Cold Email Pre-Send Checklist 2026 - 15 Things to Verify Before You Hit Send | BounceZero
| Cold Email | 10 min read | | 511 views

Cold Email Pre-Send Checklist 2026 - 15 Things to Verify Before You Hit Send

One skipped step before a cold email campaign can burn a sending domain that took months to warm up. This 15-point pre-send checklist covers domain reputation, DNS authentication, list verification, personalization, and monitoring - everything to confirm before you hit send. Save it, and run it before every single campaign.

Cold email in 2026 is a game of margins. Google and Microsoft now enforce sender requirements that used to be best practices: authenticated domains, sub-0.3% spam complaint rates, and functioning one-click unsubscribe are table stakes. Yahoo followed suit, and the smaller providers copied the playbook. The senders still landing in primary inboxes aren't the ones with the cleverest copy - they're the ones who refuse to send until every technical and list-quality box is checked.

The math is unforgiving. Email industry data consistently shows that a bounce rate above 2% starts degrading sender reputation, and above 5% most mailbox providers begin routing your mail to spam or rejecting it outright. A single campaign to an unverified list of 5,000 addresses - where 8-12% of B2B contact data decays per quarter - can generate 400+ hard bounces and undo three months of careful domain warmup in one afternoon.

The fix isn't complicated. It's discipline. Every high-volume cold emailer we work with at BounceZero runs some version of the same pre-flight ritual: check the domain, check the DNS, verify the list, review the message, confirm the monitoring. The senders who skip steps are the ones filing deliverability support tickets three weeks later, asking why open rates fell off a cliff.

This article turns that ritual into a concrete 15-point checklist. Each item takes between 30 seconds and a few minutes to verify. Bookmark it, copy it into your campaign SOP, and run it before every send - not just the first one. Campaigns fail on the details, and the details below are the ones that matter in 2026.

1. Check Your Domain Age and Reputation

Mailbox providers treat domain age as a trust signal, and cold email from a domain registered last Tuesday is one of the strongest spam indicators there is. Never send cold email from a domain younger than 30 days - ideally 60-90. Email industry data shows that domains under 30 days old see spam placement rates 3-4x higher than domains aged 90+ days, even with identical content and identical lists.

Before every campaign, verify three things about the domain you're sending from. First, its age: a quick WHOIS lookup tells you the registration date. If you bought the domain recently, park it with a simple website and let it age while you warm it up. Second, its reputation history: check Google Postmaster Tools for domain reputation (aim for "High" or at minimum "Medium"), and run the domain through blocklist checkers covering Spamhaus, Barracuda, and SURBL. A domain that a previous owner burned for spam carries that baggage with it - dropped domains with bad history are cheap for a reason. Third, its relationship to your main brand: you should be sending cold email from a secondary domain, not your primary company domain. If bouncezero.io were our outreach domain and a campaign went wrong, our transactional email, password resets, and customer receipts would suffer alongside it. Use a close variant - get-yourbrand.com, yourbrandhq.com, tryyourbrand.io - and redirect it to your main site so recipients who type it in land somewhere legitimate.

One more detail that senders miss: check the reputation of your sending IP, not just the domain. If you're on a shared pool through your sending tool, your neighbors' behavior affects you. Most cold email platforms publish their pool health; if yours doesn't, ask. And if you're running meaningful volume - 10,000+ sends per month - the economics of a dedicated IP start to make sense, because you become the sole author of your own reputation.

The 30-second version of this check: WHOIS age over 60 days, no blocklist hits, Postmaster reputation Medium or better, and it's not your primary domain. If any of those fail, fix them before writing a single subject line. Everything else on this checklist assumes a domain that providers are willing to trust in the first place.

2. Confirm SPF, DKIM, and DMARC Are Configured and Passing

Since the 2024 Google and Yahoo sender requirements - tightened further through 2025 - unauthenticated bulk email is effectively dead on arrival. All three authentication records must exist, and more importantly, must actually pass on the messages your sending tool produces. "I set it up months ago" is not verification; DNS records get overwritten, sending tools change signing domains, and a silently broken DKIM signature can run for weeks before anyone notices the open rates collapsing.

SPF (Sender Policy Framework) lists which servers may send on your domain's behalf. Check that your cold email tool's include is present, and count your DNS lookups - SPF fails permanently ("permerror") beyond 10 lookups, and stacking includes from multiple tools is the most common way senders break it without realizing. DKIM (DomainKeys Identified Mail) cryptographically signs each message. Crucially, the DKIM signing domain must align with your From domain; many tools default to signing with their own domain, which passes DKIM technically but fails DMARC alignment. DMARC tells receivers what to do when authentication fails and is now mandatory for bulk senders. Start at p=none with a rua reporting address so you collect data, then move to p=quarantine once reports confirm all legitimate mail passes. Email industry data shows DMARC-enforced domains (quarantine or reject) see measurably better inbox placement than p=none domains, because enforcement itself signals a serious sender.

