Blog · Deliverability
How to Recover a Burned Domain Reputation After Cold Email Outreach
Your business emails are going to spam. You did not change anything. Or rather - you thought the problem had already been fixed. You sent 300 to 400 cold emails a day for a while, then cut back to 10 or 15 sent manually, one by one. That should have calmed things down.
It did not.
Domain reputation does not flip back once it is burned. The reputation damage happened during the high-volume period. The cooldown reduced new damage - it did not reverse the signal that major mailbox providers already recorded. Now every email from your domain, including invoices and replies to real customers, lands in the spam folder.
This is a real scenario that comes up regularly in sysadmin and email operations forums. This article covers the full recovery path: how to diagnose what actually went wrong, what immediate steps to take, how to warm up a domain properly, and how to keep this from happening again.
Why Cold Email Burns Domain Reputation
Domain reputation is a score that mailbox providers assign to your sending domain based on how recipients interact with your mail. When you send email at volumes that spike suddenly, when spam complaint rates rise, or when you send from infrastructure that has no authentication records, providers take notice.
Cold email is not inherently bad. The damage comes from a combination of factors:
Volume spikes without warmup. A domain that sends 10 emails a day for months and then suddenly sends 400 in a week looks like a compromised account to Gmail and Outlook. The infrastructure may also look suspicious if you are sending from a shared IP with no sending history.
Spam complaints. When recipients mark your cold email as spam - which they often do with unsolicited outreach - that complaint rate is recorded against your domain. A complaint rate above 0.1% is generally considered dangerous. Above 0.3% and most major providers will start filtering your mail aggressively.
Missing or broken authentication. If your cold email is sent through an ESP or SMTP relay without proper SPF, DKIM, and DMARC configuration on the sending domain, mailbox providers have no way to verify that the mail is legitimate. Unknown or unverified senders get filtered faster.
The cooldown mistake. Reducing from 400 to 10 emails per day does not undo the damage. The reputation signal was already recorded during the high-volume period. Providers do not re-evaluate continuously - reputation recovery takes active steps, not just reduced volume.
Diagnostic Checklist - Find Out What Actually Damaged Your Reputation
Before you can fix anything, you need to know what is actually broken. Here is the step-by-step diagnostic process.
Step 1: Test Inbox Placement Across Providers
Send a plain-text test email to accounts at Gmail, Outlook, and Yahoo. Use a real subject line and content that is unlikely to trigger filters. Ask the recipient to check the spam folder too - sometimes mail arrives in the main inbox but a test email may land in spam.
If the test email lands in spam, you have a deliverability problem. If it lands in inbox but real business email goes to spam, the difference is likely content or recipient-specific signals rather than overall domain reputation.
Step 2: Check Google Postmaster Tools
If you own the sending domain, Google Postmaster Tools is free and gives you direct visibility into what Google knows about your domain. You do not need to install anything - Postmaster Tools uses DNS records and mail traffic to build its reputation data.
The key sections to review:
- Domain reputation: Low, medium, or high. If it shows low, Google is treating your domain with suspicion. There is no numeric score - just a tier label.
- Spam rate: The percentage of your mail that recipients marked as spam. If this is above 0.1%, you have a complaint problem.
- Authentication: Shows whether your SPF, DKIM, and DMARC are passing. All three should be green.
- Traffic: Volume trends over the past 30 days.
If you do not have access to Postmaster Tools - for example, if the cold email was sent from a subdomain you do not fully control - that is itself a diagnostic finding. You need to audit which domains and subdomains are actually sending mail.
Step 3: Check Microsoft SNDS and Postmaster Tools
Microsoft uses a different reputation system. SNDS (Smart Network Data Services) shows IP-based sending data. Microsoft Postmaster shows domain-level data similar to Google Postmaster Tools.
For Outlook and Microsoft 365 recipients, check:
- IP reputation: Your sending IP may be on a blocklist or have low reputation even if your domain is separate.
- Complaint rate: Microsoft tracks complaint rates differently from Google but the principle is the same - high complaints mean filtering.
- Mail volume anomalies: Sudden volume spikes trigger filtering regardless of complaint rates.
