Before the first send · not legal advice
Domains, mailboxes and authentication, before the first cold email goes out
The outbound setup that is worth doing, what each platform includes for sending accounts, and the honest limit of what any of it achieves.
What this page covers
What this page will not tell you
There is nothing here about getting past a filter. Authentication records prove a message came from the domain it claims; they say nothing about whether the person receiving it wanted it, and no arrangement of records, domains or sending patterns turns an unwanted message into a welcome one. A mailbox provider that decides otherwise is not being fooled by a setup guide.
The setup below exists so that mail you are entitled to send is not thrown away for a reason that has nothing to do with its contents. Whether you are entitled to send it is a separate question with a separate answer: who you may write to, and where.
Outbound sending has a shape that opted-in marketing does not. You are writing to people who have never heard of you, from addresses that have no history, at a volume that looks like exactly the thing every mailbox provider is built to stop. The setup below is how senders keep that from being decided against them for reasons that have nothing to do with the message.
It is worth being clear about the order. None of this makes a message welcome, and none of it should be attempted before the separate question of whether you may send it at all: what the FTC and the ICO actually say.
Send from a different domain to the one your business runs on
Use a second domain for outbound, not the one carrying your invoices, your password resets and your customer replies. The reason is blunt: sender reputation attaches to a domain, and outbound is the riskiest mail a small company sends. If it goes badly on a separate domain you retire the domain. If it goes badly on your main domain you have a much longer week.
Keep it recognisably yours — a close variant of your real name, not an unrelated string — because the identity rules below require that a recipient can tell who is writing. Hiding behind a domain nobody can connect to you is not a deliverability technique, it is the thing both the US and UK rules specifically forbid.
Authenticate the domain, and know what authentication proves
SPF, DKIM and DMARC are the records that let a receiving server confirm a message really came from the domain in the From line. They prove identity. They do not prove welcome, and no arrangement of them makes unwanted mail acceptable.
Microsoft published requirements for senders into Outlook.com — its consumer service, covering outlook.com, hotmail.com and live.com addresses. For domains sending more than 5,000 emails per day, the post requires SPF to pass for the sending domain, DKIM to pass, and DMARC at "At least p=none and align with either SPF or DKIM (preferably both)".
The post is dated 2 April 2025 and carries an update dated 29 April, and it does not agree with itself about what happens to mail that fails. One paragraph says Microsoft decided "to reject messages that don't pass the required authentication requirements", returning "550; 5.7.515 Access denied", taking effect on 5 May. The next paragraph says that after 5 May 2025 Outlook "will begin routing messages from high volume non-compliant domains to the Junk folder", with rejection coming "in the future (date to be announced)". Both sentences are in the same post and it never resolves them. The safe reading is to assume the stricter one applies.
Note the threshold is per day and per sending domain, and that most outbound programmes sit well under it. The records are worth setting regardless, because the alternative is being indistinguishable from someone forging your name.
Decide how many mailboxes you actually need
The per-inbox question is where most outbound planning goes wrong, in both directions. Providers impose their own daily sending limits per mailbox, so volume is spread across several. But more mailboxes is not a free lever: each is another identity a recipient may not recognise, another reply address someone has to watch, and another thing to pay for.
The platforms handle this very differently, and it is the single biggest hidden cost difference between them.
| Platform | Sending accounts included | Warm-up included |
|---|---|---|
| Instantly Growth, $47.00 a month | Unlimited email accounts | Unlimited email warm-up |
| Woodpecker at 500 prospects, $35.00 a month | Unlimited email accounts, marked free | 2 warm-ups, marked free |
| lemlist Email, $69.00 a month | Unlimited users and email senders | Email warm-up and deliverability hub |
| lemlist Multichannel, $109.00 per user a month | 5 senders per user | As the Email plan |
| Snov.io Starter, $39.00 a month | Unlimited senders | 3 email warm-ups |
Two things fall out of that table. First, mailbox count is not what any of these vendors is charging you for — which is why the per-inbox pricing question has an awkward answer. Second, the mailboxes themselves still cost money somewhere: every one of them is a mailbox at Google, Microsoft or another provider, billed by that provider, and none of the figures above includes it.