The verification step takes two minutes: send a test message from your actual campaign tool to a Gmail address you control, open it, click "Show original," and confirm you see SPF: PASS, DKIM: PASS, DMARC: PASS with your sending domain - not your tool's domain - in the authentication results. Do this from the exact tool, domain, and mailbox combination the campaign will use. A test from your regular inbox proves nothing about your cold email stack.

While you're in DNS, confirm two supporting records: a valid MX record on the sending domain (domains that send but can't receive look like spam infrastructure, and replies need somewhere to land) and rDNS/PTR records if you control your own IP. BounceZero's verification pipeline runs MX checks on every address we verify for exactly this reason - mail servers on both sides of the transaction check it, and so should you.

3. Verify Your List - Every Address, Every Time

This is the single highest-leverage item on the checklist, and the one most often skipped under deadline pressure. An unverified list is a loaded gun pointed at your sender reputation. B2B email data decays at roughly 2.1% per month - people change jobs, companies get acquired, mailboxes get deprovisioned - which means a list purchased or scraped six months ago has silently rotted by 10-15%. Send to it raw and those dead addresses come back as hard bounces, and mailbox providers read a high bounce rate as one thing: this sender doesn't know their recipients, which is the operational definition of a spammer.

The thresholds are stricter than most senders assume. Keep bounce rates under 2% to stay safe; above 5%, providers begin throttling and spam-foldering your mail, and many sending platforms will suspend your account outright. Across BounceZero's verification data spanning 50M+ emails, typical unverified cold outreach lists contain 6-15% invalid addresses - more than enough to blow through both thresholds on the very first send.

Verification before every campaign - not just once when you acquire the list - catches four categories of risk. Invalid mailboxes that will hard bounce. Disposable addresses from temporary email services that will never convert and often correlate with trap networks. Role accounts (info@, sales@, admin@) that route to shared inboxes where spam complaints are more likely than replies. And spam traps - addresses maintained by blocklist operators specifically to catch senders with poor list hygiene; a single trap hit can land your domain or IP on Spamhaus.

BounceZero runs all six checks on every address - mailbox existence via live SMTP conversation, catch-all detection with a 3-probe method, role detection, disposable detection, MX validation, and spam trap screening - at up to 99.8% accuracy in internal testing on SMTP-verifiable addresses against an industry benchmark of roughly 95%. That accuracy gap matters at scale: on a 50,000-address list, a 95%-accurate verifier misclassifies around 2,500 addresses; at 99.8% it's about 100. For campaign-sized jobs, our [bulk email verification](/bulk-email-validation) processes dashboard jobs of up to 1,000,000 addresses addresses in 5-10 minutes at $3 per 1,000 - cheap insurance against a bounce spike, and you can test the pipeline with 100 free verifications per month, no credit card required. If your list is more than 30 days old, re-verify it. The 30-day-old "clean" list is how careful senders still end up with 4% bounce rates.

4. Decide Your Catch-All Strategy Before You Send

Catch-all domains are the gray zone of cold email, and going into a campaign without a policy for them means improvising with your reputation on the line. A catch-all (accept-all) domain is configured to accept mail for any address at that domain - the server says "yes" to everything during the SMTP conversation, so a standard verification check can't confirm whether john.smith@ actually exists or whether the message will be silently discarded or bounced after acceptance. In B2B outreach, catch-alls are common: across BounceZero's verification data, 20-30% of a typical B2B list resolves to catch-all domains, because many companies configure their mail servers this way deliberately.

You have three defensible strategies, and you should pick one before the campaign, not during it. Conservative: exclude all catch-alls. Maximum reputation safety, but you're discarding a fifth to a third of your addressable market - often including exactly the mid-market companies cold emailers target. Aggressive: send to all catch-alls. Maximum reach, but industry data puts real-world bounce rates on undifferentiated catch-all addresses at 10-20%, which will wreck your metrics. Segmented - the approach we recommend: send to catch-alls from a separate sending domain or mailbox, at lower volume, so any bounce damage is quarantined away from your primary outreach infrastructure. Prioritize catch-all addresses with corroborating evidence the person exists - a live LinkedIn profile, a company team page, a recent conference speaker listing.

