Skip to content
GTM Guides

Cold email deliverability: staying in the inbox

Cold email deliverability is whether your mail keeps reaching the inbox over weeks and months, not whether a server accepted it this morning. It is not a setting you configure once. It is a balance you carry, and at cold email volumes nobody shows you the account statement.

By Rahul Bageria, co-founder · Updated August 2026 · 20 min read

The short answer Verified August 2026
What it is
Inbox placement over time, not the delivered count in your sequencer. Of the mail a provider accepts, the share that lands where a human will see it.
The two numbers
Spam complaints and hard bounces. Google requires a spam rate below 0.3% and recommends below 0.1%. No mailbox provider publishes a bounce number at all.
Why you cannot see them
Google says outright that low-volume domains may show no data in Postmaster Tools. The many-domains architecture that protects you is the one that blinds you.
The one published clock
Seven consecutive days below a 0.3% spam rate restores eligibility for mitigation, per Google. Nobody publishes a domain reputation recovery curve.
The stop-loss
Write down how many weeks you will spend saving a secondary domain before you retire it. Your primary domain never gets that choice.

Written by operators who run cold outbound for seed-stage teams, not by a warmup tool that sells the cure.


What deliverability actually means

Four different things get called deliverability, and that confusion is the reason founders cannot diagnose their own problem.

Definition

Deliverability is inbox placement over time: of the mail a receiving server accepted, the share that lands in the inbox rather than in spam or nowhere at all.

Also called inbox placement · full glossary

Four separate states, and you can be in a good one and a bad one at the same time:

Delivery

Did the receiving server accept the message. A binary SMTP outcome, and the number your sequencer prints as "delivered". A 98% delivered rate tells you almost nothing.

Deliverability

Of the mail that was accepted, what share reached the inbox. This is the thing you care about and the thing you can see least clearly.

Reputation

The provider's rolling judgment of your sending domain. It is the input to placement, not placement itself, and it has a memory measured in weeks.

Compliance

Whether you meet the published sender requirements. You can pass compliance and still hold a bad reputation, which is why Google grades them on separate dashboards.

Sending tools report delivery and call it deliverability. If your only evidence is a 98% delivered rate, you have measured whether a server said yes, not whether a human ever saw the message.


Authentication starts it, it does not live there

The distinction

SPF, DKIM and DMARC prove who sent a message. They say nothing about whether anyone wanted it, which is why a perfectly authenticated domain can land in spam every single time. Authentication is a floor you cross once. Everything after it is a list decision or a message decision.

The one-time build, the domains, the inboxes, the DNS records and the provider choice, belongs to our cold email infrastructure guide. This page starts the morning after that build is finished.

Scope note

The bulk-sender rules themselves, what each provider requires and when it took effect, live in the Google and Yahoo sender requirements. We use the numbers here and do not re-argue the specification.


Reputation is a balance, not a setting

Every send either adds to the balance or draws it down, and the ledger has a memory measured in weeks rather than days.

How the balance moves
1
The ledger

It is scored over a moving window

Amazon SES describes the mechanic more plainly than any mailbox provider does. It does not score you over a fixed period. It looks at "a representative volume", meaning "an amount of email that represents your typical sending practices".

2
The memory

One bad week has a long tail

Because the window follows your volume rather than the calendar, a campaign that hurt you stays inside the sample long after you stop it. That is why the fix takes an afternoon and the recovery takes weeks.

3
The lever

You own the domain, not the IP

On Google Workspace or Microsoft 365 the outbound IP is shared, and its reputation is not yours to move. Domain reputation is the only quantity a cold sender actually holds.

4
The grade

What the two ends look like

Google describes a high domain reputation as a "history of very low spam rates, and complies with Gmail's sender guidelines". A bad one is a "history of sending a high volume of spam regularly". There is a lot of room in between.

5
The floor

New domains start poor, not neutral

Spamhaus puts it flatly: an unknown reputation carries a much higher risk of emitting spam than a known-good domain, so "unknown reputations begin as 'poor' by default". A fresh domain is not a clean slate.


The thing nobody prints

The blind spot you built on purpose

The architecture that keeps one bad campaign from taking down everything is the same architecture that keeps every domain under the reporting floor.

Google says it itself

Checked in August 2026, nine of the top ten results for this keyword tell you to check your sender reputation weekly. Not one quotes this line from Google's own help center, live as of August 2026: "If your email traffic volume to personal Gmail accounts is too low, Postmaster Tools dashboards might not include data for your sending domain."

