Cold email deliverability: authentication, sender rules and the law
The best-written email achieves nothing in a spam folder. Most deliverability problems come down to a handful of settings and habits you can check in an afternoon.
Revio AI4 min read
The short version
- Set up SPF, DKIM and DMARC on any domain you send from. The large mailbox providers now expect all three from volume senders.
- Keep spam complaints very low. Google's published threshold is 0.3%, and staying well under it is the goal.
- Make unsubscribing easy and honour it quickly. It is required by law in the US and expected by mailbox providers.
- Protect your main domain. Send cold outreach carefully, at modest volume, from properly configured mailboxes.
What deliverability actually means
Deliverability is whether your email reaches the inbox rather than the spam folder, or is rejected outright. Mailbox providers such as Gmail, Yahoo and Outlook decide this using a mix of signals: whether you are who you say you are, how recipients react to your mail, and how your sending behaves over time.
Authentication: SPF, DKIM and DMARC
These are three DNS records that prove email claiming to come from your domain really does. They are set up once, in the same place you manage your domain.
| Record | What it does | In plain terms |
|---|---|---|
| SPF | Lists the servers allowed to send mail for your domain | A guest list for your domain |
| DKIM | Adds a cryptographic signature to each message | A tamper-proof seal on each envelope |
| DMARC | Tells receivers what to do when SPF or DKIM fail, and sends you reports | Instructions for handling fakes |
A sensible starting point is a DMARC policy of p=none, which asks receivers to report failures without blocking anything. Once reports show all your legitimate mail passing, you can tighten it. The important detail is alignment: the domain in your visible From address should match the domain that passes SPF or DKIM.
What the big mailbox providers now require
In 2024, Google and Yahoo began enforcing clearer requirements for anyone sending to their users, and Microsoft introduced comparable requirements for high-volume senders to Outlook.com consumer addresses in 2025. The details differ slightly, but the core expectations line up:
| Requirement | Applies to | Notes |
|---|---|---|
| SPF or DKIM authentication | All senders | Volume senders are expected to have both |
| DMARC record | Volume senders | Google has cited around 5,000 messages a day to its users as the bulk threshold |
| From domain alignment | Volume senders | Visible From domain matches the authenticated domain |
| Low spam complaint rate | All senders | Google publishes 0.3% as the threshold to stay under |
| One-click unsubscribe | Marketing and promotional mail from volume senders | Using the List-Unsubscribe header standard |
| Valid DNS and encrypted connections | All senders | Reverse DNS and TLS for the sending server |
Even if you send well below the bulk thresholds, meeting these requirements is the easiest deliverability improvement available, and it costs nothing.
Sending habits that protect your reputation
- Start slowly. A new domain or mailbox that suddenly sends hundreds of messages looks like a compromised account. Build volume gradually.
- Cap volume per mailbox. Spread outreach across properly configured mailboxes rather than pushing one hard. Revio enforces a daily cap per mailbox and carries the rest to the next morning.
- Consider a separate domain for outreach. Many teams send cold email from a closely related domain so a problem there cannot affect the main domain used for invoices and customer email. It should still clearly be your business.
- Keep bounces low. Mailing addresses that do not exist is a strong negative signal. Research-based prospecting avoids the stale addresses that come with old lists.
- Write like a person. Plain text, few links, no attachments, no image-only messages.
- Stop when people are not interested. Complaints are the fastest way to damage a domain, and they usually come from people who were contacted too often.
The law: CAN-SPAM in the United States
The CAN-SPAM Act applies to commercial email, including business-to-business email. It does not require permission before sending, but it sets rules for every message. According to the FTC's guidance, the core requirements are:
- No false or misleading header information. From, To and routing details must be accurate.
- No deceptive subject lines. The subject must reflect the content.
- Identify the message as an advertisement where it is one. There is flexibility in how, but it must be clear.
- Include a valid physical postal address for your business.
- Tell recipients how to opt out, clearly and conspicuously.
- Honour opt-outs promptly. The law allows up to ten business days; in practice, do it immediately.
- Monitor anyone sending on your behalf. You remain responsible if a vendor breaks the rules.
Penalties are assessed per email, and can reach tens of thousands of dollars for each message that breaks the rules.
Outside the United States
Other places are generally stricter, and the rules often depend on whether you are writing to a company address or an individual:
- Canada (CASL) generally requires consent before sending commercial email, with some narrow exceptions, such as where an address was conspicuously published and the message is relevant to the person's role.
- The UK and EU combine data protection rules (GDPR) with electronic marketing rules. B2B email to corporate addresses is often permitted with a clear opt-out and a legitimate interest, but the details vary by country.
If you sell into those markets, get specific advice before you start.
A checklist
- SPF, DKIM and DMARC set up and passing for every sending domain
- Visible From domain aligned with the authenticated domain
- A one-click unsubscribe and a plain opt-out line in every message
- Your physical business address in every message
- Opt-outs honoured immediately and applied across every channel
- A daily sending cap per mailbox, with volume built up gradually
- A hard limit on follow-ups per prospect
- Spam complaint rate monitored, for example in Google Postmaster Tools
Revio sends from your own mailbox and enforces opt-outs, contact limits and daily sending caps in code. More on how on the security page.
Common questions
Is cold email legal?
In the United States, sending unsolicited commercial email to businesses is legal as long as you follow CAN-SPAM. Many other countries are stricter. This is general information rather than legal advice.
Do I need a separate domain for cold email?
It is not required, but it is a common way to protect your main domain's reputation. The separate domain should still clearly belong to your business and be fully authenticated.
How do I know if my emails are going to spam?
Google Postmaster Tools shows reputation and complaint data for mail sent to Gmail users once you verify your domain. A sudden drop in replies from one provider is another warning sign.