Cold Email Infrastructure: Domains, Inboxes and Warm-Up
Cold email infrastructure is the setup that gets your outreach into the inbox: separate sending domains, authenticated with SPF, DKIM and DMARC, a set of inboxes warmed up gradually, sending spread across those inboxes, every address verified before sending, bounces suppressed between sends, and daily monitoring. Skip any piece and even great copy lands in spam.
What is cold email infrastructure?
It is everything between your message and the prospect's inbox. Copy gets the attention, but infrastructure decides whether the email is seen at all. Mailbox providers such as Google and Microsoft judge each message partly on who sent it, whether the sender can prove its identity, how that sender has behaved before, and how recipients react.
A sound setup has seven parts. Each one covers a different way cold email fails.
The seven layers, and what breaks without each
Build them in this order. Most teams start with the sending tool and add the rest after a problem. It is cheaper to do it the other way round.
| Layer | What it is | What goes wrong without it |
|---|---|---|
| Sending domains | Separate domains that look like yours, used only for outreach | Your main domain's reputation takes the damage |
| Authentication | SPF, DKIM and DMARC records on each sending domain | Providers cannot confirm the mail is really from you |
| Inboxes | Several real mailboxes per domain, with names and signatures | Too much volume from too few senders |
| Warm-up | A slow build of normal sending history before outreach | New senders look like spammers from day one |
| Verification | Checking each address is real before it is sent to | Bounces pile up and reputation drops |
| Suppression | Removing bounced, unsubscribed and opted-out contacts between sends | You email the same dead or unwilling addresses again |
| Monitoring | Daily checks on bounces, replies, complaints and placement | Problems surface weeks late, after the damage |
Why you should never send cold email from your main domain
Your main domain carries your invoices, your support replies, and your customer email. If prospecting hurts its reputation, all of that starts landing in spam too. So outreach goes out from separate sending domains instead.
A sending domain is a close variation of your brand, such as a version with "get" or "try" in front of your name, or a different ending. Point each one to your main website so a curious prospect lands in the right place. Use several domains rather than one, so a problem on one does not stop the whole program. If a domain's reputation is damaged, you rest it or retire it. Your main domain never notices.
SPF, DKIM and DMARC in plain words
These are three short text records you add to each sending domain's DNS settings. Together they let a mailbox provider check that an email claiming to be from your domain really is. Your email host and sending tool give you the exact values to paste in.
- SPF is a guest list. It names the servers allowed to send email for your domain. If mail arrives from a server not on the list, the provider gets suspicious.
- DKIM is a tamper-proof seal. Your mail server signs every message with a private key, and the matching public key sits in your DNS. The receiver checks the seal, which proves the message came from you and was not changed on the way.
- DMARC is the instruction sheet. It tells providers what to do when a message fails the SPF or DKIM check: let it through, send it to spam, or reject it. It also asks providers to send you reports on who is sending as your domain.
- A sensible order: set up SPF and DKIM first, add DMARC in monitoring mode, read the reports, then tighten the policy once you know all your real mail passes.
How does email warm-up work?
A brand-new inbox has no history. If it suddenly sends a large batch of email to strangers, providers treat it the way they treat spammers, because that is exactly what spammers do. Warm-up builds a normal history first.
In practice, a warm-up tool sends a small number of messages each day between inboxes in a shared network. Those messages get opened, replied to, and moved out of spam if they land there. Over several weeks the tool slowly raises the volume. Providers see a sender that behaves like a real person and gets real engagement.
Start warm-up on day one, while the list is still being built. Do not rush it. Follow your sending tool's ramp guidance rather than a number from a blog post, and keep a low level of warm-up running once real outreach starts. When you add new inboxes later, warm them before they carry any campaign.
Inbox rotation: spread the load
Rather than pushing more mail through one inbox, spread it across many. Each inbox sends a modest, steady amount each day, and the sending tool rotates contacts across them. If you need more volume, add warmed inboxes. Do not raise the cap on the ones you have.