Spread across eight domains at thirty sends a day each, that sentence is about you. The dashboards also withhold low-volume days deliberately, to protect the privacy of Gmail users. So the standard advice is not wrong so much as unexecutable by the people it is written for.

There is one exception, and no page ranking for this term mentions it. Yahoo's Complaint Feedback Loop is "a domain based service", so enrolling asks for a verified domain, not IP ownership you do not have.


The instrument panel you have

Six instruments a cold sender can genuinely read, in the order we would trust them.

The six instruments
Bounces

The one input you measure directly

Hard bounce rate per campaign, from your own send data. It needs no provider dashboard, it maps to a real reputation input, and you can act on it the same afternoon.

Replies

Watched per inbox, not per campaign

Reply rate as a series for each sending address. One inbox collapsing while its siblings hold steady is a placement problem, not a copy problem, and it shows up before anything else.

SMTP codes

The only channel where they speak

4xx is a temporary failure, 5xx is permanent. Read the descriptive text rather than only the number: that text is where a provider tells you what it objected to, and most sequencers swallow it.

Complaint feed

Yahoo, enrolled per sending domain

Domain based, DKIM-signed mail only, verified domain rather than owned IPs. Yahoo is a thin slice of a B2B list, so treat it as a sampling probe. A complaint arriving through it is still real evidence.

Blocklists

Checked on a schedule, not in a panic

A standing check on every sending domain. Spamhaus says most listings expire on their own once the behavior stops, so the value here is knowing early rather than reacting hard.

Compliance

Postmaster Tools, set up anyway

It costs nothing to add each domain, the compliance status dashboard is open to every sender regardless of volume, and on the days you do cross the reporting floor you get real data.

Why open rate is off the panel

Apple's own policy document says Protect Mail Activity "downloads remote content in the background by default", whether or not the recipient engages. An open is now partly a machine event. Worse, the pixel and the tracking domain that produce the number are themselves inputs a filter can score.

Why the spam chart reads backwards

Google defines spam rate as the share of messages "delivered to engaged recipient's Inbox and then marked as spam by the recipient". Mail filtered straight to spam never enters the denominator, so a rate that improves while replies fall is a warning rather than a win.


Honest thresholds, and where each one comes from

Every number in cold email gets recycled without its origin, and the origin is exactly what decides how much weight it deserves.

Metric The number Who published it What happens at it Rule or policy
Spam rate Below 0.3% Google, sender guidelines FAQ Seven straight days under it restores eligibility for mitigation Provider requirement
Spam rate Below 0.1% Google, top ten sender issues Nothing formal. It is the target Google tells you to hold Provider recommendation
Complaint rate 0.1% / 0.5% Amazon SES 0.1% puts the account under review, 0.5% can pause sending One ESP's account policy
Hard bounce rate 2% / 5% / 10% Amazon SES Under 2% recommended, 5% triggers review, 10% can pause sending One ESP's account policy
Reply rate per inbox Your own baseline Nobody One inbox falling while its siblings hold is your earliest alarm Self-imposed
The 2% bounce rule is not a mailbox-provider rule

No mailbox provider publishes a bounce threshold at all. Trace the famous 2% and you land in Amazon SES's sending review FAQs, where it is the recommended ceiling for an AWS account, 5% places the account under review, and 10% can pause its sending. Useful, well documented, and worth holding yourself to. It is one email service provider's account policy, checked August 2026, not something Gmail has ever said.


List hygiene is where cold and permission mail are graded identically

Bounces are the loudest thing you control, and they are the one place a filter treats your cold list exactly like a newsletter.

Five hygiene rules
1
The input

Bounces feed the reputation directly

M3AAWG, the working group the mailbox providers sit in, states it outright: "The volume of permanent failures is one indicator used by receivers to build a reputation about a sender."

2
The clock

Verify at send time, not build time

Lists rot at roughly the rate people change jobs, so a list verified eight weeks ago is a different list. Re-run it through a verifier the week the campaign goes out.

3
The decision

Catch-alls are a policy, not a data point

A catch-all accepts everything at the SMTP layer, so "valid" from a verifier means "unknown". Split them into their own low-volume segment and measure them separately, rather than letting them quietly set your bounce rate.

4
The trap

Dead addresses do not stay dead

Amazon SES says spamtraps "can be converted from addresses that were once valid, but have been unused (and bouncing) for an extended period of time". That is how a stale export turns a bounce problem into a reputation problem.

5
The temptation

Re-engagement is the riskiest send there is

SES calls these efforts "highly risky", able to cause trouble with traps, bounces and complaints at once. If you run one, run it small, from a domain you can afford to lose, and never from the primary.