Step 4: Check Blocklist Status
Use MXToolbox or a similar DNSBL checker to see if your sending IP or domain is listed on any major email blocklists. Being listed on even one major blacklist can cause mail to fail across many providers.
Run checks for:
- Your sending IP addresses (especially if you send through a relay or ESP)
- Your domain
- Any subdomains you use for outbound mail
If you find blocklist entries, most provide a delisting process. Some are automatic after a cooling-off period; others require a formal request.
Step 5: Read Your DMARC Aggregate Reports
This is the most underused diagnostic step - and the one that tells you the most. Most domain owners with DMARC monitoring have aggregate reports but do not read them carefully during a crisis.
Your DMARC aggregate reports show you:
- Every entity sending mail on behalf of your domain - including ones you may have forgotten about
- Whether SPF, DKIM, and DMARC are passing for each sending source
- Alignment failures that indicate mail is being sent from infrastructure you do not control
- Forwarding chains that may be breaking authentication
If you see sending sources in your DMARC reports that you do not recognize - an old ESP you stopped using, a marketing tool, a forwarding service - that is a strong signal of what burned your reputation. You may have had SPF or DKIM misconfigurations that allowed unknown senders to appear as legitimate.
This is where DMARCFlow adds direct value. DMARCFlow aggregate reports surface unknown senders quickly, with daily summaries and alerting that makes it obvious when a sending pattern has changed. Rather than waiting for Postmaster Tools to show a declining reputation signal, DMARCFlow shows you the underlying sending behavior that drives reputation - unknown senders, authentication failures, unexpected infrastructure changes. If you do not currently have DMARC monitoring set up, the diagnosis section below will show you exactly what to look for in your aggregate reports.
Immediate Steps to Stop the Damage
Once you have diagnosed the problem, stop making it worse.
Separate cold outreach infrastructure from transactional mail. If you have been sending cold email from the same domain you use for invoices, support replies, and internal communication, split them now. Use a different subdomain for outreach - something like `outreach.yourdomain.com` - and keep your root domain strictly for transactional and relationship mail.
Stop all non-essential outbound from the burned domain. If you can route transactional mail through a different sending domain or provider during recovery, do it. The goal is to reduce volume from the burned domain while preserving the reputation signals of your legitimate mail.
Do not send anything from the burned domain for 2 to 4 weeks if possible. This is the hardest advice to follow because it interrupts operations. But reputation recovery requires a quiet period. If you cannot stop completely, reduce to minimal essential volume only.
Audit every sending source in your DMARC reports. Remove any ESP integrations, marketing tools, or forwarding rules that are no longer in use. Every unknown sender in your DMARC reports is a potential reputation risk.
How to Warm Up a Domain After Reputation Damage
If you need to continue sending email - and most organizations do - here is how warmup actually works, not how warmup services market it.
Warmup is about rebuilding a sending history with mailbox providers. Providers track how consistently a domain sends mail over time. A domain with years of consistent, low-volume sending has a better reputation than a domain that sent nothing for months and suddenly started sending thousands of emails.
Week 1: 10 to 25 emails per day. Send only to engaged recipients - people who have previously replied to your emails or explicitly opted in. Use authenticated sending with proper SPF and DKIM. Monitor complaint rates daily.
Week 2: 25 to 50 emails per day. If complaint rates stayed below 0.1% in week one, you can gently increase. Do not double volume overnight - gradual increases signal legitimacy.
Week 3 and 4: 50 to 100 emails per day. Continue monitoring complaint rates. If complaints spike, pause and hold at the current volume for another week.
Month 2 onwards: gradual increase toward normal volume. You may be able to return to normal sending volumes within 6 to 8 weeks for mild damage. Severe damage - like being added to major blocklists - can take 3 to 6 months.
What warmup services actually do. Some vendors offer warmup services where their accounts receive your emails and mark them as not spam, which helps train the reputation algorithm. This works in the short term but it does not replace the underlying need for consistent, complaint-free sending volume. A warmup service that generates fake engagement while you continue sending cold email to unengaged recipients will not hold its benefit.
