Deliverability

How to stay out of spam: SPF, DKIM, DMARC & domain warm-up

Published 18 June 2026 · 7 min read · By Ripe Leads

The short answer

To reach the inbox in 2025 you need three things: email authentication (SPF, DKIM and DMARC, now mandatory for bulk senders), dedicated sending domains that are warmed up for about two weeks, and a spam-complaint rate kept under 0.3%. Miss any one and even a perfect campaign lands in spam.

On this page
  1. The 2024 rule change you can't ignore
  2. What SPF, DKIM and DMARC actually do
  3. Never send from your main domain
  4. The pre-send deliverability checklist
  5. How domain warm-up actually works
  6. List quality: the deliverability factor hiding in your data
  7. How to tell you are already in spam
  8. Common deliverability mistakes, and the fix for each

Deliverability is the silent killer of cold outreach. If your emails don't reach the primary inbox, nothing else, targeting, copy, offer, matters. And in 2024 the rules got stricter.

The 2024 rule change you can't ignore

In February 2024, Google and Yahoo rolled out new requirements for bulk senders. To keep landing in Gmail and Yahoo inboxes, senders must now:

As sysadmin and deliverability communities now put it bluntly: in 2025, without SPF, DKIM and DMARC configured, your mail will be marked spam or rejected by Gmail, Outlook and others.

0.3%The spam-complaint rate ceiling for bulk senders. Cross it and mailbox providers begin throttling or filtering everything you send.

What SPF, DKIM and DMARC actually do

RecordWhat it proves
SPFWhich servers are allowed to send mail for your domain.
DKIMThe message wasn't tampered with in transit (a cryptographic signature).
DMARCWhat receivers should do when SPF or DKIM fails, and where to send reports.

Together they tell Gmail and Outlook that you are who you say you are. The 2025 deliverability benchmark data ties the worst inbox-placement scores to exactly these gaps, poor authentication, weak IP segregation and inconsistent list hygiene.

Never send from your main domain

This is the single most important rule of cold outreach. Cold email should never go out from your primary company domain. Instead:

The payoff: even an aggressive campaign, or an accidental spam-trap hit, can never drag your real business domain into spam. Your primary domain stays clean and trusted.

The pre-send deliverability checklist

How domain warm-up actually works

Warm-up is not a checkbox in a tool, it is a trust-building period. A brand-new domain sending 500 emails on day one looks exactly like a spammer to Gmail, because that is what spammers do. A warmed domain starts with a handful of messages a day, gets replies and opens, and ramps volume gradually over roughly two weeks before carrying a real campaign.

Two mistakes ruin it. Ramping too fast, because a launch deadline is pressing, and stopping warm-up entirely once campaigns start. Reputation is not earned once and kept forever; sustained sending behaviour maintains it. The full ramp schedule and the ways people burn domains are in domain warm-up, and how not to burn a domain.

List quality: the deliverability factor hiding in your data

Authentication proves who you are. Your bounce rate tells providers how careful you are. Every hard bounce says you are emailing addresses you never verified, and mailbox providers read a rising bounce rate as a signal of scraped or stale data. Serious senders keep hard bounces under roughly 2%, and the safest way to stay there is verifying every list before it enters a sequence, then re-verifying anything older than a few months. The mechanics are covered in verification and bounce rate.

Catch-all domains deserve special care: they accept everything at SMTP level, so a verifier cannot confirm the mailbox exists. Send to them in small, monitored batches or not at all.

One European wrinkle: outside the Gmail-and-Outlook world, many DACH and Baltic companies run their mail on local providers or self-hosted servers with their own filtering quirks. The fundamentals stay the same, but inbox-placement tests should include the providers your actual target market uses, not just a Gmail seed list.

How to tell you are already in spam

Deliverability problems rarely announce themselves. Replies just slow down, then stop. By the time someone notices, the domain may have weeks of damage. Watch for the early signals instead:

Weekly seed tests and blacklist checks take minutes and catch most problems while they are still reversible. We keep a fuller routine in monitoring deliverability.

Common deliverability mistakes, and the fix for each

You can pressure-test the targeting side in our cold email benchmarks guide, but none of it works until the deliverability fundamentals above are in place.

Frequently asked

Do I need SPF, DKIM and DMARC to send cold email in 2025?
Yes. Since February 2024, Google and Yahoo require SPF, DKIM and DMARC for bulk senders. Without all three, messages are far more likely to be filtered to spam or rejected by Gmail and Outlook.
How long should you warm up a new sending domain?
About two weeks. New domains start at low daily volume that ramps gradually so mailbox providers build trust before any real campaign. Skipping warm-up is one of the fastest ways to burn a domain.
Should you send cold email from your main company domain?
No. Cold outreach should run on dedicated lookalike sending domains, never your primary domain, so an aggressive campaign or a spam-trap hit can never damage your real business email.

Sources

  1. MailReach, Email Deliverability Statistics 2025: Benchmarks & Trends
  2. Google, Email sender guidelines (bulk sender requirements, 2024)
  3. Superhuman Prospecting, Email Deliverability 101: Warm-Up, SPF, DKIM & DMARC

We protect your domain by design

Dedicated sending domains, full SPF/DKIM/DMARC setup, and a ~2-week warm-up are built into every campaign, your primary domain never gets touched.

Book a strategy call