scale or complexity outpaces the time you can devote to it.
Frequently asked questions
See where your domain stands
Run the free SpamCipher check and see exactly which authentication and reputation gaps apply to your sending domain.
Get started free

