Lesson 5 of 8 · 49 min

Deliverability, domains, warming, and bounce hygiene

Treat email deliverability as production infrastructure: SPF/DKIM/DMARC, domain isolation, mailbox fleets, warmup ramps, bounce/complaint SLOs, hygiene loops, and incident runbooks.

Copy is not the bottleneck you think

Teams debate subject lines while mail lands in spam. Deliverability is the runtime of outbound: DNS auth, domain architecture, warmup, list hygiene, complaint loops, and reputation monitoring. GTM eng interviews expect you to reason like an SRE for email — because one bad week can erase months of ICP work.
Inbox placement is not fully observable, but you can control inputs: authentication (SPF, DKIM, DMARC), content patterns, send velocity, recipient engagement quality, and hard/soft bounce handling. Treat domains and mailboxes as production capacity with error budgets.
Separate primary corporate domain from outbound sending domains/subdomains. Burn risk should not sit on the domain employees use for investor and customer email. Companion CRM tracks do not cover this — it is outbound-specific infrastructure.

Authentication baseline

text
1EMAIL AUTH BASELINE23  SPF   — who may send for this domain (include ESP IPs)4  DKIM  — cryptographic signature of message content5  DMARC — policy for failures (p=none → quarantine → reject)67  Checklist:8  [ ] Custom tracking domains if ESP uses links9  [ ] Aligned From domain with DKIM/SPF (DMARC alignment)10  [ ] BIMI optional later — not a substitute for auth11  [ ] Monitor DMARC reports (aggregate) for spoof/misconfig1213  Misconfig symptom: sudden spam foldering after ESP migration.
  1. 01SPF too many lookups — classic break when vendors chain includes.
  2. 02DKIM selector rot — keys rotated without ESP update.
  3. 03DMARC p=reject too early — can block legitimate forwarders if unready.
  4. 04Sibling domain chaos — marketing and outbound fight DNS ownership.
  5. 05Shared IP vs dedicated — tradeoffs in reputation isolation vs cost.

Domain and mailbox architecture

Common pattern: primary brand.com for humans; out.brand.com or brand-mail.com variants for cold outbound; pools of mailboxes with per-box daily limits; gradual warmup. Do not impersonate employees without policy. Document recovery: what if a domain is flagged?
text
1SENDING FLEET (example)23  primary_corp: acme.com              # humans, product, billing4  outbound_roots: tryacme.com, getacme.com5  mailboxes: 20–200 depending on volume6  each mailbox: daily_cap from warmup schedule7  DNS: SPF/DKIM/DMARC per root; tracking domain per ESP89  Pool manager assigns sends → least-loaded healthy mailbox10  Unhealthy (bounce/complaint spike) → auto remove from pool11  Never send cold from founder@acme.com at 5k/day

Warmup and velocity

Warmup builds positive engagement history. Whether you use automated warmup networks or organic ramp, the principle is the same: increase volume slowly, watch bounce/complaint, pause on anomaly. Align sequence enroll rates (L4) with fleet capacity (this lesson).
  1. 01Ramp plans — per mailbox daily caps by age (day 1…30+).
  2. 02Content consistency — sudden spammy templates after warmup undo gains.
  3. 03Geographic/timezone — send when humans engage; bot-heavy windows hurt.
  4. 04Seed tests — periodic placement checks across major inboxes.
  5. 05Incident response — throttle → diagnose list vs auth vs content vs IP.

List hygiene and bounce handling

Hygiene is continuous: validation at enroll, suppression of role accounts, prune chronic non-engagers if your ESP reputation model needs it, and immediate hard-bounce suppression. Soft bounces retry with policy; repeated soft → quarantine.
text
1BOUNCE HYGIENE POLICY23  hard_bounce     → invalid email; stop; enrich memory; maybe company flag4  soft_bounce x N → pause contact; retry later; investigate mailbox full vs block5  spam_complaint  → suppress globally; review template/list ASAP6  unsub / optout  → suppress; honor across tools within SLA hours7  blocklist hit   → incident: throttle fleet, check blacklists, fix auth/content89  Daily dashboard: hard_bounce%, complaint%, unsub%, deferral%10  Auto-throttle if hard_bounce% > budget for rolling 24h window

Content and spam features

Auth and lists dominate, but content still matters: misleading subjects, toxic link redirects, URL shorteners, heavy images, attachment cold emails, and “too many domains in one blast.” Coordinate with sequence linting (L4). Legal requirements (CAN-SPAM, CASL, GDPR bases) are part of deliverability and trust — not only counsel’s PDF.

