Cold email domain setup: protect your root domain
A $12 insurance policy for the domain your business runs on, and the exact order of operations from purchase to first send.
Volume cold outreach does not go out from the domain your business runs on. Following that rule costs about $12 a year. Ignoring it can put every mail stream you have, invoices included, in the spam folder.
This checklist is one chapter of the wider cold email infrastructure guide, which covers warm-up, caps, and suppression in one place. If you are still deciding whether outreach belongs in your plans at all, start with what a cold email actually is.
The blast radius argument
Mailbox providers score the sending domain. Invoices, password resets, replies to customers, the newsletter: to Gmail's filters, all of it is "mail from yourcompany.com," and all of it shares one reputation.
Cold outreach is the riskiest mail a company sends, because every recipient is a stranger and some of them will hit "report spam." Gmail's bulk-sender rules (February 2024) put the complaint ceiling at 0.3%, which is three complaints per thousand delivered messages. At or above that line, Gmail's published policy is blunt: no delivery mitigation until you are back under 0.3% for seven consecutive days. While you serve those days, your password resets and customer replies serve them with you.
A separate domain converts that systemic risk into a contained one. When a campaign goes wrong, you retire a $12 asset, keep the lessons, and your root domain never notices.
Why a subdomain is not enough
The tempting shortcut is outreach.yourcompany.com. Subdomain separation is the split our email deliverability handbook teaches: newsletter on a subdomain, transactional and one-to-one replies on the root, so a bad newsletter day cannot sink a password reset. A subdomain carries its own reputation, and for streams you control, that partial isolation is plenty.
The asterisk: sustained abuse on a subdomain rolls up to the parent. A subdomain is isolation, not a wall. A newsletter list opted in, so complaints there are rare accidents. Cold outreach inverts the risk profile: complaints are structural, and the rollup means the root eventually pays anyway.
So the rule we run by: subdomains separate the mail streams you control. A separate domain contains the one you cannot fully control.
Name the tradeoff too. A fresh domain starts with zero reputation and zero history, needs 2 to 4 weeks of parking, and then a multi-week ramp before real volume. That wait is the price of the insurance, and it is worth paying once, in advance, instead of after an incident.
Lookalike domains without the sleaze
The standard pattern is a near-name: yourcompany-hq.com, tryyourcompany.com, yourcompanyapp.com. Our stance is that lookalikes are fine with disclosure and rotten without it.
Fine looks like this: the From name is your real name and real company, the signature links to your actual site, and the lookalike domain itself serves a page that says plainly who owns it, or redirects to the main site. Any recipient who checks can confirm in five seconds that you are who you claim.
Rotten looks like a name chosen so the recipient cannot tell who is writing, or one that imitates somebody else's brand. CAN-SPAM prohibits materially false or misleading header information, and a domain picked to obscure identity leans toward that line; the specifics are in is cold email legal. Pick the closest honest name and disclose everywhere.
The setup checklist, in order
Buy the domain. A .com runs $10 to $15 a year at mainstream registrars as of August 2026. Choose a near-brand name you would be comfortable defending to a prospect's face. Skip the bargain TLDs; a $2 domain ending reads like the mail it usually carries.
Publish authentication the same day. SPF, DKIM, and DMARC, before the first message ever leaves. The literal records:
Type Name Value
TXT @ "v=spf1 include:<your provider's include> ~all"
TXT _dmarc "v=DMARC1; p=none; rua=mailto:dmarc@yourcompany-hq.com"
Your mailbox or sending provider generates the DKIM record for you, usually as a CNAME. Start DMARC at p=none to collect reports, then move to quarantine and reject once the reports come back clean. Gmail (November 2025) and Microsoft (May 2025) now hard-reject unauthenticated mail with a 550 error, so nothing later on this list matters until these records exist.
Stand up the mailbox and a one-page site. Create the address you will send from, then put a single page at the domain that states who you are and links the main site. An outbound-only domain with no web presence is a spam signature filters know well.
Park it for 2 to 4 weeks. Send nothing. New-domain reputation matures over 4 to 8 weeks, and mail from a domain registered on Tuesday gets read accordingly. Our playbook parks a new domain with the records published and the mailbox live, so the aging clock runs while you research the prospect list.
Warm up on a ramp. Start near 150 messages on day one and multiply by roughly 1.4 each day, reaching about 1,100 a day by day seven. That is Resend's documented domain ramp, and it is the curve we codified into our own send throttle. From week two, raise volume 10 to 20% a day, holding complaints under 0.1% and bounces under 2% as your targets, and never above whatever daily ceiling your relay imposes. Cold outreach should run far below those ceilings anyway; how many cold emails per day covers the caps, and email warm-up covers the ramp in detail.
Route replies to where you actually live. A reply answered in five minutes converts; one discovered on Thursday does not. Forward the outreach mailbox into your main inbox, or run both domains in one workspace. One warning from our own production logs: plain SMTP forwarding breaks DMARC alignment. In June 2026, Gmail silently rejected about 73% of the mail we were auto-forwarding between our own systems. Nothing errored on our side; mail simply vanished. We replaced forwarding with an API-based insert and kept SMTP forwarding only as a last resort. If you rely on forwarding, send yourself a test message weekly and count what arrives.
The cost math
| Separate outreach domain | Outreach from the root | |
|---|---|---|
| Upfront | About $12 a year, plus 2 to 4 weeks of parking | $0, sends today |
| A bad campaign burns | One disposable domain | Every message your business sends |
| Recovery | Register a new name, park, warm up again | Seven consecutive days under 0.3% complaints before Gmail lifts the penalty, then weeks of rebuilt history |
| Meanwhile | Root reputation untouched | Invoices and password resets share the damage |
The left column's worst case is a five-week restart that costs $12. The right column's worst case has no fixed end date, because reputation rebuilds on the provider's clock, and the provider does not publish one.
When the root domain is fine
Not every outreach program needs the apparatus. A founder sending three researched emails a day to named prospects, expecting replies and holding real conversations, is running correspondence, and correspondence belongs on the root domain where replies thread naturally.
The discipline that makes root outreach safe: a hard daily cap in the single digits to low tens, immediate suppression of any address that bounces, a full stop at the first spam complaint, and authentication aligned end to end. The bulk-sender rules bite at any volume, and we follow them at dozens of messages a day on our own root.
The moment you want volume past what you can personally research, the separate domain stops being optional. Buy it before you build the list; the parking clock only starts when you do.