How To Warm Up A New Sending Domain Safely
A practical, permission-first guide to establishing a new sending domain without damaging trust, overwhelming recipients or mistaking volume for deliverability.
A new sending domain starts with little or no sending history. That does not make it suspicious by itself, but it does mean mailbox providers have less evidence about whether recipients want its messages. A safe warm-up is the process of building that evidence gradually: send wanted email, first to people most likely to recognise and value it, at a steady pace that your infrastructure and audience can support.
It is not a shortcut to the inbox, and it is not an exercise in manufacturing opens or replies. Attempts to simulate engagement, use purchased data or send cold prospecting at scale create the very negative signals a warm-up is meant to avoid. For permission-based marketing, lifecycle and customer email, the most reliable approach is simpler: authenticate properly, start with your strongest consented audience, make opting out easy, and expand only when the results justify it.
What Domain Warm-Up Actually Means
Mailbox providers assess more than an IP address. They can consider the domain visible to recipients, the domain that signs the message, message authentication, sending patterns, complaints, engagement and technical delivery behaviour. A new domain therefore needs to establish a consistent, positive record over time.
“Warming a domain” is often used loosely. In practice, it involves four jobs:
- Establish identity: prove that your legitimate sending service is authorised to send for the domain.
- Establish consent and relevance: send to people who knowingly signed up and will recognise the sender and message.
- Establish predictable behaviour: increase volume in measured steps rather than switching from zero to a major broadcast.
- Establish feedback loops: detect bounces, complaints, deferrals and authentication failures before they become a pattern.
Warm-up applies most directly to the domain used in the visible From: address and the aligned authentication domains. If you change to a different organisational domain, treat it as a fresh reputation-building exercise. A new subdomain may also need its own history, even where the parent domain is established. Conversely, changing only the creative or a display name is not domain warm-up.
Do The Foundations Before Sending A Single Campaign
1. Set Up SPF, DKIM And DMARC Correctly
SPF is a DNS record that identifies services permitted to send mail for a domain. DKIM adds a cryptographic signature that receiving systems can verify. DMARC builds on them by checking whether the visible From: domain aligns with SPF or DKIM, and by publishing a policy and reporting address.
For senders delivering more than 5,000 messages per day to personal Gmail accounts, Gmail requires SPF, DKIM, DMARC, alignment of the visible From domain with SPF or DKIM, TLS and support for one-click unsubscribe on marketing and subscribed mail. Gmail says all senders should use SPF or DKIM, TLS, valid forward and reverse DNS, and keep reported spam rates below 0.3%. (Google’s sender guidance)
Yahoo’s sender guidance similarly calls for SPF and DKIM for bulk senders, a valid DMARC policy of at least p=none with DMARC passing, aligned authentication, an easy unsubscribe mechanism and complaint rates below 0.3%. (Yahoo’s sender guidance)
Start DMARC in monitoring mode only after you have inventoried every legitimate service that sends as your domain: marketing platform, transactional provider, helpdesk, ecommerce platform, invoicing tool and any internal system. Use DMARC reports to find legitimate sources that are not authenticating before moving towards enforcement. Do not let a new marketing platform silently break an otherwise healthy domain.
2. Align The Identities Recipients Can See
Use a stable, recognisable sender identity. Ideally, the brand domain in the From address, the DKIM signing domain, the tracking domain and the website recipients land on should clearly belong together. A recipient who sees news@updates.example.co.uk should not be taken to an unrelated or obscure tracking domain.
This is both a trust and diagnostic issue. If a campaign performs poorly, coherent identities make it easier to determine whether the problem is authentication, audience expectations, content, a link destination or volume.
3. Make Unsubscribing Frictionless
Marketing email needs a clear unsubscribe link in the message itself. For larger Gmail senders, one-click unsubscribe is also a technical requirement. The standard uses a List-Unsubscribe header and List-Unsubscribe-Post: List-Unsubscribe=One-Click, with a DKIM signature covering those headers. It is designed so a mailbox provider can send an unsubscribe request without asking the recipient to navigate a confirmation journey. (RFC specification)
Do not treat this as a compliance box-tick. Someone who no longer wants weekly offers should be able to leave the promotional stream quickly, or choose a lower frequency in a preference centre. It is better to lose an unwilling subscriber than gain a spam complaint.
