How to Warm Up a Domain for Cold Email: SPF, DKIM and DMARC
Warming up a domain for cold email means setting up SPF, DKIM and DMARC and ramping up sending volume gradually so your emails don't land in spam. Here's the complete step-by-step process.
Updated: 2026-08-15
Lucía Ferrer·Analyst · Cold email and deliverability
Featured tool
Instantly

What warming up a domain means
Warming up a domain for cold email means getting a new domain to a point where email servers trust it. It has two parts: setting up the SPF, DKIM and DMARC authentication records, and ramping up sending volume gradually over two or three weeks. Skip this step and your emails end up in spam, with the domain possibly burned before the campaign even starts.
Think of it like a credit history. A freshly bought domain has no reputation, and providers like Gmail or Outlook distrust anyone sending lots of mail from a domain with no track record. Warming it up is building that reputation from zero.
Why it's non-negotiable
If you want to try it yourself, create a free Instantly account (14-day free trial) and follow the steps as you read.
Deliverability is everything in cold email. It doesn't matter how good your message is if it never reaches the inbox. And an unwarmed domain has every chance of landing in spam from the very first send.
When you send from a new domain at high volume, spam filters read it as a sign that something is off. A legitimate domain doesn't jump from zero to five hundred emails a day overnight. That pattern is typical of spam, and the algorithms catch it instantly.
The good news is that warming up a domain isn't hard. The bad news is that it takes patience. There are no shortcuts that work long term.
Buy a secondary domain
Before touching anything technical, a common-sense recommendation: don't use your company's main domain for cold email.
If the main domain gets burned, you lose your corporate email, and that's a disaster you don't want to imagine. The normal move is to buy a domain similar to yours, a variation with another suffix, or a new domain built only for prospecting. They usually cost around ten to fifteen euros a year, pocket change compared to the risk you avoid.
Many people even buy two or three sending domains to spread the volume. More domains means more sending accounts, and more accounts means you can send more emails a day without overloading any single one.
The three authentication records
Here comes the technical part. Three DNS records that tell the world your emails really come from you and not from someone spoofing your domain. All three are configured from your domain provider's panel.
| Record | What it does | How to set it up |
|---|---|---|
| SPF | Declares which servers are allowed to send email on behalf of your domain | A TXT record in the DNS listing the allowed servers |
| DKIM | Adds a digital signature to every email to verify it hasn't been altered | A TXT record with the public key your sending provider gives you |
| DMARC | Says what to do when an email fails SPF or DKIM | A TXT record with a none, quarantine or reject policy |
SPF
SPF, or Sender Policy Framework, is a list of servers authorized to send email with your domain. It's set up as a TXT record in the DNS. A typical example looks like this: v=spf1 include:yourprovider.com ~all. That ~all at the end tells servers to treat any email from a server not on the list with suspicion.
If you use a cold email tool, the tool gives you the exact line to copy into your DNS. You don't have to invent anything.
DKIM
DKIM, or DomainKeys Identified Mail, signs every email with a cryptographic key. The receiving server checks the signature against the public key published in your DNS, and that's how it knows the email wasn't tampered with along the way.
The setup is similar: your provider gives you a TXT record with a key, you paste it into the DNS, done. Unlike SPF, DKIM works with a selector, a label that lets you have several keys for the same domain.
DMARC
DMARC is what ties it all together. It tells servers what to do when an email fails SPF or DKIM. The policy can be none, which does nothing, quarantine, which sends the email to spam, or reject, which rejects it outright.
For cold email, starting with a none policy and moving up to quarantine once everything works is a prudent path. A misconfigured DMARC with reject can take down legitimate emails, so better to go slow.
The warming process
With the records configured, it's time for the patient part. Warming means sending few emails at first and ramping up the volume gradually.
A common guideline is to start with ten or fifteen emails a day from a new account, then add five more every few days until you reach a maximum of twenty or thirty daily emails per inbox. The whole process usually takes two to three weeks.
During those weeks, it helps to send to addresses that will probably reply, like your own inbox or your colleagues', so providers see that your emails generate engagement. Replies are the strongest signal that you're not spam.
If warming sounds tedious, relax. There are tools that do it for you.
Automating the warmup with Instantly
Instantly includes automatic inbox warmup. You connect your sending accounts and the tool generates that gradual traffic and replies to the warmup emails, so providers see real, positive activity in your inboxes.
The advantage is that you don't have to keep track of how many emails you've sent today or whether it's time to bump the volume. The tool manages it on its own, and you focus on what matters: preparing the list and writing the messages.
Its entry plan costs around $37 a month and already includes warmup. For me it's the most comfortable way to avoid burning a domain through carelessness. You can check the details on their website.
You should also connect Google Postmaster Tools, which is free and shows your domain reputation according to Google itself. That way you can see if the warmup is on track without relying on estimates.
Mistakes that burn a domain
The first is skipping the warmup and sending volume from day one. It's the most common mistake and the most expensive. A burned domain is hard to recover, and in many cases it's cheaper to buy another one and start over.
The second is not configuring all three records. If SPF, DKIM or DMARC is missing, your domain looks suspicious by definition. It's the first thing filters check.
The third is buying email lists. Purchased lists are full of invalid addresses that bounce, and bounces are a very strong spam signal. Better a small, verified list.
The fourth is not including an unsubscribe option in your emails. Besides being bad practice, it's a legal requirement in Europe, and modern filters penalize its absence.
How to know the domain is ready
The most reliable indicator is the delivery rate. If your emails reach the inbox and not spam, you're on track. You can check by sending test emails to Gmail, Outlook and other provider accounts before launching the real campaign.
Another indicator is your Google Postmaster Tools reputation. If it shows green or yellow, you can ramp up volume with confidence. If it's red, it's time to slow down and keep warming.
When the domain handles twenty or thirty emails a day without hitting spam, it's ready to work. That's when the real cold email campaign starts. If you want a refresher on what cold email is and how to build the campaign, I have a complete guide in what cold email is.
Verdict
Warming up a domain is the step that separates the people who get replies from the people who spend the month staring at an empty inbox. It's not glamorous, it's not fast, but it's what makes everything else work.
Set up SPF, DKIM and DMARC, buy a secondary domain, ramp up the volume patiently and let a tool like Instantly handle the automatic warmup. In two or three weeks you'll have a domain with reputation and a campaign that actually reaches its destination.

Written by
Lucía Ferrer
Analyst · Cold email and deliverability
Former sales operations at a growth agency. She spends her days between SPF, DKIM and warm-up pools so your emails reach the primary inbox.
Specialty: Cold email, Instantly, deliverability, domains