Better verification shrinks the gray zone before you have to make the call. BounceZero's 3-probe catch-all detection goes beyond the single-probe test most verifiers use: rather than just flagging "this domain accepts everything," we probe with control addresses to distinguish true accept-alls from servers with more nuanced behavior, and our scoring pipeline layers additional signals on top of the raw SMTP response. The result is that a meaningful share of addresses other tools would dump into an unusable "unknown" bucket get resolved to a confident valid or invalid - which directly translates to more sendable addresses without added bounce risk.

Whatever strategy you choose, write it into your campaign SOP: which segment catch-alls go into, which domain sends to them, and what bounce threshold triggers pausing that segment. The senders who get hurt by catch-alls are almost never the ones with a bad policy - they're the ones with no policy.

5. Honor Every Unsubscribe and Suppression - Before the Send

Nothing destroys a sender faster than emailing someone who already asked you to stop. It's a legal exposure, a guaranteed spam complaint, and - since mailbox providers began enforcing the 0.3% spam complaint ceiling - a direct deliverability threat. Email industry data suggests each spam complaint damages your reputation roughly as much as 15-20 positive engagements repair it. Suppression list hygiene is the cheapest reputation protection available, and it has to happen before the send, because there's no undo.

Run four checks. First, merge suppression lists across every tool you use. The classic failure mode: a prospect unsubscribes from a campaign in tool A, then gets sequenced three weeks later from tool B because the suppression lists were never synced. If you run multiple sending tools, seats, or agencies, maintain a master suppression list and diff every new campaign list against it - a five-minute spreadsheet operation that prevents your angriest complaints. Second, confirm one-click unsubscribe (RFC 8058 List-Unsubscribe headers) is active. This is mandatory for bulk senders at Gmail and Yahoo, and it works in your favor: a one-click unsubscribe takes the frustrated recipient away from the spam button. An unsubscribe costs you one prospect; a spam complaint taxes your entire domain. Third, check your unsubscribe processing latency. Regulations allow up to 10 business days under CAN-SPAM, but if a recipient unsubscribes on Tuesday and step 3 of your sequence fires Thursday, you've converted a neutral exit into a complaint. Modern tools suppress instantly across a sequence - verify yours actually does, including for contacts already mid-sequence. Fourth, know your jurisdictions. CAN-SPAM permits B2B cold email with a valid unsubscribe and physical address. GDPR and PECR in the UK/EU require a legitimate-interest basis, genuinely relevant targeting, and easy opt-out. Canada's CASL is stricter still. If your list spans regions, segment by jurisdiction and apply the strictest applicable standard rather than gambling.

A final pass worth 60 seconds: scan the new list for previous bouncers and previous complainers, not just unsubscribers. An address that hard-bounced in March will hard-bounce today, and re-mailing known complainers is self-sabotage. Your suppression list should be the union of all three - and it should only ever grow.

6. Match Your From Name to Your Persona - and Set the Preview Text

Before a recipient reads a word of your carefully crafted body copy, they see exactly three things in their inbox: the from name, the subject line, and the preview text. Two of the three are routinely left to chance, and both take under a minute to fix.

The from name check: cold email works when it feels like one professional writing to another, and the from name is where that illusion holds or breaks. Use a real person's name - "Sarah Chen" or "Sarah from BounceZero," never "BounceZero Sales Team" or a bare brand name. Email industry data consistently shows person-name senders outperform brand-name senders on open rates in cold contexts by 15-35%, because a person triggers curiosity while a brand triggers the promotional-filter reflex. Then verify the alignment details: the from name must match the email signature (a message from "Sarah Chen" signed "Mike Torres" reads as a phishing tell), the sending mailbox should look human (sarah@ or s.chen@, not noreply@ or outreach@), and if your sequence includes a persona - an SDR name, a founder's voice - confirm the mailbox, signature, LinkedIn-referenced details, and calendar link all belong to the same identity. Recipients check. Buyers who receive 50 cold emails a week have well-trained pattern detectors.

The preview text check: the snippet after the subject line gets 40-90 characters of prime inbox real estate, and unset preview text defaults to the first line of your email - which for careless senders means "View this email in your browser" or the raw text of an unsubscribe link, an instant deletion cue. In cold email, where messages are usually plain-style rather than templated HTML, the first sentence *is* your preview text. So write your opening line to function in both roles: it must work as a snippet fragment beside the subject and as the first sentence the reader encounters after opening. Test the pairing explicitly - read your subject line and first sentence together, aloud. If the first line just restates the subject, you've wasted the space; the two should compound, with the subject opening a loop and the preview advancing it. Send yourself a test and look at it on a phone, where roughly 60% of opens now happen and preview text truncates hardest. What survives 40 characters is what most recipients will actually see.