To size it, use your own inputs: contacts to reach, times the number of emails in your sequence, divided by the daily cap you set per inbox and the number of sending days. That gives you the inbox count. For a B2B SaaS client in fleet safety, we ran five persona campaigns to 9,962 verified contacts across 35 inboxes.
Verification and suppression protect everything else
A bounce tells the provider you sent to an address you did not check. Enough of them and your reputation falls, even for mail to good addresses. So verify every address before the first send, and again before later sends if the list has aged.
Then suppress between sends: remove hard bounces, unsubscribes, and anyone who asked not to be contacted before the next touch goes out. In our own campaign, list verification and suppression cut the hard bounce rate from 11.17% to 0.43%. For the fleet safety client, hard bounces fell from 1,637 on the first send to 75 on the third send of the same campaign wave, with suppression between sends.
What should you monitor every day?
Infrastructure is not set and forget. Check these daily, per domain and per inbox, so one bad sender does not hide inside a healthy average.
- Bounces: a sudden rise points to a bad list segment. Pause it and re-verify.
- Replies by category: interested, not now, wrong person, unsubscribe. A drop in replies can be the first sign of spam placement.
- Spam complaints and unsubscribes: rising numbers mean the targeting or the message is off.
- Authentication: confirm SPF, DKIM and DMARC still pass after any DNS or tool change.
- Placement tests: send test messages to seed inboxes to see whether you reach the inbox or spam.
How Trexinet runs sending infrastructure
Trexinet sets up and runs the full stack for B2B clients: separate sending domains, authentication, warm-up, inbox rotation, verification, suppression, and monitoring. AI researches and drafts. A human approves every send. In 2026 we have sent 170,000+ emails across client programs and our own marketing, and verified 30,000+ contacts before sending.
If you want this built for your market, we write a free 30-day pipeline plan within one business day.
Related reading
- What is a GTM engineer? A plain guide for B2B teams
- Waterfall enrichment: why verification is the other half
- AI cold email outreach: what changes and what doesn't
- GTM engineering, built and run for you
Frequently asked questions
How long does email warm-up take?
Weeks, not days. A new inbox needs time to build a normal sending history with real engagement before it carries outreach. The exact ramp depends on your provider and sending tool, so follow their guidance. Start warm-up the day the domains are live, and build and verify the list in parallel so both finish together.
Do I really need separate domains for cold email?
Yes. Your main domain handles customer email, invoices, and support. If outreach damages its reputation, that mail starts landing in spam too. Separate sending domains carry the risk instead. If one is damaged, you rest or retire it and your business email keeps working. Point each sending domain to your main website.
How many inboxes do I need?
Work it out from your own numbers. Multiply the contacts you want to reach by the emails in your sequence. Divide by the daily cap you set per inbox, then by your sending days. That is your inbox count. Add a few spares so you can rest an inbox without slowing the program.
Is a warm-up tool enough to fix deliverability?
No. Warm-up builds history, but it cannot offset an unverified list, missing authentication, or messages nobody wants. If bounces are high or replies are rare, providers will notice regardless of warm-up. Treat warm-up as one layer alongside verification, suppression, authentication, steady pacing, and relevant copy.
Should my DMARC policy be strict from the start?
Start in monitoring mode. That way providers send you reports without blocking anything, and you can confirm that every legitimate sender, including your sending tool, passes SPF and DKIM. Once the reports look clean, tighten the policy so failing mail goes to spam or is rejected.
Can I use Google Workspace or Microsoft 365 inboxes for cold email?
Many teams do, and they work well when set up properly. Each inbox needs its own warm-up, correct authentication on its domain, and a steady daily cap. Always check the provider's current terms and sending limits before you start, since both providers publish their own rules and can change them.
About the author
Saptarshi Basu · Founder & CEO, Trexinet Inc.
Saptarshi Basu is the founder and CEO of Trexinet Inc., which runs fully managed AI voice agents for home-service trades and AI-assisted marketing programs for B2B teams. He writes from the calls, setups and campaigns Trexinet runs for its own customers.