Watch-outs
  • !A 2023 export mailed once, "just to see what happens"
  • !Catch-alls left sitting inside the main segment
  • !Verification run at list build and never again
  • !Bounced addresses still on the list after the campaign

Cost per check varies more than accuracy does, which is the argument in our MillionVerifier and Reoon comparison.


Ramping, and why the shape beats the schedule

Every warmup vendor sells you a schedule. Only one mailbox provider has ever published a shape, and it works for launching as well as for recovering.

  1. 1
    Minute 0

    Stop for fifteen minutes

    Google's instruction after a deferral is to send nothing at all for 15 minutes. Not a smaller batch. None.

  2. 2
    Minute 15

    Send one test message

    A single message, checked that it delivered as expected. You are asking the provider a question, not resuming a campaign.

  3. 3
    Next 24 hours

    Hold below the deferral volume

    Stay under the volume that triggered the deferral for a full day. This is the step everyone skips, and skipping it restarts the clock.

  4. 4
    Day 2 onward

    Increase 25% to 100% a day

    Google calls this "a common daily increase". It is the only ramp curve any mailbox provider has put in writing, as of August 2026.

Two things the shape implies

The same guidance says to send at a consistent rate: not 60 messages as quickly as possible and then a pause, but "one message per second consistently". A sequencer that fires the whole day's queue in four minutes is doing exactly what Google names as a problem, worth checking in whichever sequencer you run.

One volume decision is permanent: Google's FAQ says bulk sender status "doesn't have an expiration date", so a single spike to clear a backlog changes the rules you are graded against forever. The specification sits in the sender requirements breakdown.

Want the sending setup checked before you ramp it?

Book a Fit Check

Engagement is the only lever that scales

Everything else in this guide protects a balance. Only one thing adds to it.

You cannot buy reputation and you cannot warm your way to it. What moves a domain's grade upward is people wanting the mail: replies, real human opens, messages dragged out of spam, forwards. That makes relevance a deliverability input, not only a conversion one, and it is why a tighter list sent less often beats the same offer sprayed wider.

What actually counts

Replies, moves out of the spam folder, forwards, and mail a person genuinely opened. Positive signals a filter can see and a warmup pool cannot manufacture.

Why timing is technical

Reaching people with a live reason to care lifts replies per send, and replies per send is the reputation lever. That is the deliverability case for signal-based selling.

Where the message work lives

The angle, the opener and the ask sit in cold email copywriting. No DNS record has ever rescued a message nobody wanted.


Where cheap infrastructure quietly costs you

Rented mailbox farms are cheap because the risk is pooled, and you are in the pool.

The usual pitch
  • Hundreds of inboxes, provisioned this week
  • A per-inbox price that undercuts Workspace
  • Domains and IP space you never control
  • Other senders you will never meet, sharing all of it
What Google says about that

Item eight on Google's own list of top sender issues: "Using the same IP address or domains for multiple senders can result in a low domain or IP address reputation, or poor deliverability for all senders." Provider choice and what it costs sit in the infrastructure tool guide and the build guide.


The weekly and monthly routine

This is fifteen minutes a week and one named owner. If that owner does not exist, shrink the program or hand the sending to an agency that runs deliverability as part of the job.

01

Every send

Check the hard bounce rate before you call the campaign finished. Read the SMTP responses rather than the sequencer's summary. Suppress every hard bounce the same day it lands.

02

Every week

Reply rate per inbox, read as a series rather than a number. A blocklist check on every sending domain. A skim of the Yahoo complaint feed. Same fifteen minutes, same day, one owner.

03

Every month

Re-verify any list you have not sent to recently. Look at compliance status per domain in Postmaster Tools. Add one line to the incident log, even in a month where nothing went wrong.

Two entries into that log and you stop having the same argument twice.

Operator note
Learned the hard way

Reputation problems repeat because nobody writes the first one down. The log is not paperwork. It is the only thing that lets you tell a bad week apart from a pattern, and it is one line.

RB
Rahul Bageria
Co-founder, Real Good GTM

What burning a domain actually looks like

It arrives in a fixed order, and the first stage is the one people explain away.

First
Replies thin out on one inbox

Its siblings hold steady, so it reads as a bad week of copy. Nothing in the sequencer looks wrong, because delivery is still reporting 98%.

Then
Deferrals appear in the logs

4xx codes. The provider is slowing you down rather than refusing you outright, and this is the last polite warning you get.