Warm-up, and what it is honestly for
Warm-up features send low volumes of mail between accounts in a shared pool and mark the results as wanted, so a brand-new mailbox has some history before it sends anything real. Every platform here offers it, and Instantly includes it without limit on its cheapest plan.
What can be said about warm-up from published documentation is that it exists, that it is included at these prices, and that a new domain has no history until something gives it one. What cannot be said, by this site or by anyone who has not measured your specific case, is what it does to your delivery rate. Any figure attached to that claim is either a vendor's own marketing or an invention, and there will not be one here.
Build the list so that the opt-outs are real
The technical setup is the easy half. The part that decides whether an outbound programme survives is list hygiene, and two rules carry most of it.
- Keep a suppression list and screen every new list against it. The ICO's guidance on B2B email says it "makes good business sense for you to keep a 'do not email or text' list of any corporate subscribers that object or opt-out of your direct marketing by electronic mail", and adds that you should screen new lists against it. Under US law it is not optional at all: the FTC requires an opt-out to be honoured within 10 business days.
- Verify before you send, and understand what verification returns. A verifier tells you whether an address exists, not whether the person behind it wants to hear from you. And a credit spent on verification is not a guarantee: Snov.io's own documentation says it charges a credit for a "yellow" address it could not fully verify, alongside the ones it could. What a credit actually buys.
The bounce rate that follows from skipping those two is the one thing in this whole area that genuinely and immediately damages a sending domain, and it is entirely within your control before a single message goes out.
A realistic order for the first fortnight
- Register the outbound domain and point it at a mailbox provider. Nothing on this site earns anything from that choice.
- Create the mailboxes you have decided you need, and no more.
- Add SPF and DKIM for each, then a DMARC record at
p=noneso reports start arriving before any policy is enforced. - Turn warm-up on and leave it alone.
- While it runs, build and verify the list, and write the suppression process down before you need it.
- Send to a small, specific, genuinely relevant list first. Volume is the last dial to move, not the first.
The tool you use for steps four through six is the subject of the platform comparison. Steps one to three are the same whichever you pick, which is why they come first.
Questions about outbound sending setup
Do I need SPF, DKIM and DMARC for cold email?
Set all three. Microsoft's published requirement applies to domains sending more than 5,000 emails per day into Outlook.com consumer addresses and asks for SPF to pass, DKIM to pass and DMARC at "At least p=none" aligned with one of them. Most outbound programmes sit under that threshold, but the records cost nothing and a domain without them is indistinguishable from one being forged.
How many inboxes do I need for cold email?
Fewer than most guides suggest, and the platforms mostly will not charge you for them either way — Instantly, Woodpecker and lemlist's Email plan all include unlimited sending accounts. The real constraint is the daily limit your mailbox provider imposes and the number of reply addresses a person can actually watch. The costs are broken down on the per-inbox page.
Will warm-up get my emails into the inbox?
Nobody honest can promise that, and this site publishes no delivery figures at all because it has measured none. Warm-up gives a new mailbox some history; what happens after that depends on who you write to and whether they want it.
Can I use my company's main domain?
You can, and the risk is asymmetric: a bad outbound run damages the reputation of whatever domain sent it, and that domain is also carrying your invoices and password resets. A separate outbound domain is the cheaper mistake to make.
Does using a separate domain mean hiding who I am?
No, and it must not. Both the FTC guide and the ICO's PECR guidance require that a sender's identity is not disguised or concealed and that a valid contact address is provided. A second domain that plainly belongs to your business is fine; one chosen so nobody can tell who is writing is the thing the rules exist to stop.