ColdOps
All posts
Domain & inbox setup

Cold email domain setup: the complete walkthrough

By Mo Charradi, Founder8 min read

Cold email domain setup means buying secondary domains separate from your main business domain, configuring authentication records before a single email goes out, warming each mailbox for two to four weeks and then connecting to your sending tool, in that order. Skip or compress any of those steps and deliverability problems follow within the first month.

The actual setup per domain takes about an hour. The wait is the warmup.

Why sending domains must be separate from your main domain

Your company's primary domain carries everything: the website, internal email, the brand. If a sending campaign causes that domain to land on a blacklist or develop a spam reputation with Google or Microsoft, the damage extends far beyond cold email. Replies to colleagues start landing in spam. Your website contact form gets filtered. Recovery can take weeks.

Secondary domains solve this by design. They're inexpensive (usually around $10 to $15 a year), purpose-built for outbound and replaceable if one burns. One damaged sending domain doesn't touch any other domain you operate. This isolation isn't optional. It's the foundational assumption every other part of a domain setup is built on.

Step 1: Buy your sending domains

Sending domains should look like real business variants, not disposable addresses. Common patterns that work:

  • Verb prefix: getwidget.com, trywidgetpro.com, usewidgetapp.com
  • Audience or use-case suffix: widgetforteams.com, widgetforbusiness.com
  • Alternate extensions: widgetapp.io, widgetco.co (though .com still reads most credibly to a B2B buyer)

Avoid hyphens, numbers at the start of a domain and names containing "email," "info," or "official". These pattern-match spam filters. Buy from a registrar that gives full DNS control; you'll be setting four records per domain.

How many to buy: a standard setup runs 2–3 mailboxes per domain, sending 30–50 emails per mailbox per day. That's 60–150 sends per domain per day, or roughly 1,500–4,000 per month per domain. Match that against your campaign volume and you have your domain count. The cheapest cold email setup guide walks the full cost math including registrar, hosting and tool costs at different volume levels.

Spread domains across at least two registrars. A single provider outage or policy action should not be able to take down every sending domain at once.

Step 2: Configure your authentication records

This is the step most people rush and where most domain problems start. Every sending domain needs four records in place and verified before warmup begins.

SPF tells receiving mail servers which services are authorized to send on your domain's behalf. It lives as a TXT record at @ (root). Your sending tool (Instantly, Smartlead, Google Workspace, or another) will provide the exact SPF value to use. One SPF record per domain: if you have multiple, they conflict and receivers treat the record as absent.

DKIM is a cryptographic signature that proves a message hasn't been tampered with in transit. Your sending tool generates a DKIM key pair; you publish the public key as a TXT record at a subdomain like s1._domainkey.yourdomain.com. The tool signs outgoing mail with the private key; receivers verify against the public one. Getting this wrong is invisible until inbox placement drops.

DMARC tells receiving servers what to do when a message fails SPF or DKIM (reject it, quarantine it to spam, or deliver it anyway) and sends you aggregate reports on authentication results. Start with p=none (monitor only) while you verify that SPF and DKIM are passing and aligned. Once you're confident, move to p=quarantine. The DMARC policy guide covers the transition and what the aggregate reports are actually telling you.

MX records point reply email somewhere. Cold email generates replies (that's the point) and without MX records pointing at an active inbox, those replies bounce. Set MX to Google Workspace, Microsoft 365, or Zoho, whichever is hosting the mailboxes. The MX records for cold email guide covers exactly what to set and how to verify it's working.

The full authentication walkthrough (what each record does mechanically, how to check alignment and how to diagnose common failures) is in the SPF, DKIM and DMARC guide. Read it before troubleshooting; most authentication issues have a small set of root causes and are fast to fix once identified.

Step 3: Create your mailboxes

Once DNS has propagated (typically 24–48 hours), create your mailboxes. Name them like real people: james@getwidget.com or sarah@trywidget.com, not info@ or outreach@. Generic prefixes pattern-match bulk senders and raise the spam filter's priors before a single message is evaluated.

Set each mailbox up with:

  • A profile photo, so the mailbox looks like a person rather than an empty shell
  • A short, plain-text signature: name, title, company, phone number
  • No unsubscribe footer (that belongs on marketing email; cold email operates under different rules)

Log into each mailbox after creating it and send a few manual emails to accounts you control. This establishes that the mailbox is real before the warmup tool touches it.

