The Complete Cold Email Stack: From Domain Setup to Reply
Most cold email advice starts with the wrong question. People ask which sending platform to buy, when the platform is the last decision that matters. Whether your message reaches an inbox is decided almost entirely before your sequencing tool sends anything — by your domain setup, your authentication records, your sender reputation, and the quality of the list you loaded.
This guide maps the four layers of a working cold email stack, what each one is responsible for, and which tools sit where.
If you are building this today: get the infrastructure right first, then warm your inboxes and clean your list before a single campaign goes out. The sending platform comes last.
Why the stack changed
Between February 2024 and May 2025, the three largest mailbox providers moved authentication from best practice to price of admission. Google and Yahoo announced their requirements together in October 2023 with enforcement from February 2024, and Microsoft followed in May 2025. Enforcement is now fully active across all three, and Google and Microsoft issue permanent 550 rejections for non-compliant bulk mail.
That last part is the meaningful change. Non-compliant mail is not quietly filed into a spam folder where a diligent prospect might still find it. It is refused at the SMTP level.
Two numbers define the boundaries you operate inside. The bulk sender threshold is 5,000 messages per day per sending domain, and it is permanent — cross it once with a large campaign and you are classified as a bulk sender from then on. The spam complaint ceiling is 0.3%, enforced by Gmail and matched by Yahoo, with 0.1% the figure to actually aim for.
There is also a trap for anyone starting fresh, which describes most cold email operators: domains with no bulk sending history before January 2024 face accelerated scrutiny from day one. A new sending domain gets less benefit of the doubt than an aged one, which is exactly why the warm-up layer is not optional.
One clarification, because it is widely misunderstood: authentication is not only a bulk sender rule. Google requires SPF or DKIM from every sender and Yahoo requires both, regardless of volume. Sending 200 emails a day does not exempt you.
Layer 1 — Sending domains
Your primary company domain should never send cold outreach. If a campaign goes badly, the reputation damage follows the domain and cannot be reversed by pausing, putting your transactional and internal mail at risk. The standard structure is a set of secondary domains, close variants of your brand, each hosting a small number of mailboxes.
The decisions at this layer are how many domains and mailboxes each, which registrar and mailbox provider (Google Workspace and Microsoft 365 behave differently under load and differ in tolerance for new domains), and how long the domain ages before its first send. A domain registered yesterday and sending today is the clearest spam signal you can produce.
Volume per mailbox is the constraint that drives the rest of the structure — see how many cold emails per inbox per day and the full walkthrough in secondary domains for cold email.
Layer 2 — Authentication and tracking
This is DNS work, it is one-time, and it is where most stacks silently break.
SPF publishes which servers may send for your domain. DKIM cryptographically signs your messages. DMARC tells receiving servers what to do when the first two fail, and enforces alignment.
Alignment is the part people miss. If you send from a subdomain but your platform signs with the vendor's domain, you authenticate but you do not align, and DMARC fails. You can have all three records published, pass every online checker, and still fail because the From: domain does not match. Start at p=none so you can read the reports, then tighten toward p=quarantine or p=reject.
A detail specific to cold email tooling: nearly every sequencing platform offers click and open tracking through a shared vendor domain, and a shared tracking domain used by thousands of other senders is a reputation liability you inherit for free. Configure a custom tracking domain on your own subdomain instead. The certificate step is where this usually falls over — see how to configure a custom tracking domain without breaking SSL.
Full guide: SPF, DKIM and DMARC setup for cold email.
Layer 3 — Warm-up and reputation
A correctly authenticated domain with no sending history still has no reputation. Warm-up tools place your mailboxes into a network that exchanges and positively engages with messages — opening, replying, and moving mail out of spam — so providers observe normal interaction patterns before real campaigns begin.
What separates the tools at this layer is network size and quality (a pool of disposable accounts teaches providers very little), provider mix (a pool that is almost entirely Gmail does nothing for your Outlook placement), spam-folder recovery (whether the tool detects placement in spam and actively pulls messages out), and whether the tool is designed for ongoing use rather than a pre-launch sprint.
WarmupInbox is the tool covered in depth on StackRanger for this layer. See the WarmupInbox review, the background in email warm-up tools: what they do and when you need one, and the head-to-head in WarmupInbox vs TrulyInbox vs Mailwarm.
Layer 4 — List verification
Bounce rate is the fastest way to destroy a warmed domain. A list pulled from a scraper or bought from a data vendor carries dead addresses, role accounts, and spam traps — addresses maintained specifically to catch senders who did not verify.
The practical decision is not which verifier but when you verify. Bulk cleaning suits lists assembled in advance, ahead of a campaign. Real-time verification suits lists built continuously, at the point of capture or enrichment. Most operators need both, and the cost difference between them is large enough to matter.
EmailListVerify is the verifier reviewed here — see the EmailListVerify review, the timing breakdown in email list hygiene: real-time verification vs bulk cleaning, and the accuracy comparison in EmailListVerify vs ZeroBounce vs NeverBounce.
Layer 5 — Sending and sequencing
Only now does the platform choice matter. The differences that affect outcomes are inbox rotation (distributing volume across your mailbox pool automatically rather than splitting campaigns by hand), mailbox limits per plan (several platforms cap connected mailboxes per seat, which changes the real cost of a multi-domain setup considerably), reply detection and thread handling including out-of-office and bounce classification, and whether warm-up is bundled.
Pricing here is typically per seat or per contacted prospect, and the headline figure is rarely what you pay once mailbox caps are factored in. Model your real volume before comparing.
See Woodpecker vs Lemlist for the deliverability and pricing-model split between the two long-standing competitors, Woodpecker vs Instantly for inbox rotation and sending limits, the Woodpecker review, and the wider best sales engagement software roundup.
The LinkedIn layer
Not part of the email stack strictly speaking, but it shares the same buyer and a parallel failure mode: account restriction instead of domain damage.
The core decision is architecture. Cloud-based tools run from a dedicated IP assigned to your account; browser-extension tools run from your own machine. They carry different detection profiles and different risk, and the right answer depends on your volume and whether you manage one account or several.
Expandi is the tool reviewed here. See the Expandi review, Expandi vs Waalaxy, and LinkedIn automation limits: cloud vs browser extension and proxy risk.
Putting it together
A minimum viable stack, in build order:
- Register two to three secondary domains and let them age.
- Publish SPF, DKIM and DMARC on each, then verify alignment rather than mere presence.
- Create two or three mailboxes per domain.
- Configure a custom tracking domain with a valid certificate.
- Start warm-up and leave it running.
- Verify the list before loading it.
- Only then connect the sending platform, starting at low daily volume.
Skipping steps one through five to reach step seven faster is the most common and most expensive mistake in cold outreach, because the damage lands on assets you cannot repair — only replace.
For a budget-constrained version, see the cold email stack for a small agency. If your mail is landing in Promotions rather than spam, that is a different problem with a different fix: why cold emails land in the Promotions tab.