4. Separate Marketing From Critical Customer Mail
Purchase receipts, password resets, service alerts and account notifications have a different purpose and urgency from newsletters and promotions. Keep their streams logically separate, using distinct subdomains or sending identities where appropriate, so a poorly received sale campaign does not unnecessarily complicate critical customer communications. Yahoo explicitly recommends not sending bulk marketing email from the same IPs used for user mail and transactional alerts. (Yahoo’s sender guidance)
Start With Audience Quality, Not Your Entire Database
The safest first recipients are not merely “valid addresses”. They are people with recent, provable permission and a strong reason to expect the email. That typically includes recent purchasers who opted into marketing, recent newsletter subscribers who confirmed a sign-up, active account holders who selected relevant preferences, and subscribers who have clicked or replied to recent messages from your established brand.
Exclude or defer:
- purchased, rented, scraped or otherwise unverified lists;
- contacts without clear marketing consent;
- old imports with no recent relationship or engagement evidence;
- addresses that previously hard bounced, unsubscribed or complained;
- long-inactive subscribers, until the new domain has established stable performance;
- role addresses where appropriate, such as generic team inboxes, if they are not demonstrably engaged.
A validated address is not the same as a willing subscriber. Email verification can reduce the risk of sending to malformed or undeliverable addresses, but it cannot prove consent, relevance or future engagement. Keep consent evidence, including the source, date, form or checkout wording, and any preference selected.
When a list was built under an old brand or domain, explain the change plainly in the first sends: “You are receiving this because you subscribed to [brand] updates; we now send from [new domain].” Use a familiar From name, keep the message focused, and avoid launching a new identity with an aggressive discount or a catalogue of unrelated offers.
Build A Pacing Plan Around Evidence, Not A Universal Number
There is no credible universal daily-volume table for every business. A safe starting point for a retailer with 200,000 subscribers will be different from that for a specialist B2B publisher with 8,000. Provider mix, historic relationship, campaign frequency, list quality, content type and sending infrastructure all matter.
The useful principle is controlled expansion: begin with a small, highly engaged cohort; maintain a steady cadence; then increase only after reviewing meaningful outcomes. Avoid sharp spikes caused by a product launch, a migration deadline or a last-minute “send to everyone” decision.
| Warm-Up Stage | Who Receives It | What To Check Before Expanding |
|---|---|---|
| Prove the setup | Internal seed accounts and a very small group of recently engaged, consented subscribers | SPF, DKIM and DMARC alignment; correct From and Return-Path; unsubscribe operation; rendering and links |
| Establish a pattern | Recent clickers, purchasers and newly subscribed contacts, divided by mailbox provider where practical | Hard bounces, deferrals, complaints, delivery errors and whether the volume is stable day to day |
| Expand carefully | Broader recent engagers, then less-recent but still permissioned subscribers | No material deterioration in complaints, authentication, deferrals or placement indicators |
| Operate normally | The wider opted-in audience, with inactive groups managed separately | Ongoing provider dashboards, fatigue signals, unsubscribe patterns and campaign-level performance |
Increase in increments you can explain and reverse. For example, add the next engagement band after several comparable sends have delivered cleanly—not simply because a calendar date has arrived. If your normal programme involves two emails per week, do not send daily during warm-up just to accelerate the process. Consistency should resemble the relationship recipients signed up for.
Provider-aware pacing is particularly important. Gmail, Yahoo and Microsoft audiences may behave differently, and a problem confined to one provider should not automatically halt wanted mail to all others. Equally, a healthy-looking overall delivery rate can hide provider-specific deferrals or spam placement.
Measure The Signals That Matter
A “delivered” event usually means the recipient server accepted the message. It does not guarantee inbox placement, a human read or future delivery. During warm-up, prioritise signals that reveal whether recipients and mailbox providers accept your mail.
Technical And Provider Signals
- Authentication pass rate: SPF, DKIM and DMARC should pass for the intended sending stream.