Step 4: Warm up before sending anything

Warmup is the single most skipped step in cold email domain setup and the single most common cause of a burned domain in the first 30 days.

New domains and mailboxes have no sending history. Gmail, Outlook and other providers use that history to decide how to filter incoming mail. Send volume too fast to unknown recipients on a fresh domain and the signals look like spam, because they pattern-match exactly what spammers do.

A proper warmup:

  • Days 1–7: Warmup tool sends 5–10 emails per mailbox per day, mostly to other warmed seed inboxes. Replies come back. Positive engagement signals build.
  • Days 8–14: Volume climbs to 20–30 per mailbox per day. Still primarily seed traffic.
  • Days 15–21: 30–40 per day. Small batches of real prospects can start here.
  • Day 22+: Full sending volume, with warmup traffic continuing in the background indefinitely.

Keep warmup running permanently at low volume. It's an ongoing reputation maintenance signal, not a one-time launch phase. Turning it off after the initial ramp is one of the ways previously healthy domains lose their standing over months.

Two to four weeks is the standard timeframe for a domain starting from zero. The full approach (which warmup tools are worth using, what scores to watch and how to read the warmup dashboard) is in the email domain warmup guide.

Step 5: Connect to your sending tool

With authentication configured and the domain warmed, connecting to Instantly, Smartlead, or another sending platform is straightforward. A few things to check before launching campaigns:

  • Verify the connection shows a green status. Yellow or red almost always means the IMAP/SMTP credentials are wrong or a mailbox provider has started blocking the connection type.
  • Set a sending schedule. Business-hours-only sending (roughly 8am–6pm local time for the recipient) keeps the send pattern human. Round-the-clock sending from a business mailbox is an obvious machine signal.
  • Cap daily sending per mailbox even after warmup. Start at 30–40 per day and raise gradually. A burned mailbox costs you the domain, not just the campaign.
  • Decide on open tracking deliberately. Open tracking adds a pixel and rewrites links, both of which fingerprint outbound campaigns to spam filters. Many operators running high-volume cold email disable it and rely on reply rate and booked meetings as the real performance signal.

After setup: what to keep watching

A domain doesn't stay healthy automatically. Authentication records can drift: someone edits DNS and breaks SPF alignment, a DKIM key expires, DMARC reports start flagging a new sending source. Blacklist status changes if a campaign pushes a dirty list through a mailbox. Warmup health decays if the tool loses its connection silently.

Run a deliverability check on each sending domain every few days. If you're running more than five or six domains, that check becomes its own daily task, which is the point where agencies typically look at continuous monitoring. ColdOps connects each client workspace by a read-only key and watches authentication, blacklist status, bounce rate and warmup health continuously, alerting you to a slip before it cascades into a campaign failure.

The domain itself is not a set-and-forget asset. Set it up correctly, warm it patiently, then keep watching it. The fastest way to lose a well-configured domain is to stop paying attention once it's running.

Frequently asked

How many domains do I need for cold email?
Most senders run 2–3 mailboxes per domain, sending 30–50 emails per mailbox per day. Divide your monthly send volume by roughly 1,500 to 4,000 sends per domain to get your domain count. The number scales with monthly send volume. More sends require more domain capacity to stay under the daily limits that protect sender reputation.
Do I need a separate domain for cold email?
Yes. Sending cold email from your primary business domain puts your entire brand at risk. One blacklisting event or reputation hit affects your website, internal email and every other channel running through that domain. Secondary sending domains are inexpensive and replaceable; your main domain is not.
How long does it take to warm up a cold email domain?
Plan on two to four weeks for a new domain to be ready for volume sending. The first week focuses on low-volume warmup mail to build a sending history; subsequent weeks gradually increase volume while keeping bounce and complaint rates flat. Rushing the warmup is the most common reason newly configured domains burn within the first month.
What DNS records do I need for cold email?
You need four records on every sending domain: SPF (a TXT record that authorizes your sending service), DKIM (a TXT record with a cryptographic key for message signing), DMARC (a TXT record that tells receivers what to do when authentication fails) and an MX record so replies have somewhere to go. Missing any one of the four weakens the domain. A missing MX record is the quiet one, because sending still works while replies bounce. The most common setup gap is a missing or misaligned DKIM record, which causes the domain to authenticate at the record level but fail at the signature level.

Keep reading