Reference GuideDeliverability

Cold Email Deliverability 2026

Anyone running cold outbound in 2026: founders, RevOps, and agencies setting up sending infrastructure. Assumes you already have a sequencer and are trying not to burn domains on week two.

Hans Dekker
Hans Dekker

AI-Powered GTM Strategist

Creator of Clay MBA · Former Founder (Lyne.ai, acquired) · Helped 200+ B2B teams

Last updated: August 20, 2026

DeliverabilityDomainsWarmupInfrastructure14 min read

TL;DR

Deliverability in 2026 is mostly infrastructure discipline: how you buy domains, how you warm them, how you ramp campaign volume, and what you put inside the email body. This is what we run in production across Google, Microsoft, Mission Inbox, and Azure setups.

Need a hand?

Need help setting this up? Lens.ly covers company data and enrichment. Or book a call and we run outbound infrastructure for you.

Quick wins

If you only fix five things

  • Stop buying 50 lookalike domains in one day from one registrar
  • Never launch campaign volume on day one of a new domain (Spamhaus ZRD + aggressive filtering)
  • Turn aggressive provider matching OFF and distribute send load
  • Drop Mimecast/Proofpoint/Barracuda leads from Google Workspace campaigns
  • Audit every URL in your email body, signature, and tracking setup (SURBL hits links, not just your sending domain)

Send limits

Safe daily volume by provider (2026)

ProviderMailboxes/domainSends/mailbox/dayWarm + cold splitMax/domain/day
Google Workspace32010 warm + 10 cold60
Microsoft 36532010 warm + 10 cold60
Mission Inbox33015 warm + 15 cold (typical)90
Azure (Hypertide/Scaledmail)Up to 252-4Varies by tenant/config50-100

On the numbers

These limits are starting points, not ceilings

The table above reflects safe operating ranges we see hold up across multiple clients. Your offer, list quality, and copy can shift what is safe by 30-50% in either direction. A tight ICP with strong personalization survives higher volume. A scraped list with generic copy does not.

Azure is the outlier: higher mailbox counts at lower per-mailbox volume are driven by tenant and configuration constraints, not because Azure tolerates more spam signals. Providers like Hypertide and Scaledmail have brought setups as low as 25 mailboxes per domain at 2-4 emails per mailbox per day.

Domains

How to buy and name sending domains

Do not put your brand name in the domain the obvious way. Patterns like trycompany.com, getcompany.com, and usecompany.com are trivially clustered. SURBL Fresh tracks domain registrations registered on a single day; keyword clusters are even easier to detect. They pull live Whois data every single day.

Diversify where you buy domains: use multiple registrars, not one bulk checkout. Diversify when you buy: do not register 20 domains in a single day. Bulk same-day registration gets auto-flagged as a cluster even if the names look different.

Do not use .info domains. We have seen deliverability issues disproportionately on that TLD.

Many senders are moving away from Cloudflare for DNS on sending domains. Not a hard rule, but worth testing if you are troubleshooting unexplained filtering.

Domain structure

Subdomains vs root domain (standard vs enterprise)

Standard setup

Subdomains perform well when the root domain has strong reputation. Structure: 3 subdomains per domain, 1 mailbox per subdomain. Same pattern most cold email operators recommend.

Enterprise setup

Launch the root domain with up to 20 subdomains, 2-3 mailboxes each, after a full month of warmup. The root domain established reputation carries the subdomains, so you concentrate far more volume on a single brand than fresh lookalike domains allow.

Inboxes

Diversify providers and inboxes

Do not run everything through one inbox type. Mix providers where it makes sense: Gmail, Outlook, SMTP, Mission Inbox, Mailin, Zapmail, and others. Single-provider dependency means a single policy change kills your entire outbound.

There is no science behind blocklist check frequency, but our rule: do not poll blocklists at high frequency. Only check when you have reason to believe deliverability is compromised, or on a very low cadence (weekly/monthly). Obsessive checking does not fix problems and creates noise.

Security gateways

When your ICP sits behind Mimecast, Proofpoint, or Barracuda

Do

  • Identify ESG-protected domains during list building and segment them out
  • Route ESG leads to providers that handle those gateways (not Google Workspace)
  • Expect hard bounces, not spam placement, if you send Gmail to ESG inboxes

Don't

  • Send Google Workspace mail to Barracuda, Mimecast, or Proofpoint protected domains
  • Assume spam folder placement means you can keep sending (hard bounces damage reputation)
  • Ignore ESG domains because "the list is big enough without filtering"

Provider matching

The counterintuitive one: turn matching OFF

Most sequencers offer provider matching: Google inboxes only send to Gmail addresses, Microsoft inboxes only send to O365. It sounds logical. In practice, turning it ON aggressively concentrates all your sending pressure on a single ESP per domain.

That concentration burns the domain faster on that ESP. Filters see a new sender hammering only their users. When you turn matching OFF, load distributes across Gmail, Outlook, and others from the same domain. In our experience, distributed sending survives longer than strict 1:1 matching.

Test this against your own data. But if you are burning Google domains while your Microsoft match rate is 100%, matching is a likely culprit.

Warmup

Warmup motion: time, ramp, and volume

1

Follow your warmup provider first

They tune their own seed network. Their recommended ramp beats generic rules. Mission Inbox example below is one data point, not universal gospel.

