Tugam

Outbound

The cold email deliverability checklist for 2026

Google and Microsoft now publish numeric thresholds and reject mail that misses them. A working outbound programme in 2026 is an infrastructure discipline first and a copywriting exercise second.

The campaign looked healthy until the fourth week: two hundred emails a day from three inboxes, a 52 percent open rate on the dashboard, a handful of polite replies. Then the replies stopped, and a test message to a colleague's Outlook address bounced with the code 550 5.7.515. The domain had crossed a threshold nobody was watching, and it would take six weeks of near-silence to recover.

Cold email deliverability in 2026 is no longer a matter of tone and subject lines; it is an infrastructure discipline with published rules, numeric thresholds and hard consequences. This checklist covers authentication, the providers' thresholds, domain and inbox architecture, warm-up and volume, list hygiene, content, the metrics that still mean something, and the legal basis for contacting businesses in the EU and Türkiye.

Why cold email deliverability is now a rules problem

Cold email deliverability changed in 2024 and 2025 because the two largest mailbox providers stopped publishing advice and started publishing requirements. Google's sender guidelines state that from 1 February 2024, senders of more than 5,000 messages a day to Gmail accounts must authenticate with SPF, DKIM and DMARC, support one-click unsubscribe on marketing mail, and keep the spam rate reported in Postmaster Tools below 0.30 percent, with 0.10 percent as the level to stay under.

Microsoft followed. From 5 May 2025, senders of 5,000 or more messages a day to Outlook.com, Hotmail and Live addresses must pass both SPF and DKIM and publish a DMARC record of at least p=none that aligns with the From domain. Non-compliant mail is routed to junk and then rejected outright with the error 550 5.7.515, "sending domain does not meet the required authentication level".

Two points matter for a B2B outbound team. First, the 5,000 threshold counts every mailbox on the sending domain, and Google expects SPF or DKIM from all senders regardless of volume. Second, the thresholds are proxies: a domain sending 400 messages a day with a 0.5 percent spam rate is treated the same way as a bulk sender, because the filters act on reputation, not on the rulebook.

Checklist part 1: authentication (SPF, DKIM, DMARC)

Authentication is the entry ticket, not the strategy: an authenticated domain with a bad list still ends in spam, but an unauthenticated one never leaves the gate. Verify all three records on every sending domain before a single cold email leaves.

  • SPF. One TXT record per domain listing every service allowed to send on its behalf. Keep it under the ten-DNS-lookup limit; nested includes from several vendors break SPF silently.
  • DKIM. A 2048-bit key per sending service, signing every message, with the signing domain (d=) matching the From domain, because alignment is what DMARC evaluates.
  • DMARC. Start at p=none with a reporting address (rua=) so you see who sends as you; move to p=quarantine within thirty days and to p=reject once reports are clean. p=none satisfies the minimum at both providers, but p=reject is what protects the brand from spoofing.
  • A custom tracking domain. If the outreach tool rewrites links, the tracking domain must be yours, on the same root, with its own certificate; shared tracking domains inherit every other customer's reputation.

Checklist part 2: domain and inbox architecture

Never send cold email from your primary domain, because the domain that carries your invoices, customer support and hiring correspondence cannot afford the reputation swings that outbound produces. The standard architecture in 2026 is a small fleet of secondary domains, each with a few mailboxes, rotated by the sending tool.

ElementRecommended practiceWhy
Secondary domainsClose variants of the brand (brand-team.com, getbrand.com, brand.co), each redirecting to the main siteIsolates reputation; a burned domain is retired without touching the primary
Mailboxes per domain2–3More than three on one domain concentrates risk and looks like a farm
Daily volume per mailbox20–40 cold emails after warm-up, plus a similar number of warm-up messagesVolume spikes are the most common trigger of provider throttling
Provider mixA mix of Google Workspace and Microsoft 365 mailboxesEach provider's outbound reputation systems differ; diversification smooths outages
Domain age before sendingAt least 14 days of DNS and mailbox setup, then 2–4 weeks of warm-upNew domains with immediate volume are a known spam pattern

A team that needs 1,000 cold emails a day therefore needs roughly 30 mailboxes across 10 to 15 domains. That arithmetic is why volume is the wrong objective; the right one is replies per mailbox at a spam rate that keeps every domain alive.