- Hard bounces: investigate unexpected rises immediately; suppress invalid recipients rather than retrying them.
- Deferrals and rejects: temporary failures can indicate a rate, reputation or configuration issue; read the SMTP response rather than guessing.
- Complaint rate: complaints are a direct warning that message expectations are wrong. Gmail recommends staying below 0.1% and never reaching 0.3% reported spam rate. (Google’s sender guidance)
- Domain and IP reputation: use provider data as directional evidence, not as a score to chase.
Google Postmaster Tools provides dashboards for compliance status, spam rate, IP and domain reputation, authentication, encryption, delivery errors and feedback loops. It is not real-time, and low volumes may produce limited data, so do not interpret an empty dashboard as proof that everything is fine. (Google’s sender guidance)
For Yahoo, enrol in the Complaint Feedback Loop where eligible. Yahoo says the service is domain-based and requires DKIM-signed outbound email; reports can be used to suppress recipients from future campaigns. (Yahoo’s sender guidance) Monitor Microsoft-facing traffic through the relevant sender tools, including SNDS and JMRP where your sending arrangement makes them available.
Recipient Signals
Clicks, replies, purchases and preference changes can help identify relevance. Opens are less dependable as a warm-up decision metric because privacy features, security scanners and image handling can distort them. Treat a sudden burst of opens or clicks with caution; automated security tools can fetch links without representing human interest.
Look for patterns rather than one lucky campaign: are recent subscribers reading and clicking? Are certain segments unsubscribing at an unusual rate? Did a new creative create more complaints? Is an offer attracting clicks but then causing excessive frequency or buyer’s remorse? This is why content and audience decisions belong in the warm-up plan, not only DNS records.
What To Send During Warm-Up
Send the email people actually expected. The first campaign need not be a “warm-up email”; it should be useful in its own right. Good options include a promised welcome message, a subscriber-only update, a restock alert requested by the customer, a relevant editorial digest or a post-purchase follow-up with practical care guidance.
Keep early campaigns uncomplicated:
- one clear purpose and a truthful subject line;
- a recognisable From name and a reply-capable mailbox;
- brand-consistent design and a concise explanation of why the recipient is receiving it;
- a limited number of reputable, working links;
- a visible unsubscribe link and sensible preference options;
- no misleading urgency, deceptive redirects or unexplained attachment.
Test every send before expanding it. Check desktop and mobile rendering, link destinations, tracking-domain configuration, plain-text readability, authentication headers and unsubscribe processing. A campaign preflight process is valuable because a broken link, malformed header or unbranded destination is much cheaper to fix before the first large send.
When To Pause Rather Than Push Through
Pause increases—and, if necessary, pause the affected campaign—when you see a notable complaint rise, authentication failures, unusually high hard bounces, persistent provider deferrals, rejection codes that point to policy or reputation, or a clear decline in engagement from your initial cohort.
Then work from the evidence:
- Identify the scope: one provider, one segment, one campaign, one link domain or all traffic.
- Read the SMTP responses and provider dashboards.
- Confirm the message passed SPF, DKIM and DMARC alignment.
- Review the affected audience’s consent source, recency, expectation and frequency.
- Remove hard bounces and suppress complaint recipients immediately.
- Correct the root cause, return to the last stable volume, then rebuild gradually.
Do not respond by changing domains again, rotating identities or blasting a different segment. That obscures the diagnosis and can spread the problem. A short, evidence-led pause is often less damaging than forcing volume through a deteriorating reputation.
How Email Foundry Can Support A Disciplined Warm-Up
The process should work in any capable email platform. Where you use Email Foundry, its provider-aware warm-up controls, editable pacing and Safe Sending Speed can help apply a planned ramp rather than relying on manual reminders. Dynamic segments, engagement scoring, List Health and consent evidence can help identify the recent, permissioned cohorts that belong at the front of the queue.
Before each increase, Advanced Campaign Preflight & Inbox Risk, deliverability testing and tracking-domain monitoring can provide practical checks around the campaign and its links. During the programme, bounce processing, Mailbox Provider Recovery, Google Postmaster Tools, Microsoft SNDS/JMRP and Yahoo/AOL CFL connections can bring relevant diagnostic signals into the same operating routine. Human Engagement scoring and bot/security-click filtering are also useful safeguards against treating automated activity as proof that recipients are interested.