Monitoring and on-call

Someone must own email health on-call for serious outbound. Alerts: bounce spike, complaint spike, sudden deferrals, DMARC failure rise, ESP outage. Runbooks beat hero SDRs refreshing inbox placement tools.
  1. 01Q: Should cold outbound use the primary domain? Usually no for scaled cold email — isolate risk on secondary domains/subdomains with proper branding transparency. Primary stays for trusted human/product mail. Policy exceptions for very low volume exec outreach.
  2. 02Q: Warmup network vs organic only? Networks accelerate mailbox history but are not a substitute for clean lists. Combine modest warmup with strict hygiene and gradual real campaigns. Disclose internal risk posture to legal/security if required.
  3. 03Q: First response to a bounce spike? Throttle/pause affected segments, verify auth, check list source and validation age, sample failures, inspect template/ESP status — then resume under caps. Do not “push through” to hit weekly send OKRs.

Coordination with sequence enroll rates

Deliverability caps are inputs to the sequence engine’s backpressure (L4). If warmup allows 2k sends/day across the fleet, the enroll queue must not promise 10k first-touches tomorrow. Publish fleet capacity as a live metric the sequencer reads — not a Notion note updated monthly.
  1. 01Capacity signal — healthy mailbox headroom for next 24h.
  2. 02Priority drain — A-band before B when capacity tight.
  3. 03Incident mode — only replies and transactional; freeze cold enrolls.
  4. 04Post-incident ramp — re-enter volume on a schedule, not a revenge burst.
text
1DELIVERABILITY SLO EXAMPLE23  hard_bounce_rate_24h     < 2.0%   → else throttle 50%4  spam_complaint_rate_24h  < 0.08%  → else freeze cold5  deferral_rate_1h         < 15%    → else investigate ESP6  auth_fail_rate           ~ 0      → else page DNS owner78  On breach: auto action + human ack within 30m (business hours).
Legal and reputation are coupled: CAN-SPAM/CASL/GDPR-style requirements (identity, opt-out, lawful basis where required) are not “compliance theater” separate from inbox placement. A missing unsub link is both a legal risk and a complaint generator. Design for honor-unsub-across-tools within hours, not “when CRM syncs Friday.”
Interview closer: walk auth → fleet → ramp → hygiene → SLOs → incident tree in under two minutes. If you can do that without slides, you pass the deliverability slice of GTM eng loops.
Domains are production servers with a reputation filesystem. You cannot rm -rf spam consequences.
docsGoogle — Email sender guidelinesGoogledocsDMARC.org overviewDMARCarticleCloudflare — SPF/DKIM/DMARC explainedCloudflarearticleMailgun deliverability guidesMailgun

Checkpoint

Startup wants to blast 20k cold emails Friday from founder@company.com on day one. Your call?

AApprove — founder domain trust is highest and volume proves productBBlock: isolate outbound domains, auth, validate list, ramp mailboxes, set bounce budgets — then send under capsCAllow if they buy a deliverability software seat the same day
Sign up free to answer and see why

Checkpoint

DMARC reports show sudden SPF failures after adding a new ESP. Likely cause?

AProspects are marking spam — unrelated to SPFBSPF record missing new ESP includes or exceeded lookup limits — fix DNS alignmentCDMARC should be deleted to restore deliverability immediately
Sign up free to answer and see why

Checkpoint

Hard bounce rate hits 4% on a rolling day. Automated response?

ADouble volume so the percentage might diluteBAuto-throttle/pause offending segments, alert on-call, run list/auth/content tree, suppress hard bouncesCIgnore until weekly RevOps meeting next Tuesday
Sign up free to answer and see why

Checkpoint

Which statement about secondary outbound domains is most accurate?

AThey let you ignore unsubscribes because brand differs slightlyBThey isolate reputation risk from primary corp mail while still needing auth, hygiene, and honest brandingCGoogle ignores all secondary domains by default so they never work
Sign up free to answer and see why

Checkpoint

Seed tests show inbox on one provider, spam on another, after a template change only. Next best step?

AImmediately buy 50 new domains and rebuild fleet from zeroBDiff template/links vs last good, check spam features and redirect chains, throttle, and re-seed before full rampCDisable DKIM to make messages “look simpler” to filters
Sign up free to answer and see why

Can you design domain architecture, warmup ramps, bounce SLOs, and an incident tree for outbound email?

New to itGetting thereConfident

Takeaways

  • Deliverability is SRE for outbound: auth, fleet, ramp, hygiene, on-call.
  • Isolate risk from primary domains; bounce/complaint budgets throttle volume.
  • Authentication necessary, not sufficient — lists and content still matter.
  • Next: reply ops, routing, CRM write-back, SLAs (gos-reply-ops).

Next lesson: the revenue-critical human hop — reply operations that do not drop balls.

Sources

Free to read · better with Enzo

Learn it with Enzo

Save your progress, answer the checkpoints, and let Enzo quiz you on what you just read.