Lesson 5 of 8 · 49 min
Deliverability, domains, warming, and bounce hygiene
Treat email deliverability as production infrastructure: SPF/DKIM/DMARC, domain isolation, mailbox fleets, warmup ramps, bounce/complaint SLOs, hygiene loops, and incident runbooks.
Copy is not the bottleneck you think
Key idea
Authentication baseline
1EMAIL AUTH BASELINE23 SPF — who may send for this domain (include ESP IPs)4 DKIM — cryptographic signature of message content5 DMARC — policy for failures (p=none → quarantine → reject)67 Checklist:8 [ ] Custom tracking domains if ESP uses links9 [ ] Aligned From domain with DKIM/SPF (DMARC alignment)10 [ ] BIMI optional later — not a substitute for auth11 [ ] Monitor DMARC reports (aggregate) for spoof/misconfig1213 Misconfig symptom: sudden spam foldering after ESP migration.- 01SPF too many lookups — classic break when vendors chain includes.
- 02DKIM selector rot — keys rotated without ESP update.
- 03DMARC p=reject too early — can block legitimate forwarders if unready.
- 04Sibling domain chaos — marketing and outbound fight DNS ownership.
- 05Shared IP vs dedicated — tradeoffs in reputation isolation vs cost.
Domain and mailbox architecture
1SENDING FLEET (example)23 primary_corp: acme.com # humans, product, billing4 outbound_roots: tryacme.com, getacme.com5 mailboxes: 20–200 depending on volume6 each mailbox: daily_cap from warmup schedule7 DNS: SPF/DKIM/DMARC per root; tracking domain per ESP89 Pool manager assigns sends → least-loaded healthy mailbox10 Unhealthy (bounce/complaint spike) → auto remove from pool11 Never send cold from founder@acme.com at 5k/dayCommon mistake
“More new domains every week means infinite deliverability.”
Warmup and velocity
- 01Ramp plans — per mailbox daily caps by age (day 1…30+).
- 02Content consistency — sudden spammy templates after warmup undo gains.
- 03Geographic/timezone — send when humans engage; bot-heavy windows hurt.
- 04Seed tests — periodic placement checks across major inboxes.
- 05Incident response — throttle → diagnose list vs auth vs content vs IP.
Key idea
List hygiene and bounce handling
1BOUNCE HYGIENE POLICY23 hard_bounce → invalid email; stop; enrich memory; maybe company flag4 soft_bounce x N → pause contact; retry later; investigate mailbox full vs block5 spam_complaint → suppress globally; review template/list ASAP6 unsub / optout → suppress; honor across tools within SLA hours7 blocklist hit → incident: throttle fleet, check blacklists, fix auth/content89 Daily dashboard: hard_bounce%, complaint%, unsub%, deferral%10 Auto-throttle if hard_bounce% > budget for rolling 24h windowContent and spam features
Common mistake
“If SPF/DKIM/DMARC pass, spam folders are impossible.”
Monitoring and on-call
- 01Q: Should cold outbound use the primary domain? Usually no for scaled cold email — isolate risk on secondary domains/subdomains with proper branding transparency. Primary stays for trusted human/product mail. Policy exceptions for very low volume exec outreach.
- 02Q: Warmup network vs organic only? Networks accelerate mailbox history but are not a substitute for clean lists. Combine modest warmup with strict hygiene and gradual real campaigns. Disclose internal risk posture to legal/security if required.
- 03Q: First response to a bounce spike? Throttle/pause affected segments, verify auth, check list source and validation age, sample failures, inspect template/ESP status — then resume under caps. Do not “push through” to hit weekly send OKRs.
Coordination with sequence enroll rates
- 01Capacity signal — healthy mailbox headroom for next 24h.
- 02Priority drain — A-band before B when capacity tight.
- 03Incident mode — only replies and transactional; freeze cold enrolls.
- 04Post-incident ramp — re-enter volume on a schedule, not a revenge burst.
1DELIVERABILITY SLO EXAMPLE23 hard_bounce_rate_24h < 2.0% → else throttle 50%4 spam_complaint_rate_24h < 0.08% → else freeze cold5 deferral_rate_1h < 15% → else investigate ESP6 auth_fail_rate ~ 0 → else page DNS owner78 On breach: auto action + human ack within 30m (business hours).Key idea
docsGoogle — Email sender guidelinesGoogledocsDMARC.org overviewDMARCarticleCloudflare — SPF/DKIM/DMARC explainedCloudflarearticleMailgun deliverability guidesMailgunDomains are production servers with a reputation filesystem. You cannot rm -rf spam consequences.
Checkpoint
Startup wants to blast 20k cold emails Friday from founder@company.com on day one. Your call?
Checkpoint
DMARC reports show sudden SPF failures after adding a new ESP. Likely cause?
Checkpoint
Hard bounce rate hits 4% on a rolling day. Automated response?
Checkpoint
Which statement about secondary outbound domains is most accurate?
Checkpoint
Seed tests show inbox on one provider, spam on another, after a template change only. Next best step?
Can you design domain architecture, warmup ramps, bounce SLOs, and an incident tree for outbound email?
Takeaways
- Deliverability is SRE for outbound: auth, fleet, ramp, hygiene, on-call.
- Isolate risk from primary domains; bounce/complaint budgets throttle volume.
- Authentication necessary, not sufficient — lists and content still matter.
- Next: reply ops, routing, CRM write-back, SLAs (gos-reply-ops).
Next lesson: the revenue-critical human hop — reply operations that do not drop balls.
Sources
Free to read · better with Enzo
Learn it with Enzo
Save your progress, answer the checkpoints, and let Enzo quiz you on what you just read.