How to stay out of spam: SPF, DKIM, DMARC & domain warm-up
The short answer
To reach the inbox in 2025 you need three things: email authentication (SPF, DKIM and DMARC, now mandatory for bulk senders), dedicated sending domains that are warmed up for about two weeks, and a spam-complaint rate kept under 0.3%. Miss any one and even a perfect campaign lands in spam.

On this page
- The 2024 rule change you can't ignore
- What SPF, DKIM and DMARC actually do
- Never send from your main domain
- The pre-send deliverability checklist
- How domain warm-up actually works
- List quality: the deliverability factor hiding in your data
- How to tell you are already in spam
- Common deliverability mistakes, and the fix for each
Deliverability is the silent killer of cold outreach. If your emails don't reach the primary inbox, nothing else, targeting, copy, offer, matters. And in 2024 the rules got stricter.
The 2024 rule change you can't ignore
In February 2024, Google and Yahoo rolled out new requirements for bulk senders. To keep landing in Gmail and Yahoo inboxes, senders must now:
- Authenticate with SPF, DKIM and DMARC, all three, not just one.
- Offer one-click unsubscribe and honor it promptly.
- Keep the spam-complaint rate below 0.3%, Google's stated threshold.
As sysadmin and deliverability communities now put it bluntly: in 2025, without SPF, DKIM and DMARC configured, your mail will be marked spam or rejected by Gmail, Outlook and others.
What SPF, DKIM and DMARC actually do
| Record | What it proves |
|---|---|
| SPF | Which servers are allowed to send mail for your domain. |
| DKIM | The message wasn't tampered with in transit (a cryptographic signature). |
| DMARC | What receivers should do when SPF or DKIM fails, and where to send reports. |
Together they tell Gmail and Outlook that you are who you say you are. The 2025 deliverability benchmark data ties the worst inbox-placement scores to exactly these gaps, poor authentication, weak IP segregation and inconsistent list hygiene.
Never send from your main domain
This is the single most important rule of cold outreach. Cold email should never go out from your primary company domain. Instead:
- Register dedicated lookalike domains (e.g. try-yourbrand.com) purely for outreach.
- Configure SPF, DKIM and DMARC on each.
- Warm them up for ~2 weeks, low volume that ramps gradually, before any real campaign.
The payoff: even an aggressive campaign, or an accidental spam-trap hit, can never drag your real business domain into spam. Your primary domain stays clean and trusted.
The pre-send deliverability checklist
- ✅ SPF, DKIM, DMARC live on every sending domain
- ✅ Sending domains warmed for ~2 weeks
- ✅ List verified, no dead or catch-all addresses (bounces hurt reputation)
- ✅ One-click unsubscribe in every message
- ✅ Spam complaints monitored and kept under 0.3%
- ✅ Volume per inbox kept low and human-paced
How domain warm-up actually works
Warm-up is not a checkbox in a tool, it is a trust-building period. A brand-new domain sending 500 emails on day one looks exactly like a spammer to Gmail, because that is what spammers do. A warmed domain starts with a handful of messages a day, gets replies and opens, and ramps volume gradually over roughly two weeks before carrying a real campaign.
Two mistakes ruin it. Ramping too fast, because a launch deadline is pressing, and stopping warm-up entirely once campaigns start. Reputation is not earned once and kept forever; sustained sending behaviour maintains it. The full ramp schedule and the ways people burn domains are in domain warm-up, and how not to burn a domain.
List quality: the deliverability factor hiding in your data
Authentication proves who you are. Your bounce rate tells providers how careful you are. Every hard bounce says you are emailing addresses you never verified, and mailbox providers read a rising bounce rate as a signal of scraped or stale data. Serious senders keep hard bounces under roughly 2%, and the safest way to stay there is verifying every list before it enters a sequence, then re-verifying anything older than a few months. The mechanics are covered in verification and bounce rate.
Catch-all domains deserve special care: they accept everything at SMTP level, so a verifier cannot confirm the mailbox exists. Send to them in small, monitored batches or not at all.
One European wrinkle: outside the Gmail-and-Outlook world, many DACH and Baltic companies run their mail on local providers or self-hosted servers with their own filtering quirks. The fundamentals stay the same, but inbox-placement tests should include the providers your actual target market uses, not just a Gmail seed list.
How to tell you are already in spam
Deliverability problems rarely announce themselves. Replies just slow down, then stop. By the time someone notices, the domain may have weeks of damage. Watch for the early signals instead:
- Reply rate drops across all segments at once, copy problems hit one segment, deliverability problems hit everything.
- Open tracking collapses suddenly on providers where it previously worked.
- Seed-inbox tests show messages arriving in spam folders on Gmail or Outlook test accounts.
- Blacklist listings appear for your domain or sending IP.
Weekly seed tests and blacklist checks take minutes and catch most problems while they are still reversible. We keep a fuller routine in monitoring deliverability.
Common deliverability mistakes, and the fix for each
- Sending too much per inbox. Hundreds of cold emails a day from one mailbox is a filter magnet. Keep volume human-paced per inbox and add mailboxes to scale; see how many emails per day is safe.
- One domain doing everything. When it burns, everything burns. Spread volume across several sending domains.
- Image-heavy HTML templates. Cold email should look like a one-to-one message: plain text, no tracking-heavy design.
- Ignoring DMARC reports. They exist to show you authentication failures. Nobody reads them until it is too late.
- Buying "pre-warmed" domains. Their history is unknown and often bad. Warm your own.
You can pressure-test the targeting side in our cold email benchmarks guide, but none of it works until the deliverability fundamentals above are in place.
Frequently asked
Do I need SPF, DKIM and DMARC to send cold email in 2025?
How long should you warm up a new sending domain?
Should you send cold email from your main company domain?
Sources
- MailReach, Email Deliverability Statistics 2025: Benchmarks & Trends
- Google, Email sender guidelines (bulk sender requirements, 2024)
- Superhuman Prospecting, Email Deliverability 101: Warm-Up, SPF, DKIM & DMARC
We protect your domain by design
Dedicated sending domains, full SPF/DKIM/DMARC setup, and a ~2-week warm-up are built into every campaign, your primary domain never gets touched.
Book a strategy call