7. Strip Spam Trigger Words from Your Subject Line

Modern spam filtering is behavioral and reputation-driven - Gmail's filters weigh your domain history and engagement far more heavily than any single word - but content signals still contribute to the composite score, and when you're a cold sender with thin reputation history, you have no engagement buffer to absorb them. A subject line that a trusted newsletter could send with impunity can be the marginal signal that tips a cold email into the spam folder. The rule for cold email subjects in 2026: sound like a colleague, not a coupon.

The persistent offenders fall into four families. Money and urgency language: "free," "discount," "limited time," "act now," "$$$," "earn," "guarantee," "no obligation." Performance-marketing phrasing: "increase your revenue by 300%," "double your leads," "#1 solution." Formatting tells: ALL CAPS words, multiple exclamation marks, emoji in a B2B cold subject, RE:/FW: prefixes faking a prior thread (this one also violates CAN-SPAM's prohibition on deceptive subject lines - it's not just a filter risk, it's a legal one). Clickbait constructions: "you won't believe," "this one trick," "open immediately." Email industry data shows subject lines with three or more of these signals see spam placement rates several times higher than neutral subjects from equivalent senders.

What works instead is almost boring: short, lowercase-leaning, specific subjects that resemble internal email. "question about {company}'s onboarding flow," "idea for {first name}," "{mutual connection} suggested I reach out." Industry benchmarks consistently show 2-5 word subjects outperforming longer ones in cold contexts, both on opens and on spam placement. Specificity beats cleverness: a subject that could only have been written to this recipient signals relevance to both the human and, increasingly, to engagement-based filters that learn from how recipients treat your mail.

The verification step: run every subject line variant through a spam-score checker (Mail-Tester and similar tools remain useful for a directional read), then apply the sniff test no tool can automate - would you open this if it arrived from a stranger? Check your A/B variants too, not just the control; a spammy variant B poisons the same domain reputation as variant A. And review the body with the same lens: trigger language buried in paragraph three, a wall of links, or image-heavy HTML all contribute to the same composite content score. One link maximum in a cold email body is a good discipline - which sets up checklist items 9 and 13.

8. Include a Plain Text Version - or Go Plain Text Entirely

Every email technically travels as MIME parts, and a well-formed commercial message includes both an HTML part and a text/plain alternative. When the plain text part is missing or mismatched, two bad things happen. First, spam filters notice: HTML-only email is a classic spam fingerprint because legitimate mail clients generate the plain text part automatically, while sloppy spam tooling skips it. Second, a subset of your recipients - corporate security gateways that strip HTML, accessibility tools, watches and terminal clients, and executives who read mail in preview panes - see either nothing or garbage. Email industry data attributes a measurable deliverability penalty to HTML-only sends, and for a cold sender with no reputation cushion, every penalty compounds.

For cold email specifically, the stronger recommendation is more radical: skip heavy HTML entirely and send plain-style email. The highest-performing cold emails in 2026 look like something a real person typed in Gmail - no header image, no buttons, no multi-column layout, no tracking-pixel-laden template. There are three reasons. Deliverability: lightweight messages with a low HTML-to-text ratio score better with content filters, and image-heavy emails with sparse text are actively penalized. Psychology: a designed template announces "mass marketing" before a word is read, while a plain message earns the two-second consideration a colleague's email gets. And rendering: plain-style email cannot break on mobile, in dark mode, or behind an image-blocking gateway. If you use light HTML for formatting (a hyperlink, bold text, a signature), keep the message under 100KB - Gmail clips larger messages, hiding your unsubscribe link and hurting engagement measurement.

The verification steps: confirm your sending tool generates a proper multipart/alternative structure (send yourself a test and view the raw source - you should see both text/plain and text/html parts), and read the plain text version, because auto-generated plain text from HTML templates is often a soup of URLs and broken line breaks. If your tool lets you hand-edit the plain text part, do it. Then check the small details that betray automation: custom fonts that fall back badly, {{unrendered_merge_tags}}, and signature images that arrive as suspicious attachments. Send a test to Gmail, Outlook, and an iPhone mail client, and actually open all three. Thirty seconds per client, and it catches the embarrassing failures before 5,000 prospects see them.

9. Warm Up the Domain - and Cap Volume to Its Age

These two checklist items are inseparable, because they answer the same question mailbox providers are silently asking: does this domain's sending volume match its history? A domain that sent 20 emails last week and 4,000 today looks exactly like a compromised account or a freshly minted spam operation, and providers respond with throttling, spam-foldering, or outright rejection regardless of how clean your list and content are.

