Cold email deliverability: authentication, sender rules and the law

The best-written email achieves nothing in a spam folder. Most deliverability problems come down to a handful of settings and habits you can check in an afternoon.

Revio AI4 min read

The short version

  • Set up SPF, DKIM and DMARC on any domain you send from. The large mailbox providers now expect all three from volume senders.
  • Keep spam complaints very low. Google's published threshold is 0.3%, and staying well under it is the goal.
  • Make unsubscribing easy and honour it quickly. It is required by law in the US and expected by mailbox providers.
  • Protect your main domain. Send cold outreach carefully, at modest volume, from properly configured mailboxes.

What deliverability actually means

Deliverability is whether your email reaches the inbox rather than the spam folder, or is rejected outright. Mailbox providers such as Gmail, Yahoo and Outlook decide this using a mix of signals: whether you are who you say you are, how recipients react to your mail, and how your sending behaves over time.

Authentication: SPF, DKIM and DMARC

These are three DNS records that prove email claiming to come from your domain really does. They are set up once, in the same place you manage your domain.

RecordWhat it doesIn plain terms
SPFLists the servers allowed to send mail for your domainA guest list for your domain
DKIMAdds a cryptographic signature to each messageA tamper-proof seal on each envelope
DMARCTells receivers what to do when SPF or DKIM fail, and sends you reportsInstructions for handling fakes

A sensible starting point is a DMARC policy of p=none, which asks receivers to report failures without blocking anything. Once reports show all your legitimate mail passing, you can tighten it. The important detail is alignment: the domain in your visible From address should match the domain that passes SPF or DKIM.

What the big mailbox providers now require

In 2024, Google and Yahoo began enforcing clearer requirements for anyone sending to their users, and Microsoft introduced comparable requirements for high-volume senders to Outlook.com consumer addresses in 2025. The details differ slightly, but the core expectations line up:

RequirementApplies toNotes
SPF or DKIM authenticationAll sendersVolume senders are expected to have both
DMARC recordVolume sendersGoogle has cited around 5,000 messages a day to its users as the bulk threshold
From domain alignmentVolume sendersVisible From domain matches the authenticated domain
Low spam complaint rateAll sendersGoogle publishes 0.3% as the threshold to stay under
One-click unsubscribeMarketing and promotional mail from volume sendersUsing the List-Unsubscribe header standard
Valid DNS and encrypted connectionsAll sendersReverse DNS and TLS for the sending server
The rules were written for personal inboxes, but the same filtering signals are used widely, so treat them as the baseline everywhere.

Even if you send well below the bulk thresholds, meeting these requirements is the easiest deliverability improvement available, and it costs nothing.

Sending habits that protect your reputation

  • Start slowly. A new domain or mailbox that suddenly sends hundreds of messages looks like a compromised account. Build volume gradually.
  • Cap volume per mailbox. Spread outreach across properly configured mailboxes rather than pushing one hard. Revio enforces a daily cap per mailbox and carries the rest to the next morning.
  • Consider a separate domain for outreach. Many teams send cold email from a closely related domain so a problem there cannot affect the main domain used for invoices and customer email. It should still clearly be your business.
  • Keep bounces low. Mailing addresses that do not exist is a strong negative signal. Research-based prospecting avoids the stale addresses that come with old lists.
  • Write like a person. Plain text, few links, no attachments, no image-only messages.
  • Stop when people are not interested. Complaints are the fastest way to damage a domain, and they usually come from people who were contacted too often.

The law: CAN-SPAM in the United States

The CAN-SPAM Act applies to commercial email, including business-to-business email. It does not require permission before sending, but it sets rules for every message. According to the FTC's guidance, the core requirements are:

  1. No false or misleading header information. From, To and routing details must be accurate.
  2. No deceptive subject lines. The subject must reflect the content.
  3. Identify the message as an advertisement where it is one. There is flexibility in how, but it must be clear.
  4. Include a valid physical postal address for your business.
  5. Tell recipients how to opt out, clearly and conspicuously.
  6. Honour opt-outs promptly. The law allows up to ten business days; in practice, do it immediately.
  7. Monitor anyone sending on your behalf. You remain responsible if a vendor breaks the rules.

Penalties are assessed per email, and can reach tens of thousands of dollars for each message that breaks the rules.

Outside the United States

Other places are generally stricter, and the rules often depend on whether you are writing to a company address or an individual:

  • Canada (CASL) generally requires consent before sending commercial email, with some narrow exceptions, such as where an address was conspicuously published and the message is relevant to the person's role.
  • The UK and EU combine data protection rules (GDPR) with electronic marketing rules. B2B email to corporate addresses is often permitted with a clear opt-out and a legitimate interest, but the details vary by country.

If you sell into those markets, get specific advice before you start.

A checklist

  1. SPF, DKIM and DMARC set up and passing for every sending domain
  2. Visible From domain aligned with the authenticated domain
  3. A one-click unsubscribe and a plain opt-out line in every message
  4. Your physical business address in every message
  5. Opt-outs honoured immediately and applied across every channel
  6. A daily sending cap per mailbox, with volume built up gradually
  7. A hard limit on follow-ups per prospect
  8. Spam complaint rate monitored, for example in Google Postmaster Tools

Revio sends from your own mailbox and enforces opt-outs, contact limits and daily sending caps in code. More on how on the security page.

Common questions

Is cold email legal?

In the United States, sending unsolicited commercial email to businesses is legal as long as you follow CAN-SPAM. Many other countries are stricter. This is general information rather than legal advice.

Do I need a separate domain for cold email?

It is not required, but it is a common way to protect your main domain's reputation. The separate domain should still clearly belong to your business and be fully authenticated.

How do I know if my emails are going to spam?

Google Postmaster Tools shows reputation and complaint data for mail sent to Gmail users once you verify your domain. A sudden drop in replies from one provider is another warning sign.

See who you should be talking to.

Give Revio your website. It reads your business and shows you the prospects worth contacting, and why.

Revio reads your site and tells you who to sell to. No card, nothing sent.

Or talk to a human first