Then
Outright rejections

5xx codes with a policy message attached. As of August 2026 Google's FAQ says non-compliant mail will see "temporary and permanent rejections", which at least makes the failure readable.

Last
Silence that looks like success

Sends complete, nothing bounces, nothing replies. The mail is accepted and filed where nobody looks. This is the state that costs the most weeks.

If you are mid-incident

This page teaches the discipline. The symptom-by-symptom triage, ranked by how likely each cause actually is, sits in why cold emails go to spam. Start there, then come back for the recovery sequence.


How we would run it

The recovery playbook

Ten steps, in order. The first one is the step most people skip, and warmup is not step anything.

  1. 1

    Decide whether this domain is worth saving

    A secondary domain is usually cheaper to retire than to rehabilitate. A primary domain has no such option, which is exactly why cold outbound never runs from it.

  2. 2

    Stop sending from it today

    Not a reduced volume, a stop. Every further send adds to the sample the provider is judging, and that sample already says the wrong thing about you.

  3. 3

    Find the cause before you fix anything

    List, message or infrastructure. Fixing the wrong one costs a fortnight and teaches you nothing that transfers to the next campaign.

  4. 4

    Read the SMTP responses properly

    4xx is temporary, 5xx is permanent, and the descriptive text is where the provider says what it objected to. M3AAWG's guidance is to act on that text, not on the number alone.

  5. 5

    Check the blocklists

    Run every sending domain through the public lists. Spamhaus says listings "do expire automatically when listing criteria are no longer met", so stopping the behavior is most of the remedy.

  6. 6

    Fix the input, not the symptom

    Re-verify the list, cut the segment that generated the complaints, change the message that earned them. No amount of warmup traffic edits a sample that already exists.

  7. 7

    Run the one clock that exists

    Google publishes exactly one: bulk senders "will be eligible for mitigation when their spam rates remain below 0.3% for 7 consecutive days". Every other timeline you have been quoted is a guess.

  8. 8

    Restart on Google's own shape

    Below the volume that caused the trouble for 24 hours, then a daily increase of 25% to 100%, sent at a consistent rate rather than in bursts. Same shape as a launch.

  9. 9

    Move real business mail off it

    Contracts, invoices and support threads should never share a domain with an outbound experiment. If that has already happened, separate them before you restart anything.

  10. 10

    Write the incident down

    Date, domain, what changed in the seven days before, what the codes said, what you did, how long it took. One line, and it is the cheapest insurance on this page.

!
Caution

Never pay to be delisted

Spamhaus answers this in one word, "Absolutely not": there is "never any charge or fee associated with removing any Spamhaus listing", and any offer to remove one for money is a scam.

Do this instead
Fix the cause, use the operator's own free removal process, and let automatic expiry do the rest.
Operator note
Learned the hard way

Warmup is insurance you buy before the burn, not medicine after it. Pool traffic cannot outvote a large sample the filter already holds, and we would not trust a dataset on that question from a company selling warmup.

KM
Kshitij Maheshwari
Co-founder, Real Good GTM

Pushback

Where the common advice is wrong

Almost everything written about this keyword is written by companies selling warmup, and it shows in which four rules keep getting repeated.

The common advice

"Watch your reputation weekly, hold bounces under 2%, warm for two weeks, and avoid spam trigger words."

  • Check Postmaster Tools every week
  • 2% is the bounce rule
  • Warm for two weeks, then send properly
  • Avoid spam trigger words
What holds up

"Instrument what you can actually see, source every threshold, ramp on the published shape, and fix the list."

  • At cold volumes the dashboards may show nothing, and Google says so
  • 2% is one ESP's account policy, not a provider rule
  • The published shape is 25% to 100% a day, at a steady rate
  • Word lists appear nowhere on Google's own top ten issues

What is true now, and what stopped being true

This is the section that dates fastest, so it carries its check date and it is the part we revise first.

The claim you will read Status, August 2026 Where that comes from
Postmaster Tools removed the reputation dashboards False Google's dashboards page still documents domain and IP reputation, next to a compliance status dashboard open to every sender.
Open rate tells you where you landed Dead Apple downloads remote content in the background by default, whether or not the recipient engages.
Non-compliant mail just gets filtered Changed Google's sender guidelines FAQ now says such messages will experience disruptions, including temporary and permanent rejections.
Nobody publishes a ramp curve Newly false Google's top ten sender issues sets out a deferral procedure and a 25% to 100% daily increase. Almost nothing ranking for this term cites it.
Avoid spam trigger words Obsolete Word lists appear nowhere on Google's own list of the ten issues it sees most. Misleading display names and subject lines do.