The warmup check. A new sending domain needs 3-6 weeks of gradually increasing, engagement-positive activity before it can carry real campaign volume. Practically, that means starting at 10-20 emails per day per mailbox and increasing roughly 10-20% every few days, with genuine engagement - opens, replies, threads - on the early mail. A note on tooling: automated warmup networks (pools of mailboxes that auto-open and auto-reply to each other) have been in mailbox providers' crosshairs since Google began detecting and discounting them; several major sending platforms have deprecated their warmup features under provider pressure. Treat automated warmup as a supplement at most. The engagement that reliably builds reputation in 2026 is real: seed conversations with colleagues and partners, early low-volume outreach to your warmest segments, and reply-worthy messages. Before a campaign, verify the domain has at least 3-4 weeks of consistent sending history and that recent mail is landing in the inbox - check Google Postmaster Tools and send test messages to seed accounts you control at Gmail and Outlook.

The volume cap check. Match your daily ceiling to domain maturity: under 3 months old, stay under 50 cold emails per mailbox per day; 3-6 months, up to 100-150; only mature domains with sustained positive reputation should exceed 200 per mailbox per day. These numbers align with what deliverability practitioners converge on across the industry, and the per-mailbox framing matters - scaling in 2026 is horizontal. Serious senders run multiple mailboxes across multiple secondary domains, each within safe limits, rather than pushing one domain hard. If you need 1,000 sends per day, that's 5-7 domains with 2-3 mailboxes each, not one mailbox on steroids.

Finally, verify your sequence math before launch. A 5,000-prospect campaign with a 4-step sequence isn't 5,000 emails - it's up to 20,000 over the sequence window. Divide by your daily cap and confirm the schedule your tool will actually execute stays under the ceiling on every single day, including the days when step 1 for new prospects overlaps with steps 2-4 for earlier ones. Ramping volume with a verified list compounds the benefit: warming a domain on unverified addresses means teaching providers your reputation with bounces baked in.

10. Schedule Sends by the Recipient's Timezone

An email that arrives at 3 a.m. recipient time doesn't get read at 3 a.m. - it gets buried under the 40-80 messages that accumulate before the recipient's morning triage, where it competes as item 30 in a batch-delete session. Email industry data consistently shows cold email engagement peaking on Tuesday through Thursday, between roughly 8 and 11 a.m. in the recipient's local time, with a secondary window in the early afternoon. The exact best hour varies by audience - executives skew earlier, developers later - but the principle doesn't: recency in the inbox at the moment of attention beats everything, and that requires sending by the recipient's clock, not yours.

The pre-send verification has three parts. First, confirm your list has timezone data and that it's populated. Most sending tools support timezone-based scheduling, but it silently falls back to a single global send time when the timezone field is empty - which for an international list means some meaningful fraction of your prospects get the 3 a.m. delivery. Derive timezone from company location or country fields if you don't have it explicitly; even country-level resolution (grouping into 3-5 timezone bands) captures most of the benefit. Second, check the distribution of your list across zones against your sending window. A list that's 60% US East Coast, 25% UK/Europe, and 15% APAC needs either staggered sends or per-zone segments; a single 9 a.m. Eastern blast hits London at 2 p.m. (acceptable) and Sydney at 11 p.m. (wasted). Third, verify the throttle interacts sanely with the schedule. If your tool spreads 300 sends across a 9-to-11 window with randomized intervals - which you want, because metronomic one-per-90-seconds sending is a bot fingerprint - confirm the window doesn't spill past lunch for the last third of the list.

Two second-order details separate careful senders. Avoid the top of the hour: a disproportionate share of automated email fires at :00, so scheduling at 9:17 or 10:43 both dodges the rush and looks more human. And respect the calendar, not just the clock - check the send date against public holidays in your target regions (a U.S. campaign landing on July 4th week, a French campaign in mid-August) and against your own prospects' industry rhythms, like avoiding month-end for finance roles. None of this rescues a bad message, but timing is one of the few free multipliers in cold email: identical campaign, identical list, and the well-timed version can outperform by 20-30% on opens simply by being near the top of the inbox when attention arrives.

11. Put Tracking Links on a Custom Domain

Here's a failure mode that catches even experienced senders: your domain is warmed, your list is verified, your copy is clean - and your email still hits spam because of the link inside it. When you enable click tracking, your sending tool rewrites every URL through a redirect domain, and by default that's a shared tracking domain used by thousands of the tool's other customers simultaneously. Your deliverability becomes hostage to the worst spammer sharing that infrastructure: when their campaigns get the shared domain flagged by Spamhaus DBL, SURBL, or Google Safe Browsing, every email containing it - including yours - inherits the penalty. Blocklist checkers routinely show popular sending platforms' default tracking domains cycling on and off blocklists, and you have zero visibility into or control over when it happens.

