DELIVERABILITY, DONE RIGHT  //  dedicated domains, warmed inboxes, real inbox placementApply
Deliverability

Cold email deliverability: the thresholds that decide inbox placement

Updated August 2026  //  by Mark Glazer  //  every number here is one we run our own infrastructure on

The short answer: cold email deliverability is the share of your cold sends that lands in the inbox rather than the spam folder. It is decided by a handful of hard numbers: keep spam complaints under 0.3 percent, bounces under 2 percent, SPF under 10 DNS lookups, and conservative per-mailbox volume - around 10 to 12 cold emails per mailbox per day on Google Workspace and around 1 to 2 on Microsoft 365 - after 2 to 2.5 weeks of warmup. Cross 5,000 messages a day to Google or Yahoo and the bulk-sender rules become mandatory.

Most deliverability advice is adjectives. This page is the numbers: the thresholds providers actually enforce, and two lessons from our own bounce forensics that change how you read a bounce report.

The 0.3 percent complaint line

Google and Yahoo hold bulk senders to a 0.3 percent spam-complaint rate, three complaints per thousand delivered messages. That makes complaint rate a targeting metric, not a copy metric: nobody reports a relevant email, and no subject-line trick rescues an irrelevant one. Above the line, placement degrades quickly and is hard to win back. If your mail is already junking and you want the fuller list of causes, start with why cold emails go to spam.

2 percent bounces is the working ceiling, 5 percent is throttling

We run our own fleet to a 2 percent bounce ceiling. Sustained rates above 5 percent invite throttling and blocks regardless of volume or copy quality. The only reliable way to stay under it is to re-verify every list with a live email-verification pass immediately before sending, not when the data was bought. Vendor "verified" flags are not verification: in one of our own audits, 35 of 35 dead mailboxes behind a bounce spike traced back to leads whose vendor validation said valid. A flag written months ago tells you what the address was, not what it is.

The 5,000 a day bulk-sender gate

Send 5,000 messages a day to Google or Yahoo and the bulk-sender requirements stop being recommendations: SPF, DKIM, DMARC and one-click unsubscribe are all required, and mail that fails them is rejected or junked outright. Treat the gate as the baseline at any volume. The same checks protect placement long before you reach the threshold, and retrofitting authentication onto a domain that has already been sending is much harder than doing it first.

SPF fails permanently past 10 DNS lookups

An SPF record is allowed at most 10 DNS lookups. Every include, a, mx and redirect mechanism spends from that budget, and nested includes count too. Exceed it and the record returns a permanent error, which means every message you send evaluates as unauthenticated no matter how clean the rest of the setup is. This is the most common silent failure we see, because each new tool politely asks you to add one more include. Our deliverability checker runs the live 10-lookup audit in your browser, alongside MX, DMARC, DKIM selectors, MTA-STS, TLS-RPT and BIMI.

Conservative per-mailbox volume, after 2 to 2.5 weeks of warmup

Volume is a deliverability control, and the number is lower than most of the industry quotes. We operate 10 to 12 cold emails per mailbox per day on Google Workspace and 1 to 2 on Microsoft 365, where a tenant-wide external-recipient cap makes the architecture different. Total volume scales by adding warmed mailboxes and additional provider pools, never by raising the per-mailbox number - both providers permit far more than we send, and a provider ceiling is an anti-abuse limit rather than a recommendation. A new mailbox needs 2 to 2.5 weeks of warmup before it carries campaign traffic, so real capacity is decided weeks before you need it.

The ramp is in our email warmup guide, the capacity arithmetic is worked through in how many cold emails per day, and the reason placement risk is spread across separate provider pools rather than concentrated in one is in cold email infrastructure.

Deliverability is not one thing: it depends who receives the email

The single largest factor in whether a cold email reaches the inbox is not your copy or even your warmup - it is the recipient's mail provider, and it is readable from their MX record before you ever hit send. We measured the receiving landscape across 8,384,502 business domains, and the three environments that matter behave very differently:

Receiving environment Share of B2B domains What deliverability looks like How we send into it
Microsoft 36528.48%Tenant-level external-recipient throttling plus Defender filtering. The stricter of the two hyperscalers toward an unknown sender.A separate M365 pool at roughly 1 to 2 cold sends per mailbox per day, ramped slowly.
Google Workspace25.84%More predictable, with a higher tolerance for genuine one-to-one mail. The easiest of the three to place in.A Google pool at roughly 10 to 12 sends per mailbox per day.
Security gateway
(Proofpoint, Mimecast, Barracuda)
5.88%A product bought specifically to stop unsolicited mail. The hardest tier: unknown senders are quarantined before a human ever sees them.A dedicated, well-warmed pool, the slowest ramp, and the expectation that some will still quarantine.
Self-hosted and regional hosts30.89%Idiosyncratic - anywhere from weak filtering to niche strictness, provider by provider.A small test send first; let early bounces and replies set the pace before scaling.

