Decay University · Part 7: The practitioner track

Lesson 61 of 64

Cold email deliverability: the honest answer

Why cold email fights every reputation system by design, the truth about rotation networks and warm-up pools, the legal lines, and what to tell a client.

Last updated 19 July 2026

After this lesson you can answer the cold outreach question like a professional: with the structural facts, the real status of the tools sold around it, the legal lines, and a script that doesn't dodge.

Cold email is not a harder version of the sending this course teaches. It is a structurally different game, because every reputational mechanism you met in Part 3 was tuned, over decades, to suppress exactly this shape of mail. Unsolicited bulk email is the reason spam filters exist. When a cold campaign struggles to land, that is not the system misfiring; it is the system doing the one thing it was built to do. A practitioner track owes you a straight chapter on this, because clients will ask, and most of the industry answers them with evasions.

The machinery is aimed at it

Recall what sender reputation actually measures: how the people you mail react. A consented list arrives at every campaign carrying history, months of opens and replies already in the ledger. A cold list arrives carrying nothing. No prior relationship means no engagement history to argue for you, and no expectation means the recipient's first decision about your domain is whether to delete the message or press report-spam.

Now run the complaint arithmetic from list hygiene. Google's stated guidance is a spam rate under 0.1%, never reaching 0.3%: three reports per thousand delivered. An opted-in list rarely brushes that line. Mail a thousand strangers and three annoyed people is an optimistic outcome, which is why one cold campaign can cross a threshold the client spent years of good sending staying under.

The rulebook is also explicit before any arithmetic starts. Google's sender guidelines say it in one sentence: "Don't send messages to people who didn't sign up to get messages from you."

Authentication changes none of this. SPF, DKIM and DMARC prove who sent the mail, and identity is the thing a cold sender least wants sharpened. Perfect authentication on unwanted mail is well-identified spam. You read that sentence back in Part 4; cold outreach is where it stops being theoretical.

The dodge industry

Because the system suppresses this shape of sending, an industry sells shape-changers. Four products recur, and each deserves an honest verdict rather than a sneer.

Burner domains. Register cheap throwaway domains, send from them, discard them when they burn. This works at first, then meets the cold-start problem from the shared vs dedicated IPs lesson: a new domain has no history, so filters treat its volume cautiously from day one, and a freshly registered domain doing bulk sending is itself a pattern receivers score. The tool's lifespan is measured in weeks.

Lookalike domains are the uglier sibling: clientname-team.com standing in for clientname.com, so replies look official while the "real" domain stays clean. Two problems the sales page omits. It trains the client's own market to trust imitations of the brand, a gift to whichever phisher tries next. And a domain chosen to resemble something it isn't starts a conversation about deception that laws on truthful identification are already part of.

Inbox rotation spreads the campaign across dozens of rented mailboxes and domains so no single identity trips a volume threshold. The tooling is genuinely clever. It is also a coordinated sending network, which is a thing mailbox providers actively hunt, and when the network gets mapped, the accounts go down in batches, mid-campaign.

Warm-up pools are networks of mailboxes that open each other's mail, click it, reply to it, and rescue it from spam folders, all to fabricate an engagement history. You met this in Part 3: it is manufactured engagement, and it does nothing to change how real recipients receive the real campaign, so whatever reputation it buys starts draining on the first true send.

The one-line verdict on all four: they work briefly, they decay fast, and the decay is not bad luck. It is countermeasure engineering doing its job. On top of that they sit outside provider policy, and the fake-engagement variety was already prohibited territory when the bulk sender rules formalized what providers expect.

The people who run the mail system have put their position in writing. In November 2025, M3AAWG (the working group where mailbox providers, ESPs, and anti-abuse teams coordinate) published a position on cold email. Its language is unusually blunt: "using deceptive and misleading delivery methods to send unsolicited email (including Cold Email) is an abusive practice", and attempts to bypass volume limits, mask sending domains, or "artificially simulate subscriber engagement" are "not acceptable in any manner". The detail I find most telling is how the document says cold senders get identified: spam trap hits, blocklistings, high unknown-user bounces, high complaint rates. That is the damage signature Part 4 taught you to avoid, read from the receiving side. The infrastructure community recognizes cold outreach by its wreckage.