The honest answer: warmup is slow because reputation is built slowly. No service bypasses the time requirement.
Prevention - Keep Your Domain Reputation Healthy Going Forward
Once you have recovered, do not return to the practices that caused the problem.
Never send cold email from your primary transactional domain. Create a separate subdomain or entirely separate domain for cold outreach. If the outreach domain gets burned, your transactional mail domain reputation stays clean.
Implement full authentication (SPF, DKIM, DMARC) on every sending domain. This is not optional. If your sending infrastructure changes - you switch ESPs, add a new relay, start using a forwarding service - update your DNS records immediately. Forgotten ESP delegations are one of the most common sources of DMARC failures and reputation damage.
Monitor DMARC reports continuously. Set up daily or weekly DMARC report summaries so you know when new sending sources appear on your domain. DMARCFlow is built for this - the alerting layer catches unknown senders before they become reputation problems.
Warm up any new sending infrastructure before volume use. If you provision a new subdomain or switch sending providers, start at low volume and ramp gradually. Treat every new sending domain as having zero reputation, regardless of whether your root domain has a good reputation.
Separate your sending by type. Use different subdomains for transactional mail, marketing, and cold outreach. This way, if one category of mail causes reputation problems, the others are isolated.
How DMARCFlow Helps You Catch Reputation Problems Early
Domain reputation is a lagging indicator. By the time Postmaster Tools shows a declining reputation signal, the damage to your deliverability has already happened. The leading indicators are in your DMARC aggregate reports.
DMARCFlow surfaces the sending behavior that drives reputation: unknown senders on your domain, sudden changes in sending volume or infrastructure, authentication failures that indicate misconfiguration or unauthorized relay use. These signals appear in DMARC reports days or weeks before mailbox providers update reputation tiers.
During recovery, daily DMARC monitoring with DMARCFlow lets you catch new unknown senders immediately. If a team member sets up a new email tool that sends from your domain without proper authentication, you see it in the DMARC report before it damages your recovering reputation.
For ongoing prevention, DMARCFlow alerting on sending anomalies is more actionable than checking Postmaster Tools once a week. A new ESP that starts sending from your domain without your knowledge will show up as an unknown sender in your daily DMARC summary. DMARCFlow also tracks alignment failure rates - if your SPF or DKIM alignment starts failing for a known sending source, that is an early warning sign before reputation drops.
Set up alerts for: new unknown senders appearing on your domain, sudden volume spikes from sources you do not recognize, and increasing authentication failure rates. These three patterns cover the most common causes of reputation damage.
FAQ
How long does domain reputation recovery take? For mild damage - moderate complaint rates, no blocklist entries - 4 to 8 weeks of consistent low-volume sending can restore inbox placement. For severe damage - blocklist entries, very high complaint rates - recovery can take 3 to 6 months. There is no shortcut.
Can I use the same domain for cold email and transactional email? No. Use separate subdomains or domains. If your transactional domain reputation is important to you, protecting it from cold email risk is the only practical strategy.
My emails go to spam even though SPF and DKIM are passing. Why? Authentication passing means your mail is not being blocked for failing to prove it is from you. But reputation is a separate signal. You can have perfect SPF and DKIM and still go to spam if your complaint rates are high or your sending history is short or damaged.
How do I check if my domain is on a blocklist? Use MXToolbox Blacklist Check, DNSBL.info, or MultiRBL. Check both your sending IP addresses and your domain. Most blocklists have a delisting process if you are listed erroneously.
What volume should I send during warmup? Start at 10 to 25 emails per day in week one, increasing by roughly 50% per week if complaint rates stay below 0.1%. Stop increasing if complaints spike.
Do DMARC reports show reputation problems before Postmaster Tools does? Yes. DMARC reports show you unknown senders, authentication failures, and infrastructure changes that drive reputation. Postmaster Tools shows the result - a declining reputation tier. DMARCFlow monitoring gives you the leading indicators; Postmaster Tools shows the lagging result.
Should I create a subdomain for cold email outreach? Yes. Always. Use a subdomain specifically for cold outreach, separate from your primary transactional domain. This isolates reputation risk entirely.