There's a second, subtler problem: domain mismatch. An email sent from yourbrand-outreach.com whose links resolve through track.someplatform.net presents exactly the pattern phishing detection is trained on - the visible sender and the link destination don't align. Corporate secure email gateways (Proofpoint, Mimecast, Microsoft Defender for Office 365) weight this heavily, and in B2B cold email, those gateways stand in front of a large share of your prospects. When your tracking domain matches your sending domain, links authenticate the message instead of undermining it.

The fix costs nothing but a DNS record. Create a subdomain of your sending domain - link.yourbrand-outreach.com or go.yourbrand-outreach.com - CNAME it to your platform's tracking endpoint, enable HTTPS on it (an http:// tracking link in 2026 is its own red flag, and most platforms now provision the certificate automatically), and select it as the tracking domain in your campaign settings. The pre-send verification: send yourself a test, hover over every link, and confirm each resolves through *your* domain, then click through and confirm the redirect actually works and the certificate is valid. Check every mailbox and every campaign, because tracking domain settings are frequently per-workspace and a new mailbox silently defaults back to the shared domain.

While you're auditing links, apply cold email link discipline: one link maximum in the body, no URL shorteners ever (bit.ly and friends are so abused that many gateways flag them on sight), no linking the raw URL as visible text if it's long and parameter-laden. Many senders go further and strip links from step 1 entirely, introducing them only after a reply - a message with zero links has one less surface for filters to score. And reconsider open tracking on the most sensitive campaigns: the tracking pixel is detectable, some gateways flag it, and Apple Mail Privacy Protection has made open data unreliable anyway. Replies are the metric that matters.

12. Test Your First-Line Personalization on Real Rows

Personalization is the difference between cold email and spam - both in the recipient's judgment and, increasingly, in the mailbox provider's, since engagement-based filtering means messages people reply to lift your whole domain and messages people ignore sink it. Email industry data consistently shows genuinely personalized first lines lifting reply rates 2-3x over template-only sends. But personalization that *breaks* is worse than none at all: "Hi {{first_name}}," or "loved your recent post about undefined" doesn't just lose the prospect, it advertises to everyone who receives it that they're row 3,412 in a spreadsheet.

The pre-send verification is mechanical and non-negotiable. First, audit the data columns your template references. For every merge field - first name, company, custom first line, trigger event - filter your list for blanks, and either fill them, set a fallback that reads naturally, or cut those rows. Check formatting while you're there: ALL-CAPS names from a scraped source ("Hi JENNIFER"), legal suffixes in company fields ("I saw that Acme Corp Ltd. raised..."), and first-name fields containing full names are the classic tells. Second, render real previews. Every serious sending tool can show the assembled message for a specific row - spot-check 10-20 rows minimum, deliberately including the messiest-looking ones, not just row 1. Third, send actual test messages for 2-3 rows to your own seed inbox, because preview rendering and sent rendering occasionally differ, especially around line breaks and conditional (spintax) blocks.

If you're using AI-generated first lines - standard practice at scale in 2026 - the failure modes shift from blank fields to confident nonsense: lines referencing a LinkedIn post the person didn't write, congratulating them on a funding round from two years ago, or opening with the same "I noticed that..." construction 4,000 times, which pattern-matching filters and pattern-matching humans both catch. Human-review a random 10% sample of generated lines before launch, and reject the batch if more than a couple fail. A useful quality bar: the first line should be specific enough that it couldn't be sent to anyone else on the list. "Loved your recent post" fails; "your point about onboarding drop-off at the 3-day mark matched what we measured" passes.

One connection senders miss: personalization quality and list verification are the same investment from different angles. There's no return on researching a thoughtful first line for a mailbox that no longer exists - across BounceZero's verification data, with 6-15% of typical outreach lists invalid, that's 6-15% of your research and AI-generation spend going straight into the void. Verify first, then personalize what's real.

13. Configure Bounce Monitoring Before the First Send Goes Out

Everything so far has been prevention. This final technical item is your early-warning system, and it must exist *before* the campaign starts - because the difference between catching a bounce spike at send 200 versus discovering it at send 5,000 is the difference between a paused segment and a burned domain. Deliverability failures are rarely gradual; they cascade. Bounces raise suspicion, suspicion triggers throttling and spam-foldering, spam placement kills engagement, and collapsed engagement confirms the provider's judgment. The senders who survive incidents are the ones whose monitoring caught step one.

