Outbound Lead Generation

Cold Email Deliverability Infrastructure: The Standard We Run Every Campaign To

Targeting doesn't matter if the message never reaches the inbox. This is the full deliverability stack — sending domains, authentication, warmup, tracking, sending caps, and list verification — that sits under every signal-driven outbound campaign we run.

By Constant Concepts AI · Infrastructure standard re-verified quarterly

Key takeaways

  • Every sending domain is a secondary domain — 3–5 per company — never the primary domain the business runs its real mail on.
  • SPF, DKIM, and DMARC are aligned on every sending domain before it's allowed to send a single message.
  • Per-mailbox sending stays capped around 30/day, spread across the domain pool rather than pushed through one account.
  • Our operating standard is under 2% bounce and above 95% inbox placement on every campaign — not just the good ones.

We run this infrastructure for our own outbound program before we ever run it for a client — so this isn't a vendor checklist, it's the operating standard we hold every campaign to. None of it is optional; each layer exists because skipping it is exactly how a sending domain gets burned.

Why infrastructure comes before targeting

The best-targeted message in the world does nothing if it lands in spam. Deliverability isn't a setting you configure once — it's a set of layered protections, each addressing a different way a sending program can burn its own reputation. Build the infrastructure first; the targeting and messaging sit on top of it.

Secondary sending domains

Every outbound program sends from secondary domains — typically 3 to 5 per company — set up exclusively for outbound and never used for the business's real mail. The primary domain, the one on invoices and client correspondence, never touches an outbound send queue.

The reason is isolation, not disguise. Cold outbound carries inherent deliverability risk — bounces, spam complaints, unsubscribes — even when it's run well. Isolating that risk on domains built for exactly this purpose means a bad signal on one domain never touches the domain the business depends on for everything else. It also means outbound volume can scale by adding domains and mailboxes to the pool, rather than pushing any single domain past a safe sending pattern.

SPF, DKIM & DMARC alignment

Every sending domain carries its own SPF record authorizing the sending platform, its own DKIM signing key, and a DMARC policy aligned across the From and Return-Path headers. Mailbox providers use all three to decide whether a message is legitimately from who it claims to be — an unaligned or missing record is one of the fastest ways to land in spam regardless of content.

New domains start with a DMARC policy that reports without rejecting, then move toward enforcement as sending history builds a clean reputation. Getting authentication wrong isn't a soft penalty — a misaligned domain can be filtered before the message content is ever evaluated.

Automated warmup schedules

New domains and mailboxes ramp send volume gradually — starting well below the eventual daily cap and building up over several weeks — while an automated warmup process generates positive sending signals (opens, replies, and messages recovered from spam) that give the domain a sending history before it carries a single real campaign message.

Skipping warmup and sending real campaign volume from a brand-new domain is one of the most reliable ways to get flagged in the first week. Warmup is not a formality; it's the domain earning the sending reputation the rest of the infrastructure depends on.

Dedicated tracking domains

Open and click tracking runs through its own CNAME'd subdomain per sending domain, never a shared tracking link. A shared tracking domain used across many senders gets flagged industry-wide the moment any one of those senders behaves badly — and that flag then follows every message that uses the same tracking link, regardless of how clean the actual sender's practices are.

Per-mailbox sending caps

Each mailbox caps out around 30 sends per day — well under the volume that reads as automated to a mailbox provider. Outbound volume scales by adding mailboxes and domains to the pool, not by pushing any single mailbox past a safe cap. A program that needs to send 300 messages a day runs that across ten mailboxes at 30 each, not one mailbox at 300.

Multi-step list verification

Every address goes through a multi-step verification pipeline before it's allowed into a send queue, targeting under 2% bounce on every send. A single verification pass isn't enough — each step catches a different failure mode a prior step can miss.

1.Find

An email-finder pass locates the candidate address for the enriched contact.

2.Verify

A syntax and domain check confirms the address is well-formed and the domain accepts mail at all.

3.Handshake

An MX/SMTP handshake check confirms the receiving mail server accepts mail for that specific mailbox — without actually sending anything.

4.Queue

Only addresses that clear all three steps enter the send queue. Everything else is dropped before it can become a bounce.

Bounce rate is the single most reputation-damaging metric a sending domain accrues, because it's a direct signal to mailbox providers that the sender isn't managing their list — verification exists to keep that number low before a single message is sent, not to clean it up afterward.

The operating standard

Above 95% inbox placement and under 2% bounce is the benchmark we run every campaign to. These are our own operating standards — the numbers we hold ourselves to, not a third-party research figure — and every layer above exists specifically to hit them: domain separation limits blast radius, authentication earns trust, warmup builds history, tracking domains stay clean, sending caps look human, and verification keeps bad addresses out of the queue entirely.

A campaign that misses either number isn't a messaging problem — it's an infrastructure problem, and the fix is almost always upstream of the copy: a domain that skipped warmup, a list that skipped verification, or a sending pattern that looks automated.

CAN-SPAM compliance

Deliverability infrastructure and legal compliance are two different requirements, and both are non-negotiable. Every outbound message includes a working opt-out mechanism honored promptly, a real physical postal address, and truthful subject lines and header information — the message identifies who it's actually from and doesn't disguise its purpose.

Domain separation reinforces compliance rather than working around it: if an opt-out is mishandled or a complaint spikes on a given domain, the exposure is contained to that domain instead of following the business's primary mail domain into every future message it sends.

FAQ

Why not just send from our normal company email?

Because the primary domain is where the business actually needs mail to land reliably — invoices, client replies, internal mail. Outbound at volume carries deliverability risk by nature (bounces, spam complaints, unsubscribes), and isolating that risk on secondary domains means a bad signal never touches the domain the rest of the business depends on.

What happens if a sending domain gets flagged anyway?

It gets paused and rotated out of the pool. Because outbound runs across 3–5 secondary domains instead of one, losing a single domain doesn't take down the whole outbound program — sending shifts to the remaining domains while the flagged one is diagnosed and either repaired or retired.

Is sending from a secondary domain still CAN-SPAM compliant?

Yes — CAN-SPAM governs the message and the sender's conduct (truthful headers, an honored opt-out, a physical postal address), not which specific domain the message is sent from. Domain separation is a deliverability and reputation practice on top of compliance, not a substitute for it.

How long until a new domain is ready to send at full volume?

New domains and mailboxes go through an automated warmup ramp before they carry real campaign volume — starting well below the eventual per-mailbox cap and increasing gradually as the domain builds a positive sending history. Skipping warmup is the single fastest way to get a brand-new domain flagged on day one.

Want outbound that actually lands?

See how Atlas runs signal-driven outbound on this exact infrastructure, or book a 30-minute AI Readiness Briefing to talk through your own outbound program.

Keep reading: signal-based prospecting, the speed-to-lead problem, and AI lead qualification.

Ready to stop doing this manually?

We map your workflows, deploy the right AI Worker, and guarantee the math pencils out before you sign.

Constant Concepts · Phoenix, AZ · Veteran-owned · All Playbooks