Cold-email deliverability checklist
Verify the system.
A deliverability checklist cannot promise that a message will appear in a particular folder. Receiving systems evaluate identity, infrastructure, recipient feedback and local policy. The useful goal is to prove that your sending setup meets the documented requirements for each destination and that the people contacted should receive the message. Google's guidance applies specifically to personal Gmail accounts; Microsoft documents separate limits for Exchange Online senders. 12
Run the checks on the actual sending domain, mailbox and message path, not only on a domain you own. Save the date and result of each check. If an agency or platform sends on your behalf, include that route. This article is a verification order, not a workaround for provider controls.
1. Confirm the sender identity
List every domain and mailbox that will send campaign messages. For each, record who owns it, the visible From address, the service that submits mail, the return path and the provider used to send. Verify that each third-party sender is authorized in your domain setup. Google's baseline guidance lists SPF or DKIM for all senders, while its bulk-sender category lists SPF, DKIM and DMARC. Microsoft also recommends setting up SPF, DKIM and DMARC for your sending domain. 12
Do not merely check that a DNS record exists. Send a controlled message through every real path and inspect its authentication result. For direct email, Google says the visible From domain must align with either the SPF domain or the DKIM domain to pass DMARC alignment. 1 An authenticated but unrelated service domain is not the same thing as aligned identity. Document which identifier aligned and retain the result for later comparison when providers or settings change.
Google also requires a TLS connection for transmission to Gmail and describes the need for a sending IP address to have a matching reverse-DNS hostname. 1 Ask the sending provider who manages the IP and reverse DNS; the website DNS administrator may not control them. Record the hostname and responsible provider rather than assuming a valid website record proves mail infrastructure is correct.
2. Check recipient permission and suppression
Recipient quality is not a numerical trick. Google advises against sending messages to people who did not sign up to receive them. 1 Before a sequence starts, document where the address came from, what relationship or permission exists, the intended content and the jurisdiction. Remove recipients who have opted out or objected. A technically authenticated message can still be unwanted.
For applicable US commercial email, the FTC says there is no business-to-business exception to CAN-SPAM. 3 The FTC bars misleading header information and deceptive subject lines. 3 Its guidance also calls for a valid physical postal address and a clear explanation of how a recipient can opt out of future marketing email. 3 Treat these as legal scope checks, not proof that a contact is appropriate under every provider policy or every other country's law.
Build one suppression record that every mailbox, sequence tool and outsourced sender checks before each message. The FTC says a covered opt-out request must be honored within ten business days and that outsourcing does not remove the company's responsibility. 3 An internal process should stop scheduled messages when an objection arrives, without waiting for the outer deadline. Keep the request date, channel, affected address and confirmation that active sequences were stopped.
3. Verify the applicable opt-out mechanism
Google says marketing and subscribed messages must support one-click unsubscribe and show a visible link in the message body. 1 Check the mechanism by sending a test to a mailbox you control, using the opt-out path and confirming that later scheduled sends are suppressed. Do not label a link as functional merely because it appears in a template.
The FTC's US rule and Google's Gmail rule have different scopes and purposes. The FTC requires a clear way to stop future marketing email; Google's one-click requirement applies to marketing and subscribed messages sent to personal Gmail accounts. 13 A single implementation may need to satisfy both, but the page should not imply that meeting one requirement automatically satisfies all others. Review the current rules for each provider and region before launching.
4. Control sending volume and rate
Provider service limits are ceilings, not recommended campaign targets. Microsoft says Exchange Online applies outbound limits to cloud mailboxes at both user and organization levels, with recipient and message-rate limits enforced as hard service controls. 2 Its documentation lists a 30-message-per-minute mailbox submission rate and says excess submissions are throttled into later minutes. 2 That number does not mean sending at the cap is safe or appropriate.
Microsoft states Exchange Online is not designed for bulk-mailing scenarios and recommends spreading bulk sends over time rather than releasing everything at once. 2 Google likewise advises a consistent rate instead of bursts, a low starting volume to engaged users and gradual increases. 1 Record the expected daily and hourly load before launch and set alerts below provider limits. Do not split traffic across identities merely to evade a restriction.
Keep recipient frequency separate from total sender volume. One sender may be within a service limit while a single person receives too many messages from several representatives. Coordinate account ownership and stop rules across sequences. The responsible operations team should be able to answer both questions: how much mail did the domain send, and how many contacts did this person receive?
5. Monitor what providers actually report
Google advises monitoring delivery with Postmaster Tools as sending volume grows. 1 Microsoft identifies message trace as a way to track individual outbound messages and delivery failures. 2 Build a simple log of authentication result, provider response, deferral or rejection code, complaint or opt-out signal, and corrective action. Do not treat a dashboard as proof that every individual message arrived where you intended.
When a provider rejects or restricts a sender, investigate the cause before resuming. Microsoft explains that Exchange Online enforces outbound controls to protect against spam, bulk-mailing abuse and compromised accounts. 2 Check account security, recent sending changes and message traces, then follow the provider's remediation process. Do not create a new sender identity as a substitute for addressing the underlying issue.
Review the evidence after any change to DNS, provider, mailbox, routing or list source. A passing test from last month may not describe today's mail path. Keep dated screenshots or exported records of configuration, test messages and provider responses. That documentation makes it possible to tell whether a new problem followed an infrastructure change, a recipient-source change or a change in sending behavior.
FAQ
What should be checked first?
Is a published DMARC record enough?
Can an Exchange Online mailbox be used for unlimited bulk sending?
Does US commercial email law exempt B2B messages?
How we researched this
We checked Google's sender guidelines, Microsoft's Exchange Online sending-limit documentation and the FTC's US commercial-email guide on October 1, 2026. 123 The sources apply to different systems and jurisdictions. This checklist records what to verify, not a promise of placement or legal compliance in every market.
Rather have outbound done for you?
Modern Inbound runs the whole stack: the data, the inboxes, the copy and the replies. You take the meetings.
Talk to Modern InboundSources
- Google, email sender guidelines, checked October 1, 2026.
- Microsoft, Exchange Online sending limits, checked October 1, 2026.
- FTC, CAN-SPAM compliance guide, checked October 1, 2026.