Email infrastructure

Cold email deliverability setup

SPFDKIMDMARCMailgunSMTPDomain warm-up
What this is

The unglamorous layer under every outbound campaign: DNS authentication records, a separate sending domain, a custom tracking domain, and a warm-up plan. Configured, verified against real test sends, and documented so you can prove it is correct later.

Gmail and Yahoo stopped treating authentication as a recommendation. If your sending domain cannot prove who it is, filtering happens before a human ever sees the subject line, and no amount of rewriting the first sentence changes that.

This is a one-time infrastructure job, not an ongoing campaign service. I set the records, verify them with real sends into seeded inboxes, and hand you a document showing what each record does and how to check it still passes in six months.

Who this is for

What is included

Three DNS records, one sending domain, one tracking domain, and a verified test send. That is the whole job when it is done properly.

ItemWhat gets done
AuditCurrent SPF, DKIM and DMARC state checked, plus blacklist and reputation lookups on your domain and IP
SPFA single valid record listing every legitimate sender, kept under the DNS lookup limit
DKIMKey generated at the sending provider, published, and verified as signing correctly
DMARCPolicy published with reporting address, starting at monitor and tightened once alignment is confirmed
Sending domainA separate outbound domain configured so campaigns cannot damage your primary domain's reputation
Tracking domainCustom CNAME tracking subdomain, so links do not point at a shared provider domain
Provider setupMailgun, SMTP or your existing platform connected, with bounce and complaint handling enabled
Warm-up planA written volume ramp over the first weeks, with the metrics that say pause or continue
VerificationReal test sends to seeded inboxes across major providers, with headers checked for pass on all three records

How the setup runs

  1. Audit first. I check what your domain currently publishes and where mail is being sent from. This alone often explains the problem.
  2. DNS access. Either you grant registrar access, or I send exact record values for you to paste. Both work.
  3. Records published. SPF consolidated, DKIM keys generated and published, DMARC set to monitor with reports going somewhere you will read.
  4. Domains separated. Outbound moved onto its own sending domain with its own tracking subdomain.
  5. Verified by test send. Real messages sent and headers inspected, confirming all three checks pass rather than assuming they do.
  6. Warm-up handover. The ramp schedule, the metrics to watch, and the point at which DMARC gets tightened from monitor to quarantine.

Proof

Deliverability build

DNS & SMTP Configuration

Mailgun sending domain with SPF, DKIM and DMARC configured and verified end to end for outbound campaigns.

What comes next

AI Reply Qualifier

Once mail lands, replies need triage: intent classified and a CRM opportunity opened automatically.

Scope and timeline

Audit only

A written report on your current authentication, reputation and blacklist status, with the exact records to fix it.

1–2 days
Full setup

Records published and verified, sending and tracking domains configured, provider connected, warm-up plan delivered.

3–5 days
Multi-domain

Several sending domains and mailboxes provisioned for volume outbound, each authenticated and warmed separately.

1–2 weeks

DNS propagation adds up to 48 hours outside my control, so timelines above assume it. The full explanation of what each record does lives in why your cold email goes to spam, including the setup steps if you would rather do it yourself.

Not sure whether your domain is authenticated?

Book a free 15-minute call and I will check your current SPF, DKIM and DMARC records live on the call and tell you what is missing. It takes about four minutes.

Book a free 15-minute call →

Frequently asked questions

Why are my emails going to spam even though the content is fine?

Most often authentication. If SPF, DKIM and DMARC are missing or misaligned, major providers treat the message as unverified before anyone reads a word of it. Content filtering happens after authentication.

How long does domain warm-up take?

Plan for two to four weeks on a new domain, starting at low daily volume and increasing gradually while watching reply and bounce rates. Sending at full volume on day one from a fresh domain is the fastest way to burn it.

Should I send cold email from my main company domain?

No. Use a separate but similar sending domain, so damaged outbound reputation does not take your invoices, quotes and internal mail with it. The main domain keeps a strict DMARC policy and stays out of campaigns.

Does fixing deliverability improve my reply rate?

It removes the ceiling on it. Authentication decides whether your message is eligible to be read; the offer and the list decide whether it gets a reply. Fixing DNS on a bad list changes nothing.

Can you work with my existing sending tool?

Yes. The DNS and authentication layer is the same whether you send through Mailgun, a dedicated cold email platform, Google Workspace, or a CRM's built-in sender.