2

Mission Inbox warmup settings

Daily ramp of +4 until you hit 30/day. Target ~80% warmup reply rate from day one. Minimum 15 natural days before any campaign sends.

3

Post-warmup campaign ramp (critical)

Do NOT send at max mailbox capacity on day one of campaigns. Start at 5 emails/mailbox/day. Add 5 per day until you hit your ceiling (e.g. 30/day). Warming at 30 then stacking 30 more of outbound on day 15 doubles volume overnight. Filters flag that spike.

4

Provider sequencing

Google first for 2 weeks. Then open to other providers. Microsoft last, 2 weeks after that. Microsoft is the least forgiving of new senders.

Blocklists

Spamhaus, warming pools, and ZRD

We have seen Spamhaus list domains that were only in a warming pool because the warming pool itself contained Spamhaus spam traps. Your domain gets guilt by association with the warmup network you chose. Pick warmup providers with clean seed pools.

Spamhaus also runs ZRD (Zero Reputation Domain), which automatically lists every newly registered domain for roughly the first 24 hours after it appears in zone files. This is not a punishment. It is a "too new to trust" flag. Hard argument for never launching on day one and for minimum warmup periods before campaign volume.

SURBL

SURBL is not a registration tracker. It is a URI blocklist.

SURBL is often misunderstood. It is not primarily tracking who registered domains yesterday. It is a URI blocklist: the receiving server extracts all URLs and domains from the message body and queries SURBL zones. If any domain in the email matches a listed domain, filtering triggers, even if your sending IP is completely clean.

SURBL lists are lists of websites that have appeared in spam messages, not lists of message senders. So it primarily punishes the domains inside your emails: links, unsubscribe domains, click trackers, calendar booking links, and yes, domains in your plain-text signature.

This is why teams rotate IPs, change ESPs, and fix SPF/DKIM/DMARC but still see filtering. The domain in the links is the real issue. DBL listings cascade: if a blocked domain is found anywhere in your messages, delivery is impacted and your IP can end up on the CSS list.

Plain text does not save you. Audit your signature, your booking link, your case study URL, and any tracking domain. If it resolves to a domain on SURBL, your clean sending domain takes the hit.

Cheat sheet

What hurts you vs what people blame

People blameOften the real issue
Sending IP reputationA listed URL or tracking domain in the email body (SURBL/DBL)
SPF/DKIM misconfigurationVolume spike after warmup (30 warm + 30 cold overnight)
Email copy sounding like AISame-day bulk domain registration cluster
Wrong sequencer settingsGoogle Workspace to Mimecast/Proofpoint (hard bounces)
Need more domainsProvider matching concentrating burn on one ESP

Frequently Asked Questions

How many cold emails can I send per day from Google Workspace in 2026?

Safe operating range: 3 mailboxes per domain, 20 sends per mailbox per day (10 warmup + 10 cold), 60 emails per domain per day total. Ramp campaign volume slowly after warmup; do not jump to max on day one.

Should I turn provider matching on for cold email?

Aggressive provider matching (Google only to Gmail, O365 only to O365) concentrates sending pressure on one ESP per domain and burns it faster. In our experience, turning matching OFF and distributing load across providers survives longer. Test against your own data.

How long should I warm up a new domain before sending campaigns?

Minimum 15 natural days (2 weeks) before any campaign volume. At Mission Inbox we ramp warmup 4 emails/day until 30/day with ~80% warmup reply rate. After warmup, start campaigns at 5 emails/mailbox/day and add 5 daily until you hit your ceiling.

Can I cold email Mimecast, Proofpoint, or Barracuda inboxes from Google Workspace?

No. If your ICP sits behind those security gateways, do not send from Google Workspace. You will get hard bounces, not spam folder placement. Route those leads to a different provider or drop them from the list.

What is Spamhaus ZRD and does it affect new domains?

ZRD (Zero Reputation Domain) automatically lists every newly registered domain for roughly the first 24 hours after it appears in zone files. It is a "too new to trust" flag, not a punishment. This is why you should never launch campaigns on day one.

What is SURBL and why do my links hurt deliverability?

SURBL is a URI blocklist. Receiving servers extract all URLs and domains from your message body and query SURBL zones. If any domain in the email matches a listed domain, filtering triggers even if your sending IP is clean. It punishes domains inside your emails (links, trackers, signatures), not senders.

Should I use trycompany.com or getcompany.com domains for cold email?

Avoid obvious brand-keyword patterns (trycompany, getcompany, etc.). SURBL Fresh tracks domains registered on a single day; keyword clusters are even easier to detect. Prefer unrelated domain names without your brand baked into the prefix.

In what order should I send to email providers when ramping?

Send to Google first. After two weeks of Google-only sending, open up to other providers. Only start sending to Microsoft two weeks after that. Microsoft is the least forgiving of new senders, so it goes last.

Run it yourself

Lens.ly gives you company intelligence, contact data, and GTM APIs. Self-serve, pay as you go.

Explore Lens.ly

Run it for me

We build the list, write sequences, set up infrastructure, and launch. Full outbound engine, typically $3-5k/mo depending on volume.

Book a quick chat

Want the full cold email system? Templates, infrastructure, and follow-ups in one guide.

Cold email guide →

Operator-grade reference from the field. Browse all reference