imoji 1
Get up to 600 credit/month for free. Register Now
Illustration of a pre-send checklist clipboard with ticked boxes beside a paper plane ready to launch, for cold email deliverability

Cold Email Deliverability Checklist: 12 Checks Before You Hit Send

Most cold email disasters are visible before the first message leaves. The bounce spike, the spam folder, the burned domain: each one announces itself in advance, if you know where to look. This cold email deliverability checklist is that look: 12 checks across domain, list, and send, each with what to check, why it matters, and how to verify it in under a minute. Budget about 15 minutes before you send a cold email campaign. It’s the companion to our full cold email marketing guide, which covers the strategy; this page only cares whether you’re ready to send today.

Your domain (checks 1-4)

Your domain is your identity as a sender; if these four fail, nothing else on this page matters.

1. Your sending domain is warmed up

A warmed domain has weeks of gradual, real sending behind it: small volumes, growing slowly, with actual replies coming back. A domain registered last Tuesday has none of that, and mailbox providers can see its age the moment your first message arrives.

Why it matters: a young domain with no history gets judged on its worst signal, and cold outreach always produces a few bad signals.

Check it: look up the domain’s registration date (any WHOIS lookup shows it) and glance at your sending logs. Less than three or four weeks of gradual activity? Today is a warm-up day, not a campaign day.

2. SPF is set up and passing

SPF is the DNS record that lists which servers are allowed to send mail for your domain.

Why it matters: without it, receiving servers can’t confirm your sending tool is authorized, and unverifiable mail from a stranger is an easy filtering decision.

Check it: send a test email from your cold email tool to a Gmail or Outlook account you own. In Gmail, open the message’s three-dot menu and pick “Show original”; in Outlook, view the message headers. Near the top you’ll see spf=pass or spf=fail. The same test covers the next two checks.

3. DKIM signing is on and passing

DKIM adds a cryptographic signature to every message, proving it really comes from your domain and wasn’t tampered with along the way.

Why it matters: providers now expect authentication from anyone sending in volume, and an unsigned message starts in the suspicious pile.

Check it: same test email, same header view. Look for dkim=pass next to the SPF result. Your sending tool probably has a domain status page too, but the headers are the ground truth.

4. A DMARC policy is published

DMARC ties SPF and DKIM together and tells receiving servers what to do with mail that fails them.

Why it matters: Gmail and Yahoo require DMARC from high-volume senders and treat it as a trust signal from everyone else.

Check it: the same “Show original” view shows dmarc=pass. If any of the three reads fail, or doesn’t appear at all, stop and fix it first. Our plain-English guide to SPF, DKIM and DMARC walks through the whole setup in under an hour.

Your list (checks 5-8)

The full guide says it bluntly: most cold email failures are list failures wearing a disguise. These four checks catch them while they’re still cheap.

5. Every address was verified in the last 30 days

Not “verified once, back in spring.” Lists decay constantly as people change jobs and mailboxes get deleted, so a verification result has a shelf life of roughly a month.

Why it matters: cold senders have no reputation cushion, and every dead address converts directly into a hard bounce that providers hold against you.

Check it: open your list file and look at the verification date (any decent verifier stamps one). Older than about 30 days, or addresses added since? Re-verify before sending. And if the list came from scraping or an import, put it through the fuller scraped-list cleaning workflow first.

6. Hard bounces from previous sends are suppressed

Every address that ever hard-bounced for you should sit on a suppression list that today’s campaign respects.

Why it matters: repeatedly mailing a known-dead address is the clearest “careless sender” signal you can hand a mailbox provider.

Check it: confirm your tool’s suppression list is active for this campaign, then make sure today’s list wasn’t rebuilt from an old export that predates those bounces. Re-imports are how dead addresses sneak back in.

7. Role addresses got a deliberate decision

info@, sales@, support@, office@, addresses that belong to a function rather than a person.

Why it matters: they’re read by nobody in particular or by several people at once, which means fewer replies and a better chance someone flags a message that wasn’t meant for them.

Check it: filter your list for the common role prefixes and look at each group. Keeping some can be the right call (office@ is often the only door into a small local business), but every role address should be a choice, not a leftover.

8. Catch-all and unknown addresses are in their own batch

A catch-all domain accepts mail for any address, so no verifier can promise a mailbox actually exists there. Unknowns are addresses that never returned a definitive answer.

Why it matters: these are the addresses most likely to bounce late or swallow your message silently, and you don’t want that risk mixed into the send your reputation depends on.

