DELIVERABILITY, DONE RIGHT  //  dedicated domains, warmed inboxes, real inbox placementApply
Deliverability

Cold email deliverability: the thresholds that decide inbox placement

Updated August 2026  //  by Mark Glazer  //  every number here is one we run our own infrastructure on

The short answer: inbox placement depends on authentication, reputation, recipient feedback, message content and sending behaviour. SMTP acceptance does not prove inbox placement. Check the receiving provider's requirements and actual delivery responses; no mailbox volume, warming period or content score guarantees placement.

Most deliverability advice is adjectives. This page is the numbers: the thresholds providers actually enforce, and two lessons from our own bounce forensics that change how you read a bounce report.

The 0.3 percent complaint line

Google recommends a Postmaster spam rate below 0.1% and avoiding 0.3% or higher. Yahoo requires a rate below 0.3%. Use each provider's measurement, rather than substituting a campaign bounce or unsubscribe rate. Complaints can reflect unwanted mail, content, frequency or recipient expectations; relevance alone cannot prevent them. Google guidance; Yahoo requirements. See also why cold emails go to spam.

A working bounce limit and response-based investigation

ReplyLead uses a 2% bounce rate as an internal review threshold, not a universal provider cutoff. Investigate a new spike promptly: invalid addresses, recipient policy refusals and temporary failures require different responses. Rechecking addresses can reduce stale-list risk but cannot guarantee acceptance. Read SMTP diagnostics and provider guidance before resuming affected sends.

Gmail and Yahoo have different bulk-sender definitions

Google counts roughly 5,000 messages in 24 hours to personal Gmail accounts, aggregated by primary domain; assigned bulk status persists. Yahoo does not publish a fixed volume threshold. Both have requirements for smaller senders as well. Google scope and classification; Yahoo classification. Bulk authentication includes SPF, DKIM and DMARC; marketing or subscribed mail has unsubscribe requirements. Check message type, alignment and the full Gmail requirements and Yahoo requirements before sending.

SPF has a limit on DNS-querying terms

SPF evaluation permits at most 10 DNS-querying terms: include, a, mx, ptr, exists and redirect, including evaluated nested terms. Exceeding the limit returns SPF permerror. That result does not by itself describe DKIM or the final DMARC result; recipient policy also matters. RFC 7208, section 4.6.4. The deliverability checker helps inspect DNS configuration; it does not test inbox placement.

Our operating settings are not provider guarantees

ReplyLead's stated operating settings are 10–12 cold emails per mailbox per day on Google Workspace, 1–2 on Microsoft 365, and an initial 2–2.5-week preparation period. These are operating choices, not published safe-sending limits or proof a mailbox is ready. Check authentication, recipient expectations, provider responses and reputation as volume changes. More mailboxes do not exempt a sender from provider policies.

The ramp is in our email warmup guide, the capacity arithmetic is worked through in how many cold emails per day, and the reason placement risk is spread across separate provider pools rather than concentrated in one is in cold email infrastructure.

Deliverability is not one thing: it depends who receives the email

A recipient's MX record can identify a hosting provider or front-end gateway. Our 9,058,780-domain census describes this infrastructure; it does not measure inbox placement or establish which provider is easiest to reach. Tenant settings and additional filters may differ behind the same MX classification. What happened when we actually sent to each group is measured in cold email reply rates by email provider.

Receiving environment Share in the domain census What the classification tells you What to verify
Microsoft 36528.48%Microsoft hosting classification; individual tenant policies can differ.Authentication results, recipient responses and tenant-specific restrictions.
Google Workspace25.84%Google hosting classification; business Workspace recipients are distinct from the personal-Gmail scope above.Recipient-domain settings and observed SMTP responses.
Security gateway
(Proofpoint, Mimecast, Barracuda)
6.45%Visible security gateway; it may front another mailbox platform.The gateway's response and the underlying recipient policy where known.
Self-hosted and regional hosts30.89%Other classified hosting environments, with varied configurations.The actual provider and response codes before diagnosing a failure.

