Skip to content
B2B Customer Acquisition

How to Send B2B Cold Email Without Hitting the Spam Filter

By Binode5 min read

Deliverability is an infrastructure problem, not a copy problem. SPF, DKIM, DMARC, and the warm-up process.

Code editors displayed on a computer screen

In short: cold email lands in spam because of infrastructure far more often than because of copy. Since 2024, Gmail has required senders of more than 5,000 messages a day to pass SPF, DKIM, and DMARC, to include a one-click unsubscribe link, and to keep their spam complaint rate below 0.3%. A campaign sent without those three records in place will be filtered no matter how good the writing is.

Why it is infrastructure, not copy

Teams sending cold email usually look for the problem in the subject line. But the filter looks at the sender before it reads the message: who is this domain, how has it behaved, can its identity be verified?

Knowing that order matters, because improving the wrong thing wastes time. Flawless copy from an unauthenticated domain performs worse than ordinary copy from an authenticated one.

Three records: SPF, DKIM, DMARC

Together these answer one question: did this domain really send this email?

SPF is a DNS record listing which servers are authorized to send mail on behalf of your domain. The receiving server checks whether the message came from one of them.

DKIM adds a cryptographic signature to every outgoing message. The recipient verifies it against the public key in your domain's DNS; if the signature holds, the message was not altered in transit and genuinely came from you.

DMARC says what to do when the first two fail, and sends you reports. The policy starts at none (report only) and moves to quarantine or reject once the infrastructure is proven.

Sending without all three both lowers deliverability and leaves your domain open to someone else sending mail in its name.

Domain strategy

Cold campaigns should not go out from your primary domain. If a campaign goes badly, the domain that suffers is the one your invoices and contracts also travel on.

The common and correct approach is separate, similar domains: if the primary is company.com, sending happens through company.co or companyapp.com. Each domain gets a few mailboxes and sending is spread across them.

That separation keeps the campaign's risk away from the company's daily communication.

Warm-up: a new domain cannot send immediately

A new domain has no sending history, and filters do not trust a sender without one. Warm-up is the process of building that history by raising volume gradually.

In practice it takes two to four weeks. It starts with a handful of messages a day, volume climbs step by step, and during that period real correspondence that receives replies is generated — because filters look at interaction, not only at sending.

Skipping warm-up is the most common and most expensive mistake: the domain is blacklisted in the first week and takes months to recover.

List quality and complaint rate

Gmail's threshold is explicit: the complaint rate must stay under 0.3%. That means no more than three complaints per thousand messages.

Holding that threshold is a list problem, not a copy problem. Sending to unverified addresses raises bounces, and the bounce rate directly lowers sender reputation. Verifying addresses before sending is the highest-return step in the whole campaign.

Every message must also carry a one-click unsubscribe link. That is no longer a courtesy but one of Gmail's bulk-sender requirements — and in practice it works in your favour, because it lowers the complaint rate.

Checklist

Before sending:

  • A separate sending domain is registered; the primary domain is protected
  • SPF, DKIM, and DMARC records are configured and verified
  • DMARC starts at none, with reports routed to an address
  • The domain has been warmed for two to four weeks
  • The list is verified and invalid addresses removed
  • Every message carries a one-click unsubscribe link
  • Complaint and bounce rates are monitored
  • The lawful basis for processing is assessed and documented

The last item is not optional wherever you operate: a recipient's rights in commercial electronic messages, and the lawful basis for processing their data, are a separate matter from deliverability and have to be satisfied on their own terms.

Frequently asked questions

How many emails count as safe? There is no fixed number; behaviour matters more than volume. A few dozen messages per mailbox per day is a common ceiling on a warmed domain, but your complaint and bounce rates are what actually set the limit.

We got blacklisted — what now? Stop sending, find the cause (usually an unverified list or a skipped warm-up), clean the list, and file a delisting request with the relevant blocklist. Retrying immediately on the same domain makes it worse.

Does AI personalization improve deliverability? Indirectly, yes. Personalization lifts reply rates, a sender who receives replies gains reputation, and reputation determines deliverability. But personalization alone produces nothing without the infrastructure in place.

Can we never send from our primary domain? Correspondence with existing customers and transactional email of course goes from the primary domain. What has to be separated is cold campaigns.

Sources

  • Google, Email sender guidelines — from February 2024, senders of more than 5,000 messages a day must pass SPF, DKIM, and DMARC, offer one-click unsubscribe, and stay under a 0.3% spam complaint rate.
  • Microsoft, Sending mail to Outlook.com — sender authentication and reputation requirements.

Closing

In cold email, copy starts to matter once the infrastructure is right. The order is fixed: separate domain, three authentication records, warm-up, verified list — then content.

See our B2B customer acquisition service.

Book a free discovery call

Let's find out where your organization stands

In a free 30-minute discovery call, we'll talk through your current state and the right first move.

Book a Call