Updated September 28, 2026 | 10 min read

How to set up your sending infrastructure for cold email (without burning your domain)

<article>

How to set up cold email domains without burning the main one

I once watched a team spend a full week on one cold email. Sharp subject line, tight copy, clear ask. Then they sent it from their main company domain, got flagged as spam within two days, and took their invoices and client replies down with it. The email was never the problem. The setup underneath it was.
This is more common than you’d think. Domains that were never set up properly send most of the emails that land in spam (more on that here). Without the right foundation, Gmail and Outlook have no reason to trust you, so they don’t. Fixing that foundation is most of what our deliverability work at lemlist actually is, and it’s a big part of why teams rate us 4.6/5 across 2,000+ reviews on G2 (see for yourself).
So here’s what I’ll walk you through: the domains to buy, the DNS records to set, how many mailboxes your volume needs, and the warm-up schedule that keeps them alive. Your cold email lands. Your main domain stays clean.
One thing to know before you start. The rules got stricter while everyone was busy A/B testing subject lines. Google’s sender guidelines have required authentication from high-volume senders since February 2024, and Gmail started ramping up enforcement against non-compliant traffic in November 2025. Microsoft followed with its own requirements for Outlook, Hotmail and Live.com on May 5, 2025. Providers used to quietly dump sloppy senders in spam. Now they reject the mail outright. Everything below is built for that reality.

Fix your infrastructure before you touch your copy

Cold email deliverability comes down to your infrastructure, your warm-up routine, and how consistently you monitor both. Everyone loves to argue about content. The opener, the CTA, the perfect subject line. I get it, that’s the fun part. But if the infrastructure underneath is broken, none of it ships. So we start at the bottom.
Infrastructure means your domains and mailboxes. It also covers how you authenticate and ramp them up. Here’s the order I set it up in:
  • Buy a separate domain for outbound
  • Pick a lookalike that providers trust
  • Authenticate it with SPF, DKIM and DMARC
  • Let the domain and mailboxes age
  • Size your mailbox count to your volume
  • Split across providers
  • Run the 4-phase ramp-up
  • Keep a backup

Never send cold email from your main domain

This is the mistake I see most. Your main domain runs your invoices, your client threads, your whole business. If it gets burned (flagged as spam by providers), all of that breaks with it, not just your outreach.
So buy a separate domain just for outbound, and point it at your main website. If your outbound domain redirects nowhere real, that’s a red flag for providers too.

Pick a lookalike domain that providers trust

A lookalike domain is a variation of your main name, used only for sending. Some patterns help you, others quietly hurt you.
Patterns that work:
Patterns to avoid:
  • Exotic or unfamiliar TLDs that providers don’t recognize
  • Typosquatting, like swapping an “m” for an “n” to mimic your real domain. That reads like phishing.
  • Numbers in the name. Tempting for branding, painful for cold outreach.
  • Separators like hyphens between words
Before you buy, check the domain’s history. Search “[domain name] blacklist” on Google to see if it was flagged before, then run the domain through our free Deliverability setup checker once it’s live. And when you pick where to host it, your provider matters more than people expect, so it’s worth choosing a domain host built for outreach.

Authenticate your domain: SPF, DKIM, DMARC

Three DNS records decide whether a provider even considers your email real. Skip them and you’re not sending cold email, you’re donating it to spam folders.
SPF is a list. It tells receiving servers which IPs and services are allowed to send mail using your domain. If a message arrives from somewhere that isn’t on that list, it fails the check, so every tool you send from needs to be included.
DKIM is a signature. Your sending server signs each message with a private key, and the receiver checks it against the public key published in your DNS. If the signature holds, the message wasn’t tampered with in transit and it genuinely came from your domain.
DMARC is the instruction. It tells providers what to do when SPF or DKIM fails: monitor (p=none), quarantine, or reject. Start at p=none so you can read the reports and see who’s sending on your behalf, then tighten once your records are clean.
All three are now table stakes. Google’s sender guidelines require SPF and DKIM authentication, a published DMARC record, and a From domain that aligns with either the SPF domain or the DKIM domain at the organizational level. Google defines a bulk sender as anyone sending close to 5,000 messages or more to personal Gmail accounts in 24 hours, which means most cold email teams sit comfortably under the threshold. That’s not a free pass. The senders who follow the bulk rules anyway are the ones whose mail keeps landing, because the same signals feed the reputation scoring that applies to everyone.