The practical consequence is the mistake most senders make: a single blended sending setup treats a Microsoft tenant and a Google mailbox identically, so it over-sends into the strict environment and wastes headroom in the tolerant one. We run separate pools per receiving environment, sized to each, so a bad day on one pool cannot stop the whole programme. You can read any prospect domain's environment before you add it to a list with the mail provider lookup or the technographic signal tool.

Bounce forensics, lesson one: gateway blocks are not bad addresses

In one of our own bounce investigations, 35 percent of blocked deliveries were secure-email-gateway rejections, Mimecast-class appliances refusing mail on the receiving side, not invalid addresses. Most reporting tools file both in the same bounce bucket, so the obvious response, cleaning the list harder, fixes nothing. The rejection string tells you which problem you actually have. One tell worth memorizing: when Gmail returns a 550, it names the sending domain if the domain itself is the problem. An address problem and a domain problem look identical in a bounce-rate chart and need opposite fixes. You can see which environment answers for any recipient domain — Google, Microsoft or a gateway — with our free mail provider lookup.

How common is that receiving side? We resolved the MX records of every distinct email domain in a 188 million lead database and classified who receives the mail: across 8,384,502 domains, 5.88 percent sit behind a security gateway and 54.32 percent are Microsoft 365 or Google Workspace. That is the denominator missing from most bounce post-mortems, and it is published in full on who actually receives B2B email.

Bounce forensics, lesson two: 11 of 16 domains went down together

From our own fleet: 11 of 16 sending domains that shared one obvious name prefix ended up on a URI blocklist together. The pattern was guessable, so one listing became a family listing. Two rules fell out of that day. First, sending domains stay separate from your main domain precisely so this class of damage is isolated and the domains are disposable. Second, never build a mailbox fleet on one recognizable naming pattern: vary the registrations so no single listing can pattern-match the rest of your infrastructure.

Content signals, in one number

Copy matters less than the thresholds above, but it is not nothing. Our spam checker highlights 1,130 trigger words across tiered categories as you type, in the browser, no signup. Run it after the infrastructure is right, not instead of it: clean copy sent through a blocklisted domain still goes to spam, while plain copy from a pristine, authenticated domain usually lands.

This page is the checklist we run for clients: dedicated domains, full authentication, warmed mailboxes, live verification before every send, and monitoring on all of it, paid for out of the revenue we help close. The business case in numbers is in the ROI calculator, and the longer version of the model is on why ReplyLead.

Common questions

What is a good bounce rate for cold email?

Under 2 percent, measured on recent sends rather than lifetime averages, which hide new problems behind old data. Sustained rates above 5 percent invite throttling and blocks. If a spike appears, read the rejection strings before cleaning the list, because gateway refusals and dead addresses need different fixes.

What spam complaint rate gets you filtered?

0.3 percent is the line Google and Yahoo enforce for bulk senders, three complaints per thousand delivered. It is effectively a targeting metric: relevant mail to the right people rarely gets reported, and no copy edit compensates for the wrong list.

Do the bulk-sender rules apply if I send fewer than 5,000 a day?

The hard gate applies at 5,000 messages a day to Google or Yahoo, but SPF, DKIM, DMARC and one-click unsubscribe are worth treating as the baseline at any volume. They protect placement long before the rule forces them.

Why does my SPF record fail when it looks correct?

Most likely the 10-DNS-lookup limit. Nested includes count against the budget, and past 10 the record permanently errors, so all your mail evaluates as unauthenticated. Run the live lookup audit in our deliverability checker to see the real count.

Are vendor-verified leads safe to send to?

Not without a live re-verification pass immediately before sending. A vendor flag describes the address at the time the data was collected, not today. In one of our audits, 35 of 35 dead mailboxes behind a bounce spike carried vendor validation that said valid.

Are all bounces caused by bad email addresses?

No. In one of our investigations, 35 percent of blocked deliveries were secure-email-gateway rejections on the receiving side, not invalid addresses. Read the rejection string: a Gmail 550 that names the sending domain means the domain is the problem, not the list.

We run these thresholds so you never have to watch them

Dedicated domains, full authentication, warmed mailboxes and live list verification, built and monitored for our clients, paid out of the revenue we help close.

Apply to work with us Check your domain now

Related reading: why verified email lists still bounce, the six traps behind our own 7.05 percent bounce postmortem. Also: cold email infrastructure, how to architect domains and mailboxes, and the header analyzer for reading what a receiver actually did.