You wrote a decent email. You checked the list twice. You sent two hundred of them and got nothing back, not even a polite no. Before you rewrite the subject line for the fifth time, check whether anybody ever saw it. Most cold outreach that fails does not fail on persuasion, it fails on delivery. The message went to spam, or it was quietly dropped at the gateway with no bounce at all, so your sending tool still shows a green tick and you carry on believing the copy is the problem.
Here is the setup that fixes it. About two hours of real work, then a day of waiting for DNS to settle and two weeks of patience. You can start the whole thing this afternoon.
Never send cold outreach from your main domain
If your company runs on yourcompany.com, do not send cold email from it. Buy a second domain that looks like a sibling, something like getyourcompany.com or yourcompany.co, and point it at your main site with a permanent redirect so anyone who types it still lands in the right place. Every outreach mailbox lives on that second domain.
The reason is simple. Reputation attaches to a domain, it is slow to build and fast to lose. If a campaign goes badly you want the damage sitting on a domain you can quietly retire, not on the one carrying your invoices, your contracts and your replies to paying clients. The failure mode is common and ugly: a company runs an untested campaign from its main domain for a few weeks, then discovers its ordinary business mail is landing in spam.
The three DNS records that decide whether you exist
SPF is a TXT record on the sending domain listing which servers may send mail as you. On Google Workspace that is v=spf1 include:_spf.google.com ~all. One SPF record only, never two, and mind the limit of ten DNS lookups. Chain four or five providers into a single record and it silently stops evaluating, which to a receiver looks exactly like having no SPF at all.
DKIM signs every message with a private key so the receiver can verify it really came from you and was not altered on the way. In Google Workspace you generate a 2048 bit key under Apps, Google Workspace, Gmail, Authenticate email, publish the TXT record it hands you, then go back and click Start Authentication. That final click is the step almost everyone forgets, and without it the key sits there doing nothing while you assume you are signed.
DMARC tells receivers what to do when SPF and DKIM disagree, and it is the record small senders skip most often. Publish a TXT record at _dmarc.yourdomain reading v=DMARC1; p=none; rua=mailto:you@yourdomain. Start at p=none so nothing is blocked while you read the reports, then move to quarantine once they come back clean. Skip DMARC and Google Postmaster Tools shows you nothing at all, which means you are flying with no instruments.
What the big mailbox providers now require
Since February 2024 Google and Yahoo have required all three of those from bulk senders, along with a working one click unsubscribe and a low spam complaint rate. Microsoft has brought in comparable rules for high volume senders into Outlook and Hotmail. The published thresholds sit around five thousand messages a day to one provider, which is far above what a sane B2B campaign sends, so founders read the announcement and decide none of it applies to them. That is the wrong read. Those requirements are a floor, not a ceiling, and the filters run the same signals on everyone. Authenticate properly whether you send fifty a day or fifty thousand.
Google asks bulk senders to keep reported spam under 0.3 percent. At small volumes that is a brutally thin margin. One complaint in three hundred puts you at the line, so make the opt out obvious instead of burying it, and drop anyone who says no on the first message without a second thought.
Warm up like a person, not like a tool
A new domain with a new mailbox has no history, and firing three hundred messages on day one from a mailbox that has never sent anything is the fastest way to burn it. Give it two weeks minimum at low volume, to people who will actually open and reply. Warmup services help because they manufacture that early positive signal, but they do not replace real conversation, and providers have got much better at recognising purely synthetic warmup traffic.
When you scale, add mailboxes rather than raising volume per mailbox. Thirty to fifty cold sends a day per mailbox is a sane ceiling. If you need three hundred a day, that is six to ten mailboxes spread across two or three sending domains, not one heroic inbox doing all the work.
Turn off tracking on the first message
Open tracking works by loading a tiny invisible image from a tracking domain, and link tracking rewrites your links to run through that same domain. On a brand new sending domain, using a shared tracking domain that thousands of other senders also use, that is one of the loudest spam signals you can produce. Give up the open rate on first touch. You lose a vanity number and you gain the delivery, and the only number that means anything in cold outreach is replies.
Test before a real prospect ever sees it
Send your live template to mail-tester.com and fix whatever it flags. Then send it to a Gmail address and an Outlook address you control and look at where it lands, Primary or Promotions or spam. In Gmail open Show original and confirm you see SPF pass, DKIM pass and DMARC pass. Three passes and Primary placement on both providers means the plumbing is right, and any silence after that really is the copy or the list.
Keep the message itself plain. Short, text only, no images, no attachments, no HTML signature stuffed with a logo and social icons. A signature block that looks like a newsletter reads like a newsletter to a filter.
If you have already burned a domain
The signs are clear enough. Your normal replies to clients start landing in spam, or Google Postmaster Tools shows your domain reputation as low or bad. Stop all cold sending from that domain immediately and do not try to push through it. Give it four to eight weeks of nothing but ordinary human mail while reputation recovers, and move outreach onto a fresh domain built the way described above. A burned domain does not respond to better copy.
What to do today
Buy the sending domain and redirect it to your main site. Create two mailboxes on it. Publish SPF, DKIM and DMARC, then verify each one actually passes instead of assuming it does. Switch off open and link tracking. Start a two week warmup at low volume. Register the domain in Google Postmaster Tools so you can see what receivers think of you. That is the entire list, and none of it is hard, it is just rarely done in the right order.
If you would rather have this built once and built properly, that is a good part of what we do at Talent Alliance Hub, along with the CRM sitting behind it so every reply lands in a pipeline instead of dying in an inbox. Tell me what you sell and who you sell to, and I will tell you what your setup should look like before you spend anything.