Let your domain age before you send

Patience is not optional here. Do not send any cold email in the first four weeks after buying a domain. This gives blacklist checks time to clear and lets the domain settle.
Same logic for a new mailbox. Send nothing in the first week. Put it in an answer-only mode that replies to existing threads, then warm it up for four to five weeks before any cold outreach. Warm-up is just the mailbox sending and receiving normal-looking mail so it builds a sender reputation before you scale. lemlist automates that whole process, and it also flags problems early instead of after you’ve torched a domain.

Work out how many mailboxes your volume needs

This comes down to two things: how many leads you have and how fast you want to reach them. lemlist’s deliverability team caps mailbox volume at 40 emails per day, with 25 to 35 as the safer range.
Two quick examples:
  • 1,000 leads in 3 weeks (15 sending days). That’s about 67 emails a day. At 40 per mailbox, you need at least 2 mailboxes.
  • 500 leads in 1 week (5 sending days). That’s 100 emails a day. At 40 per mailbox, you need at least 3 mailboxes.
The rule underneath: the more you spread your volume across domains and mailboxes, the lower each one’s limit can be, and the safer your overall reputation stays.
You have three honest ways to get there. You can do the whole thing by hand: buy the domain at a registrar, add the SPF, DKIM and DMARC records yourself, create each mailbox, and warm them one by one. Plenty of teams do, and it works fine if you enjoy DNS. You can also buy pre-warmed inboxes from third-party vendors, which skips the waiting but means trusting someone else’s warm-up history and hoping those mailboxes weren’t shared or abused before you got them. Or you skip the weekend of copy-pasting TXT records and let lemlist provision the domains and mailboxes for you and handle the DNS.

Split your mailboxes across Google and Microsoft

Most business email runs on Google Workspace or Microsoft 365, split fairly evenly between the two. So don’t stack all your mailboxes on one provider.
Spreading across both does two things. It protects you if one provider has an outage or a policy change, and it gives you more sender-recipient combinations when your leads sit on different providers.
It also means you’re playing by two rulebooks at once, and both got tougher. Microsoft’s sender requirements took effect for Outlook.com, Hotmail and Live.com on May 5, 2025: SPF, DKIM, DMARC with at least p=none, plus a valid sender address and working one-click unsubscribe. Non-compliant bulk mail now comes back as a permanent 550 5.7.515 rejection rather than sliding into a spam folder where you’d never notice. Google is enforcing on the same logic. Set your records once, on every sending domain, before your first campaign goes out.

Ramp up in 4 phases and never pass 40 a day

Teams always ask our deliverability team the same thing: what’s the right way to ramp up with lemwarm before sending with lemlist? The answer is a 4-phase system. The whole point is that your real sending volume never goes over 40 emails a day per mailbox.
  • Ramp-up (4 to 6 weeks): Set your lemwarm limit to 40 and your ramp-up increment to 1 or 2. Then let the volume grow on its own. If you set the increment to 2, lemwarm sends 2 on day one, 4 on day two, 6 on day three, and so on until it hits the limit.
  • Reputation stabilization (1 to 3 weeks): Keep warming until your lemwarm deliverability score sits above 90 and holds there. Then you’re clear.
  • Volume switching: Lower your warm-up volume and start sending real campaigns in lemlist. Your actual sending never crosses 40 a day. You’re just switching some of that budget from warm-up to outreach.
  • Ongoing reputation check: Keep a small batch of warm-up emails (around 10) going in the background at all times. These are plain mails with no links, no images, no sensitive content, so they’re the most likely to reach the inbox. If their spam rate spikes while a real campaign is running, that’s your early warning that something in your reputation is slipping. Pair it with Monitoring & alerts so you go look before it costs you replies.
You can set the limit and the increment directly in lemwarm’s setup, so none of this is manual.

Keep 10% of your domains and mailboxes in reserve

Always keep a backup. Roughly 10% of your setup should sit idle and ready. 10 domains, keep 1 spare. 100 mailboxes, keep 10.
The reason is simple. If a mailbox or domain takes a hit mid-campaign, you swap in a backup the same day instead of scrambling to fix the original while your sequence stalls.

Over to you

Infrastructure is a system you keep running: separate domains, smart lookalikes, authenticated DNS, patient aging and warm-up, the right mailbox count for your volume, provider diversity, and backups on standby. Get this right first, because no clever subject line can save a domain that was built wrong from the start. And with Gmail and Outlook now rejecting unauthenticated mail instead of hiding it, the cost of skipping the setup shows up faster than it used to.
If you’d rather not build this by hand, start a 14-day free trial and let lemlist provision it for you. No credit card required.
</article>
Share this post