What to realistically expect

A ceiling worth knowing, and a floor nobody selling cold email software will print.

The ceiling

Placement is never 100%, and it is not even across providers. What you control is the shape of the sending: steady, small and relevant beats spiky and large, on infrastructure whose reputation is genuinely yours.

The trade

Doing this properly means sending less. Fewer, better-aimed messages is not a compromise you make for deliverability. It is the same decision that makes the outbound work at all.

The honest floor

Every mailbox provider's published guidance says to send only to people who asked for it. M3AAWG, the group those providers sit in, says plainly that "Email appending is a direct violation of core M3AAWG values", and appending is close to how most cold lists get built. That does not make cold outbound unworkable. It means you operate on tolerance rather than permission, and every threshold on this page is the price of that.


Key takeaways

Key takeaways
5 points
  • 1 Deliverability is a balance with a memory, not a setting you configure.
  • 2 At cold volumes, the dashboards everyone recommends may show you nothing.
  • 3 Know who published every threshold you manage against.
  • 4 Bounces and complaints are the two inputs you can actually move.
  • 5 Set the stop-loss on a secondary domain before you need it.

FAQ

Questions founders ask

What is a good bounce rate for cold email?
Under 2% is a sound working ceiling, and stop a campaign at 5%. No mailbox provider publishes a bounce threshold at all: the 2% figure traces to Amazon SES's sending review FAQs, where it is the recommended ceiling for an AWS account, 5% places the account under review and 10% can pause sending. That is one email service provider's account policy rather than a Gmail rule, and still the best-sourced bounce number in circulation.
What spam complaint rate is too high?
Google's published requirement is a spam rate below 0.3%, and Google's own recommendation in its top sender issues article is below 0.1%. The catch is that at cold email volumes you probably cannot see your complaint rate at all, because Postmaster Tools may report nothing for a low-volume domain. So you manage the inputs instead: list quality, relevance, how often you send, and how easy you make it to say no.
How do I check my domain reputation?
Set up Postmaster Tools for every sending domain, and accept that it may show nothing, because Google withholds data on low-volume days. The compliance status dashboard still works regardless of volume. Enroll each domain in Yahoo's Complaint Feedback Loop, which is a domain based service and asks for a verified domain rather than IP ownership. Then carry the rest yourself: hard bounce rate per campaign, reply rate per inbox watched as a series, and a standing blocklist check.
How long does it take to recover a burned domain?
Nobody publishes a domain reputation recovery curve, so anyone quoting you a number of weeks is guessing. The one published clock is Google's: bulk senders become eligible for mitigation when their spam rates stay below 0.3% for seven consecutive days. Spamhaus says its listings expire automatically once the behavior that caused them stops. Beyond those two facts, plan for the recovery to take longer than the fix, because reputation is scored over a moving window of your recent sending.
Does email warmup actually work?
As insurance before you send, plausibly. As a cure after a burn, no. Warmup traffic teaches a filter that a domain sends mail people engage with, and a burned domain has already handed that filter a large sample saying the opposite. No mailbox provider has endorsed warmup networks, and nobody has published a controlled dataset showing that pool warmup improves placement. The argument on both sides is structural rather than measured, so treat any vendor number with suspicion.
How many emails a day can I safely send from one inbox?
There is no provider-published cold email cap, so every number you have read, 50 an inbox, 100 a day, one domain per 100 sends, is somebody's house policy. Set your own and hold it. What providers do publish is the shape rather than the ceiling: increase gradually, keep the rate consistent, and do not burst. Google's guidance is explicit that firing 60 messages as quickly as possible and then pausing is worse than one message per second, steadily.
Rahul Bageria, co-founder of Real Good GTM
About the author
Rahul Bageria

Co-founder of Real Good GTM. He has built and run cold email infrastructure for seed-stage B2B teams, which mostly means learning the unglamorous half of outbound the expensive way. This guide is the operating discipline behind the sending we run for clients, written from the primary sources rather than from other people's blog posts.

Connect on LinkedIn

Keep going

The rest of the cold email stack

This page covers staying in the inbox. These three cover building the thing, diagnosing it when it breaks, and the tools people reach for first.

Want someone else holding the thresholds?

Book a fit check. We'll look at how you send today, where the reputation risk actually sits, and whether outbound is the right motion for your stage at all. If it isn't, we'll tell you that too.

Book a Fit Check

No hard sell. No fake numbers. Real good work speaks for itself.