These capabilities do not make an unconsented list safe or replace sound judgement. They make it easier to follow the right process consistently and to stop when the evidence says stop.
Practical 30-Day Action Plan
- Days 1–3: audit identity. Choose the marketing From domain or subdomain. Configure SPF, DKIM, DMARC and TLS through your sending provider. Verify DMARC alignment using real test messages. Set up a branded tracking domain if you use tracked links.
- Days 1–5: audit data. Document consent sources. Remove unsubscribes, complaints, hard bounces and duplicate records. Verify uncertain addresses, but do not equate verification with permission. Build segments for recent purchasers, recent subscribers and recent clickers.
- Days 3–7: test operations. Send internal tests to several mailbox providers. Confirm rendering, links, headers, reply handling, preference centre behaviour and one-click unsubscribe. Register available provider monitoring and feedback-loop tools.
- Week 2: send to the strongest cohort. Use one expected, useful message. Keep the volume deliberately limited and the daily pattern steady. Monitor bounces, deferrals, complaints, authentication and recipient response.
- Week 3: expand one engagement band. Only if the first sends are stable, add another recent and consented cohort. Keep creative, frequency and sending configuration broadly consistent so the results remain interpretable.
- Week 4: widen carefully and plan re-engagement separately. Continue controlled growth to more of the active list. Do not fold long-inactive records into the same ramp. Give them a distinct, lower-risk re-engagement strategy—or sunset them if their consent and relationship are no longer clear.
- Every send: retain the right to stop. Review provider-specific data, suppress complaints and hard bounces promptly, investigate abnormal changes, and revert to the last stable level before trying to grow again.
A successful warm-up is not defined by reaching the biggest possible volume in 30 days. It is defined by reaching a sustainable sending pattern in which recipients recognise the sender, want the messages and can easily control what they receive.
Frequently asked questions
How Long Does It Take To Warm Up A New Sending Domain?
There is no fixed period. It depends on list quality, provider mix, volume, cadence and recipient response. Plan for gradual expansion over several comparable sends, and delay increases whenever complaints, bounces, deferrals or authentication issues worsen.
Can I Send My Whole List From A New Domain Straight Away?
Usually, no. Start with recently engaged, clearly consented subscribers and expand in controlled stages. Sending the entire database at once can create a sudden reputation and complaint risk, especially where the list contains old or uncertain records.
Should I Use A Separate Domain For Marketing Email?
A dedicated marketing subdomain or domain can make reputation management clearer, particularly when separating promotions from transactional customer mail. It must still be properly authenticated, aligned and recognisable to recipients.
Do I Need SPF, DKIM And DMARC Before Warming Up?
Yes. Authentication should be working before campaign sending begins. Gmail and Yahoo require stronger authentication and DMARC alignment for bulk senders, while correct authentication is foundational for all legitimate senders.
Are Open Rates A Good Warm-Up Metric?
Not on their own. Opens can be affected by privacy protection and automated image loading. Review complaints, hard bounces, deferrals, authentication, clicks, replies, purchases and provider feedback together.
Does Email Verification Warm Up A Domain?
No. Verification can help identify invalid or risky addresses, but it does not create consent, relevance or recipient engagement. Use it as one hygiene measure alongside consent records and engagement-based segmentation.
What Should I Do If Gmail Or Yahoo Starts Deferring My Messages?
Pause volume increases, inspect SMTP responses and provider dashboards, verify SPF/DKIM/DMARC alignment, review the affected audience and campaign, suppress bad addresses, then resume only from the last stable level after fixing the cause.
Sources and further reading
- Gmail Email Sender Guidelines — Google
- Gmail Email Sender Guidelines FAQ — Google
- Postmaster Tools Dashboards — Google
- Yahoo Sender Best Practices — Yahoo Sender Hub
- Yahoo Complaint Feedback Loop — Yahoo Sender Hub
- RFC 8058: Signaling One-Click Functionality For List Email Headers — IETF / RFC Editor