Checklist part 3: warm-up, volume and bounce control

Warm-up is the practice of building a sending history on a new mailbox before it carries cold email, and Google's own guidance describes the principle: "start with a low sending volume to engaged users, and slowly increase the volume over time", keeping the rate consistent rather than sending in bursts. Instantly's 2026 benchmark report, drawn from billions of sends across its workspaces, recommends five to ten emails a day at the start, increasing gradually over four to six weeks.

Automated warm-up networks, in which mailboxes exchange messages and mark them important, establish a baseline, though providers increasingly recognise the pattern. The more durable warm-up is real correspondence: replies to partners, internal threads, newsletters. Keep warm-up running at a reduced level after the mailbox goes live.

Bounce control most often separates a stable programme from a collapsing one. Instantly's benchmark puts acceptable bounces below 2 percent, "ideally much lower"; in practice a mailbox that bounces more than 3 percent in a day should stop until the list is re-verified. The mechanics:

  • Verify every address with a validation service before it enters a sequence, and again if the record is older than 60 days.
  • Exclude catch-all domains from the first send, or route them to a separate low-volume mailbox where a bounce costs less.
  • Set the sending tool to pause a mailbox automatically at a 3 percent daily bounce rate, and to remove any address that hard-bounces from every list, permanently.
  • Watch 550 5.7.515 and 4.7.x responses separately: the first needs DNS work, the second needs volume reduced.
The thresholds are proxies: a domain sending 400 messages a day with a 0.5 percent spam rate is treated the same way as a bulk sender.

Checklist part 4: list hygiene and content

The list decides the spam rate, and the spam rate decides everything else. A cold email to the right person with a relevant reason is rarely reported; one to a generic inbox, a former employee or a company outside the profile is reported often, and every report counts against the domain.

  • Source from the ideal customer profile, not from a vendor's export. Build the account list first, then find the contacts; a purchased list in reverse order produces both bounces and complaints.
  • Remove role addresses (info@, sales@, office@) and anyone who has previously asked not to be contacted, on any domain you operate.
  • Cap the sequence at four to seven steps over three to four weeks; Instantly's data attributes 58 percent of replies to the first message and 42 percent to follow-ups, so the fifth follow-up produces more reports than replies.
  • Write in plain text, or close to it. One font, no images, no templates, at most one link and preferably none in the first message. Rich formatting is the signature of a newsletter; cold email is judged by the standards of a personal message.
  • Keep the first message under 80 words, with one question. Long first messages are read as pitches and reported as such.
  • Include a working opt-out. A plain sentence ("Reply 'no' and I will not write again") is enough for one-to-one mail; honouring it within a day is what keeps the spam rate down.

Checklist part 5: measure replies, not opens

Open rate no longer measures anything, and a programme that optimises for it makes the wrong decisions. Apple's Mail Privacy Protection downloads remote content in the background and hides "when and how many times you view" a message, registering an open whether or not a person saw it. Tracking pixels also add an image and a tracking domain to every message, a deliverability cost in itself. Belkins, in its analysis of 7.5 million cold emails sent in 2025, disabled open tracking entirely and reports no open-rate data.

The metrics that still describe reality are these:

  • Reply rate per mailbox and per sequence step. Belkins found an average of 0.45 percent across all 2025 sends, higher for founders (0.57 percent) and companies with 0–10 employees (0.72 percent) than for enterprises with 10,000+ (0.22 percent). Instantly's workspaces average 3.43 percent, with the top quartile above 5.5 percent. The figures differ because the denominators differ; what matters is tracking your own number weekly and noticing a drop of a third, which is a deliverability problem before it is a copy problem.
  • Positive reply rate, separating interest from "unsubscribe" and out-of-office messages.
  • Bounce rate, daily, per mailbox.
  • Spam rate in Google Postmaster Tools, per domain, against the 0.10 percent target.
  • Inbox placement, tested weekly with seed addresses on Gmail, Outlook and at least one corporate Microsoft 365 tenant.

Checklist part 6: the legal basis, GDPR and KVKK

B2B cold email to business contacts in the EU can rest on a legitimate-interest basis when it is targeted, proportionate and easy to refuse; it cannot as indiscriminate bulk mail. Recital 47 of the GDPR states that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest"; each member state's ePrivacy rules then decide whether a corporate address may be emailed without prior consent, and most permit it for contact relevant to the recipient's role, with an opt-out. Document the legitimate-interest assessment, state the reason for contact in the message and honour every objection immediately.