The legal layer

The email marketing laws lesson drew the map; here is where cold email sits on it. In the US, cold email is lawful under CAN-SPAM's opt-out model, provided the headers are truthful, the mail identifies its sender, a postal address rides along, and opt-outs get honored, and provided you remember liability reaches whoever presses send. In the EU, UK, and Canada, consent regimes make most cold B2C mail unlawful before the first message goes out, and CASL puts the burden of proving consent on the sender.

B2B is the genuinely murky part. Some consent regimes treat corporate addresses differently from personal ones, the details differ country by country, and a prospect list nearly always spans borders. This is the point where working knowledge ends and a lawyer in the relevant jurisdiction begins; a practitioner who says so plainly is worth more than one who improvises.

How this decays

The shortest decay note in the course. Cold sending infrastructure does not decay the way the rest of this curriculum describes, slowly and silently. It decays fast and on purpose, because the countermeasures are designed to burn it. A burner domain is decay, pre-paid.

The script

What you tell a client who asks should sound something like this, in your own words.

If you do this, do it with open eyes. Lawfully, which means knowing which countries your list touches before sending, not after. On a separate, honestly named domain you have already accepted losing, never a lookalike. At low volume, to a list built from real research rather than a scraped export. And with a hard wall between it and everything you have built: separate domain, separate sending path, separate tracking links, nothing shared with the streams you learned to protect in separate your mail streams.

Sometimes the right answer is shorter: "I don't do this work." That sentence is a legitimate professional position, not squeamishness, and quoting the true cost often gets you there anyway. Price a cold engagement honestly (the legal review, the expendable domain, the near-certainty of rebuilding) and many clients discover that what they actually wanted was a warm list they haven't built yet.

Which is the real point. Everything in this course is the craft of making wanted mail land. The cold email industry spends the same skills making unwanted mail sneak, and only one of those compounds: reputation is an asset when recipients want you and a treadmill when they don't. I'll admit our product takes a side here. Inbox Decay's monitoring would happily tell you the moment your burner domain hits a blocklist, but using it that way is like fitting a smoke alarm to a building you plan to burn down.

Next, the course stops teaching and starts testing: the client-readiness gauntlet, real client situations played one decision at a time.

Terms from this lesson

  • cold email - unsolicited email sent to create a business relationship with a recipient who has no prior relationship with, or gave no consent to, the sender.
  • burner domain - a throwaway domain used for cold sending and discarded once its reputation burns; its short lifespan is the countermeasures working.
  • lookalike domain - a domain registered to resemble a legitimate one (clientname-team.com for clientname.com) so mail appears to come from the real brand.
  • inbox rotation - spreading a campaign across many rented mailboxes and domains so no single identity trips volume thresholds; a coordinated network providers hunt.
  • warm-up pool - a network of mailboxes that open and reply to each other's mail to fabricate engagement history; prohibited manipulation, not reputation.
  • M3AAWG - the Messaging, Malware and Mobile Anti-Abuse Working Group, where mailbox providers and anti-abuse teams coordinate; publisher of the cold email position.

Check yourself

1. A founder says: 'Our cold campaigns pass SPF, DKIM and DMARC perfectly. Why does the mail still go to spam?'

2. What is the honest assessment of warm-up pools and inbox rotation networks?

3. A client wants a cold B2B campaign covering prospects in the US, Germany, and Canada. Which statement is accurate?

Scenario

Your client is a B2B software company with two years of clean, consented sending behind their domain. Sales has bought a tool and a 15,000-address prospect list. The founder says: 'Send the cold campaign from our main domain. Its reputation is great, so it'll actually land.'

What do you tell them?