Four components to verify. First, bounce processing: confirm your Return-Path/bounce mailbox is correctly configured and your tool is actually parsing what lands there - hard bounces (5xx: mailbox doesn't exist) must permanently suppress the address and pause it across every active sequence, while soft bounces (4xx: full mailbox, greylisting, temporary deferral) should retry with backoff and convert to suppression after 3-4 consecutive failures. Send a test to a known-invalid address at your own domain and confirm the bounce appears in your dashboard within minutes. Second, alert thresholds: decide your kill criteria in advance and write them down - a sensible default is pause the campaign automatically if bounce rate exceeds 3% at any point, and investigate manually above 1.5%. If your tool supports auto-pause, enable it; if not, commit to a manual check after the first 100-200 sends before the schedule releases the rest. Third, reputation dashboards: verify Google Postmaster Tools is set up for your sending domain (it requires DNS verification, so doing it mid-incident wastes a day you don't have) and check Microsoft SNDS if you control your IPs. Fourth, blocklist monitoring: schedule a recurring check of your sending domains, tracking domains, and IPs against Spamhaus, Barracuda, and SURBL - weekly at minimum, daily during active campaigns.

Then close the loop on interpretation. Not all bounces mean dead addresses: 5.7.x-class rejections often indicate policy blocks - your content or reputation, not their mailbox - and a cluster of those is a different emergency than a cluster of user-unknown bounces, requiring a content and reputation review rather than list cleaning. Distinguishing bounce classes is genuinely hard; it's one of the deeper problems in email verification, and it's why BounceZero's SMTP-response classification exists - the same taxonomy that powers our up to 99.8% accuracy in internal testing on SMTP-verifiable addresses applies to reading your bounce logs correctly. If you're building your own monitoring, our [email verification API](/api-email-validation) returns detailed per-address results at a provider-dependent response time, fast enough to re-verify addresses in real time as sequences progress - catching addresses that died between list verification and send step 3.

The Complete 15-Point Checklist - Save This

Here is the full checklist in run-through form. Copy it into your campaign SOP, your Notion template, or a note pinned next to your sending tool. The full pass takes 30-45 minutes for a new campaign and under 15 for a repeat send on established infrastructure - against the weeks it takes to recover a damaged domain, it's the best time investment in cold email.

Infrastructure (items 1-2):

1. Domain age & reputation - sending domain 60+ days old, secondary (not your primary brand domain), no blocklist hits, Postmaster reputation Medium or better.

2. SPF / DKIM / DMARC - all three pass on a test from the actual campaign tool; DKIM aligned to your From domain; DMARC at enforcement or moving toward it; valid MX on the sending domain.

List quality (items 3-5):

3. List verified - every address run through verification within the last 30 days; invalids, disposables, unwanted role accounts, and spam traps removed; projected bounce rate under 2%.

4. Catch-all strategy decided - written policy for the 20-30% of B2B addresses on accept-all domains: exclude, segment to a separate domain, or send with corroborating evidence.

5. Suppressions honored - master suppression list merged across all tools; previous unsubscribers, bouncers, and complainers excluded; one-click unsubscribe active.

Message (items 6-9):

6. From name matches persona - real person's name, consistent with signature, mailbox, and every identity detail in the message.

7. Preview text set - first line works as an inbox snippet, compounds with the subject, survives 40 characters on mobile.

8. No spam triggers in the subject - no urgency/money language, caps, fake RE:, or clickbait; 2-5 words, specific, colleague-toned.

9. Plain text present - proper multipart structure or fully plain-style send; under 100KB; no broken merge tags; tested in Gmail, Outlook, and mobile.

Sending mechanics (items 10-13):

10. Domain warmed - 3-4+ weeks of consistent, engagement-positive sending history; recent test mail landing in the inbox.

11. Volume capped to age - daily ceiling matched to domain maturity (≤50/day under 3 months); full sequence math checked, not just step 1.

12. Timing by recipient timezone - timezone data populated, sends scheduled Tue-Thu mornings local time, holidays checked, off-the-hour send times.

13. Custom tracking domain - all links resolve through your own subdomain over HTTPS; one link max; no shorteners.

Quality & safety (items 14-15):

14. Personalization tested - no blank merge fields, real-row previews checked, AI-generated lines human-sampled, test sends reviewed.

15. Bounce monitoring live - bounce processing verified, auto-pause threshold set at 3%, Postmaster Tools connected, blocklist checks scheduled.

Item 3 is the one to automate first, because it's the highest-risk item to skip and the easiest to systematize: a verification pass through BounceZero costs $3 per 1,000 addresses, returns in 5-10 minutes for dashboard jobs of up to 1,000,000 addresses, and every campaign inherits the protection. If you want to quantify what list hygiene is worth for your specific volume and bounce profile, our [ROI calculator](/roi-calculator) does the math. Run the checklist, every campaign, no exceptions - the discipline is the strategy.

Frequently Asked Questions

How often should I re-verify my cold email list?