How the Tugam Growth Engine applies to deliverability

Deliverability is built into each stage of the Tugam Growth Engine rather than bolted on afterwards. In Enrich, every contact is verified and every account scored against the profile before it can enter a sequence, the largest single lever on spam rate. In Personalize, the first message names a specific reason for writing, stays under 80 words and is reviewed by a person; relevance is a deliverability control as much as a conversion one. In Branch, replies, bounces and objections route automatically: a refusal suppresses the contact across every domain, a hard bounce removes the address permanently, an out-of-office reschedules rather than resends. In Deliver, volume per mailbox, warm-up ratios, seed tests and Postmaster Tools are a weekly operating routine, and a domain that drifts above 0.10 percent is rested before it is blocked.

What we do at Tugam

Tugam builds and runs this infrastructure as part of Forward Deployed AI Engineering for growth: one operator-engineer sets up domains, DNS, mailboxes, warm-up, verification, sequencing and reporting inside your environment, usually within three to four weeks, and hands over a documented system your team operates. It replaces the outbound team and the agency retainer with a fixed-scope build measured on replies and meetings, not sends. We work from Istanbul and Amsterdam and set the legal basis and mailbox architecture according to whether the target market is the EU, Türkiye, the Gulf or Asia.

The 2026 cold email deliverability checklist

  1. Register two to four secondary domains, redirect them to the main site, and let them age for at least two weeks with SPF, DKIM (2048-bit) and DMARC (p=none with reporting, then p=quarantine) in place.
  2. Create two to three mailboxes per domain on a mix of Google Workspace and Microsoft 365; set up a custom tracking domain or disable link tracking.
  3. Warm up for four to six weeks, starting at five to ten messages a day, and keep warm-up running at a reduced level permanently.
  4. Cap each mailbox at 20 to 40 cold emails a day; never spike.
  5. Verify every address before sending and re-verify after 60 days; exclude role addresses and catch-alls from the first send.
  6. Set automatic pauses at a 3 percent daily bounce rate and suppress hard bounces and refusals across all domains.
  7. Write plain-text first messages under 80 words with one question and a one-line opt-out; keep sequences to four to seven steps.
  8. Disable open tracking; report on reply rate, positive reply rate, bounce rate, Postmaster spam rate and weekly inbox placement.
  9. Document the legitimate-interest assessment for EU contacts and register merchant recipients in İYS for Türkiye; honour every objection within one business day.
  10. Review Postmaster Tools every Monday; rest any domain above 0.10 percent spam rate for two weeks before it reaches 0.30 percent.

Deliverability is the quiet part of outbound: when it works, nobody notices, and when it fails, every other investment in the programme stops producing. If you are setting up cold email for a new market, or trying to understand why a working campaign went silent, we are glad to look at the configuration with you.

Frequently asked questions

What spam rate does Google allow for cold email?
Google's sender guidelines require senders to keep the spam rate reported in Postmaster Tools below 0.30 percent and recommend staying below 0.10 percent to absorb occasional spikes. The same guidelines require SPF, DKIM and DMARC for senders of more than 5,000 messages a day to Gmail, and one-click unsubscribe for marketing messages.
How many cold emails can one mailbox send per day?
A conservative operating range in 2026 is 20 to 40 cold emails per mailbox per day after a four-to-six-week warm-up, with warm-up traffic continuing at a reduced level. Sending 1,000 messages a day therefore requires roughly 30 mailboxes across 10 to 15 secondary domains, never the primary domain.
Why is open rate no longer a useful cold email metric?
Apple's Mail Privacy Protection downloads remote content in the background and hides when and how often a message is viewed, so tracking pixels register opens regardless of whether anyone read the email. Tracking pixels also add an image and a tracking domain to every message. Reply rate, positive reply rate, bounce rate and Postmaster spam rate describe reality; open rate does not.
Is B2B cold email legal under GDPR and in Türkiye?
Under the GDPR, Recital 47 recognises direct marketing as a possible legitimate interest, and most member states allow role-relevant B2B email with an opt-out, provided the legitimate-interest assessment is documented and objections are honoured. In Türkiye, prior consent is not mandatory for messages to merchant or tradesperson recipients, but their addresses must be registered in İYS, a refusal channel must be provided, and sending must stop within three business days of a refusal.

Discuss this with Tugam

If this is relevant to your plans, we would be glad to talk through how it applies to your company.

Chat on WhatsApp