Check it: sort the list by verification status. Valid addresses go in the main send. Catch-all and unknown go into a separate, smaller batch to send later, if at all.

Your send (checks 9-12)

Domain authenticated, list clean. The last four checks are about not fumbling the send itself.

9. Today’s volume matches your reputation

The number of emails you plan to send today should fit your domain’s age and history, not your ambition.

Why it matters: a sudden burst from a young domain looks exactly like a spammer waking up, and providers respond by filtering first and asking questions never.

Check it: on a young domain, keep it to dozens per day, not hundreds, and grow only across weeks of clean results. Then check the schedule: sends spread through the day read as human, a single 9:00 blast does not.

10. The message passes the plain-and-personal test

Four quick sub-checks: no heavy HTML or images, no attachments, one or two links at most, and a sentence that could only have been written to this recipient.

Why it matters: a cold email is a stranger’s handshake, and the more it resembles a marketing template, the faster it dies.

Check it: read the message as the recipient would. If you can’t point to the line that explains why you’re writing to them specifically, it isn’t ready, and nothing else on this checklist can save it.

11. The opt-out works, without you

There’s a working way for recipients to decline further email, and using it triggers suppression automatically.

Why it matters: a functioning opt-out is what keeps legitimate B2B outreach on the right side of most laws, and for the recipient, the alternative to an easy no is the spam button.

Check it: send yourself a test, use the opt-out, and confirm the address lands on your suppression list with no human involved. One minute now against a complaint later.

12. You know where you’ll watch, and when you’ll pause

Before anything goes out, you can name the exact screen where bounces and replies will appear, and you’ve already picked the number that stops the send.

Why it matters: the difference between a rough hour and a burned domain is how fast you pause.

Check it: open your tool’s live campaign or bounce report now, not mid-send. Set the threshold in advance: our bounce-rate benchmarks put the danger line around 2%, so a spike past that means pause, find the failing segment, and only then continue. And if deliverability already tanked on a previous campaign, first check whether your domain is blacklisted: sending harder into a blacklist only deepens the hole.

The printable version

The whole cold email checklist in one block. Copy it and run it top to bottom before every campaign:

  • ☐ 1. Sending domain has weeks of gradual warm-up history
  • ☐ 2. SPF passes on a test email (“Show original” in Gmail)
  • ☐ 3. DKIM passes on the same test
  • ☐ 4. DMARC policy published and passing
  • ☐ 5. Every address verified within the last 30 days
  • ☐ 6. All previous hard bounces suppressed
  • ☐ 7. Role addresses kept only on purpose
  • ☐ 8. Catch-all and unknown addresses split into a separate batch
  • ☐ 9. Volume fits the domain’s age, spread through the day
  • ☐ 10. Message is plain and personal: no attachments, few links, a real reason
  • ☐ 11. Opt-out tested and suppressing automatically
  • ☐ 12. Monitoring open, pause threshold decided (bounce spike = stop)

Eleven of these take a minute each. The one people actually skip is number 5, and it happens to be the easiest to fix: a free Reoon Email Verifier account comes with free verification credits every day, no card required, enough to verify a sample of your list today and the rest before your send date. Run the checklist, fix what fails, and hit send knowing that nothing on this page is what kills the campaign.

FAQ

How long before sending should I verify my list?

As close to the send as practical; the same week is ideal, and anything older than about 30 days is stale. A clean result from three months ago describes a list that no longer exists. If you added addresses after verifying, verify those too.

Do I need all of SPF, DKIM and DMARC for cold email?

Yes. They work as a set: SPF authorizes your sending servers, DKIM signs each message, and DMARC tells receiving servers how strictly to enforce the other two. An established sender might coast on partial setup for a while; a cold sender has no history to fall back on, so authentication does all the vouching. Setup takes under an hour.

What bounce rate should make me stop a cold campaign?

Treat 2% as the line. Under it, keep going and keep watching. A spike past it mid-send means pause, work out which segment is bouncing, remove it, and re-verify before resuming. Domains get ruined not by hitting a bad batch but by letting a 10% bounce rate run to completion.

How many cold emails can I send on a new domain?

Fewer than you’d hope. There’s no official number, but experienced senders start with a handful a day and reach a few dozen only over several weeks, increasing only while bounces stay near zero and real replies keep arriving. Volume is something a domain earns; a new domain pushing hundreds on day one is the pattern providers filter hardest.

Share The Blog With Your Friends

Related Blog Posts