Verify any list within 30 days of sending to it, and re-verify before every campaign if the list is older than that. B2B email data decays at roughly 2.1% per month as people change jobs and mailboxes get deprovisioned, so a list verified in January is carrying meaningful invisible rot by April. For long-running sequences, it's also worth re-verifying addresses before later sequence steps - an address can die between step 1 and step 4. At $3 per 1,000 verifications, re-verifying a 10,000-address list costs $30; a bounce spike that pushes your rate past 5% can cost you weeks of domain recovery and, on some platforms, your sending account.

What bounce rate is safe for cold email in 2026?

Keep hard bounces under 2% - that's the threshold below which most mailbox providers treat you as a sender who knows their recipients. Between 2% and 5% you're accumulating reputation damage with every send, and above 5% providers begin throttling, spam-foldering, or rejecting your mail, and many sending platforms suspend accounts. Across BounceZero's verification data spanning 50M+ emails, typical unverified outreach lists contain 6-15% invalid addresses, which means an unverified list almost guarantees you'll blow through both thresholds. Set an automatic campaign pause at 3% and investigate manually at 1.5% - catching a spike at send 200 instead of send 5,000 is what saves the domain.

Should I send cold email to catch-all addresses?

It depends on your risk tolerance, but never send to them undifferentiated from your verified-valid segment. Catch-all domains accept mail for any address, so standard verification can't confirm the specific mailbox exists - and 20-30% of a typical B2B list resolves to catch-all domains, so excluding them entirely sacrifices real pipeline. The recommended approach is segmentation: send to catch-alls from a separate sending domain at lower volume, prioritizing addresses with corroborating evidence the person exists (live LinkedIn profile, company team page). BounceZero's 3-probe catch-all detection also resolves a meaningful share of addresses that single-probe verifiers would leave as 'unknown,' shrinking the gray zone before you have to make the call.

Do I really need a separate domain for cold email?

Yes - this is one of the least negotiable items on the checklist. Cold email carries inherent reputation risk no matter how carefully you execute: complaint rates are higher than opt-in mail, and one bad campaign can land a domain on a blocklist. If that happens to your primary domain, your transactional email, password resets, invoices, and internal mail all suffer with it. Use a close variant of your brand (get-yourbrand.com, yourbrandhq.com), redirect it to your main site, warm it for 3-6 weeks, and cap its volume by age. At scale, run several secondary domains in parallel with 2-3 mailboxes each rather than pushing one domain past safe limits.

How long should I warm up a new sending domain before launching a campaign?

Plan on 3-6 weeks minimum. Start at 10-20 emails per day per mailbox with genuine engagement - real replies and threads, not just automated warmup pool activity, which mailbox providers have gotten aggressive about detecting and discounting - and increase volume 10-20% every few days. Before launching, verify the domain has consistent recent sending history, that test messages to your own Gmail and Outlook seed accounts land in the inbox, and that Google Postmaster Tools shows Medium or High reputation. Then keep volume matched to age even after warmup: under 50 cold emails per mailbox per day for domains under 3 months old, scaling to 100-150 at 3-6 months. Warming on a verified list matters too - building reputation on addresses that bounce teaches providers exactly the wrong lesson.

What's the fastest way to run this checklist before every campaign?

Split it into one-time setup and per-campaign checks. Items 1, 2, 10, 11, and 13 (domain, DNS, warmup, volume caps, tracking domain) are infrastructure - set them up once, then spot-check monthly and after any tool change. Items 3-9, 12, 14, and 15 are per-campaign: verify the list, apply suppressions, review the message, confirm scheduling and monitoring. In practice that's 30-45 minutes for a new campaign and under 15 for a repeat send. The list verification step is the easiest to make automatic: upload to BounceZero's bulk verifier and a 1,000,000-address dashboard job returns in 5-10 minutes, or wire our API (provider-dependent response time) into your workflow so every new prospect is verified the moment it enters your CRM. You can start with 100 free verifications per month, no credit card required.

Check Item 3 Off in the Next 10 Minutes

Verify your list with up to 99.8% accuracy in internal testing on SMTP-verifiable addresses at $3 per 1,000 emails - 100 free verifications every month, no credit card required.

Learn More
cold email checklist cold email setup email deliverability pre-send checklist cold outreach

Continue with related resources

Move from this article to the most relevant guide, tool, or evidence page.

AL

Written by

Ayoub Lebda

Founder, BounceZero - Email-infrastructure engineer

Ayoub built BounceZero's 5-stage validation pipeline, its dedicated BGP-announced IP infrastructure, and the Patroni HA PostgreSQL cluster behind every verification. Previously built high-volume email delivery infrastructure. Trained at 1337 Benguerir (École 42 network, 2019). Open-source: bgp_analyzer.