The practical consequence is the mistake most senders make: a single blended sending setup treats a Microsoft tenant and a Google mailbox identically, so it over-sends into the strict environment and wastes headroom in the tolerant one. We run separate pools per receiving environment, sized to each, so a bad day on one pool cannot stop the whole programme. You can read any prospect domain's environment before you add it to a list with the mail provider lookup or the technographic signal tool.

Bounce forensics: distinguish invalid addresses from policy refusals

A bounce counter alone does not distinguish a nonexistent mailbox from a gateway policy refusal. Read the full SMTP status, enhanced code and diagnostic text, then check the receiving provider's documentation. A 550 response or a domain name in its text does not by itself establish the root cause. Our mail provider lookup identifies the visible receiving environment for further investigation.

How common is that receiving side? We resolved the MX records of every distinct email domain in a 188 million lead database and classified who receives the mail: across 9,058,780 domains, 6.45 percent sit behind a security gateway and 52.89 percent are Microsoft 365 or Google Workspace. That is the denominator missing from most bounce post-mortems, and it is published in full on who actually receives B2B email.

Keep domain reputation separate from address validation

Domain or URL reputation issues need a different investigation from invalid recipient addresses. Preserve the rejection evidence, review the identified listing and follow its remediation process. Separate sending domains do not guarantee isolation of reputation effects. A domain-name generator can help plan names, but naming variety cannot establish that mail will be accepted.

Content signals, in one number

The spam checker highlights 1,130 terms and other text patterns for editorial review. Its scoring is a heuristic; it cannot see provider reputation, recipient preferences or final folder placement. Assess wording alongside infrastructure and recipient feedback. Neither plain text nor successful authentication guarantees the inbox.

This page is the checklist we run for clients: dedicated domains, full authentication, warmed mailboxes, live verification before every send, and monitoring on all of it, paid for out of the revenue we help close. The business case in numbers is in the ROI calculator, and the longer version of the model is on why ReplyLead.

When a send fails, the code says why. SMTP error codes lists every response Google and Microsoft document for Gmail and Microsoft 365, and what each means for a cold email.

Common questions

What is a good bounce rate for cold email?

We use 2% of recent sends as an internal review threshold. It is not a universal safe rate. Investigate changes and classify the SMTP responses before choosing a remedy; address failures and policy refusals are different problems.

What spam complaint rate gets you filtered?

Check the receiving provider's published guidance and dashboard definition. A complaint threshold is not a guarantee that mail below it reaches the inbox. Complaints, bounces and unsubscribes are distinct metrics.

Do the bulk-sender rules apply if I send fewer than 5,000 a day?

Yes. Smaller senders still have requirements. Gmail's bulk definition concerns personal Gmail recipients and primary-domain volume; Yahoo does not specify a numerical bulk threshold. See the linked provider requirements above.

Why does my SPF record fail when it looks correct?

Possible causes include syntax errors, multiple SPF records or excessive DNS-querying terms. More than 10 evaluated DNS-querying terms produces SPF permerror; it does not automatically mean DKIM fails. Use the deliverability checker and inspect actual authentication results.

Are vendor-verified leads safe to send to?

A validation result has a time and scope. Addresses can change, and a receiving server can reject valid addresses for policy reasons. Recheck stale data, honour suppression requests and inspect current responses; a vendor label is not a delivery guarantee.

Are all bounces caused by bad email addresses?

No. Invalid addresses, temporary service failures and recipient policy refusals can all appear in delivery reporting. Read the full diagnostic and provider documentation; a 550 code alone does not identify the cause.

We investigate delivery with you

Dedicated domains, full authentication, warmed mailboxes and live list verification, built and monitored for our clients, paid out of the revenue we help close.

Apply to work with us Check your domain now

Related reading: why verified email lists still bounce, the six traps behind our own 7.05 percent bounce postmortem. Also: cold email infrastructure, how to architect domains and mailboxes, and the header analyzer for reading what a receiver actually did.