Cold email / infrastructure

Cold email infrastructure: the plumbing nobody shows you

We run our own cold email infrastructure on a 60/40 split of Microsoft and Google inboxes, and a mature campaign here sends 10,000 emails a day without touching spam. Most guides to cold email infrastructure are written by a tool trying to sell you a dashboard. This one is written by the people who run the plumbing.

5 million of those emails went out in the past 12 months. 3,000+ of them turned into booked calls. None of that happens if the infrastructure underneath is wrong, because the offer, the list, and the copy never reach an inbox to be judged.

Short version up front: cold email infrastructure is the domains, mailboxes, DNS authentication, warmup, and monitoring underneath a campaign, and the working numbers are 20 to 30 cold sends per inbox per day, 2 to 3 mailboxes per Google domain or up to 100 per Microsoft tenant, with SPF, DKIM, and DMARC live before the first send.

Infrastructure is not personality. It is plumbing. Get it wrong and nothing else you write matters.

The cold email infrastructure numbers that actually hold

These are the working answers, not the marketing-page answers. They assume you are sending cold, not newsletters, which is a different game with different rules.

QuestionThe working answerWhere it breaks
Inboxes per domainGoogle 2-3; Microsoft up to 100 (1 domain = 1 tenant)Quoting one provider's ratio as if it were universal
Domains neededSize in inboxes first, then convert at your provider's ratioFixing a domain count before knowing which provider it sits on
Safe sends per inbox, cold20-30 a day at steady stateConfusing the provider's technical ceiling with a safe cold-send number
DNS records requiredSPF, DKIM, and DMARC, all 3, before send 1DMARC published as p=none and never tightened
Warmup before cold sending2-4 weeks per inboxDomain bought Monday, cold send Tuesday
Our infrastructure, past 12 months
60/40
Microsoft to Google inbox split
10,000/day
Sent on a mature campaign
5M+
Cold emails sent, past 12 months

Infrastructure is plumbing, not personality. Get it wrong and the rest is unread.

What cold email infrastructure actually is

Cold email infrastructure is the domains, mailboxes, DNS authentication, warmup, and monitoring underneath a campaign. It is not the sending tool. Instantly, Smartlead, and every other sequencer sit on top of infrastructure, they do not replace it. You can run the sharpest sequencer on earth through infrastructure that was never warmed up correctly, and every email lands in spam before anyone reads the subject line.

The job of infrastructure is boring on purpose. It exists so the offer, the list, and the copy get a fair shot at being judged on their own merits, instead of getting killed by a spam folder before a human ever sees them.

Monitoring is the part most setups skip. A domain does not send you a warning before it gets blacklisted, it just quietly stops landing in inboxes. Free blacklist checkers exist, Google Postmaster Tools shows you your own domain's reputation on Gmail, and most sending platforms surface bounce and complaint rates in real time. None of it helps if nobody looks. Put a name on who checks it every week, or it will not happen.

How many domains do you need for cold email

Work backward from the volume you actually want to send, but do not start with a domain count. Start with inboxes, because how many inboxes fit behind one domain depends entirely on the provider, and the two are nothing alike.

  • Google: 2 to 3 mailboxes per domain. At 20 to 30 cold sends per inbox, a fully ramped Google domain carries 40 to 90 sends a day.
  • Microsoft: up to 100 mailboxes per domain. The standard build is one domain to one tenant to 100 mailboxes, billed flat whether you fill 40 slots or all 100. On this side the domain is not the limiting unit.

So the same target volume produces wildly different domain counts:

  • 300 emails a day is roughly 12 inboxes: 4 to 6 Google domains, or one Microsoft tenant.
  • 1,000 emails a day is roughly 40 inboxes: 15 to 20 Google domains, or one Microsoft tenant.
  • 10,000 emails a day is roughly 400 inboxes: 130 to 200 Google domains, or about 4 Microsoft tenants.

Our own mature campaigns run at that last line, split 60/40 across Microsoft and Google infrastructure so no single provider's policy change can take the whole operation down at once. The split is also why the math above matters: the Google half of a 10,000-a-day operation accounts for nearly all of the domains, and nearly all of the administration.

Nobody starts there. We didn't either. Infrastructure gets built in the same order every time: a handful of domains warmed and proven first, volume added only as bounce and spam-complaint rates stay clean, more domains bought when the existing ones are already earning their keep. Buying the full count on day 1 and warming all of it at once just means burning every domain at the same speed instead of a few.

One rule sits above all of this: never send cold from your primary business domain. A bounce spike or a spam flag on a domain built for outbound should never be able to touch the domain your website, your invoices, and your real inbox live on. Buy alt domains, close enough to your brand to look legitimate, and keep them entirely separate.

How many inboxes per domain for cold email

There is no single number here, and anyone who gives you one is quoting their own provider and calling it a law.

On Google, 2 to 3.Everything rides on that one domain's reputation, so stacking mailboxes concentrates risk without buying much more safe volume. Put 10 on a single domain and the day it gets flagged you lose 10 inboxes in one event instead of 3.

On Microsoft, up to 100. The standard build is one domain to one tenant to 100 mailboxes, and the tenant bills flat regardless of how many slots you fill. The economics push the opposite way: fewer domains, more mailboxes behind each one.

We covered the per-inbox ramp and daily volume math in how many cold emails to send per day, this is the domain-level version of the same principle: spread the risk, do not concentrate it.

Sending limits by provider, and why they do not matter as much as you think

Google Workspace technically allows up to 2,000 sends a day per user, and Microsoft 365 allows 10,000 recipients a day per user under a 30-messages-per-minute rate limit. Neither number is a cold-send number. Those ceilings exist for transactional and permission-based mail. Send cold at anywhere close to them from a fresh mailbox and deliverability collapses inside a week.

The number that actually matters for cold outreach is 20-30 sends per inbox a day at steady state, ramped up slowly from a handful on day 1. The provider's technical ceiling and your safe cold-sending ceiling are two different numbers, and confusing them is one of the fastest ways to burn a new domain.

The DNS setup: SPF, DKIM, and DMARC in plain terms

All 3 records, correctly configured, before the first cold email goes out. Not after.

  • SPF lists which servers are allowed to send mail for your domain.
  • DKIM signs every email cryptographically so a receiving server can confirm it was not altered or spoofed in transit.
  • DMARC tells receiving servers what to do when SPF or DKIM fails, and reports back to you when someone tries to spoof your domain.

Google's bulk sender guidelines require all 3 for any domain sending 5,000 or more messages a day to Gmail addresses, plus a spam complaint rate under 0.3% and one-click unsubscribe on marketing mail that meets RFC 8058. Keep your own target tighter than the requirement: complaints under 0.1% and bounces under 2%, under 1% on freshly verified lists. This is not a best-practices suggestion. Since late 2025, Gmail rejects non-compliant bulk mail outright instead of routing it to spam.

What cold email infrastructure setup actually costs

Budget roughly $10-15 a year per domain, plus the mailbox licensing on Google Workspace or Microsoft 365. Multiply that by however many domains the volume math above gives you. The shape of the bill differs by provider: Google charges per mailbox, so cost tracks inbox count, while a Microsoft tenant bills flat per domain whether you fill 40 of its 100 slots or all of them. Either way the license line is the small number.

The license fee is almost never the real cost. The real cost is the hours: buying domains, configuring DNS on every one of them, running a proper warmup schedule per inbox, and checking blacklist and bounce signals every week for as long as the infrastructure exists. Skip that ongoing maintenance and the setup decays quietly until a campaign that worked in month 1 is landing in spam by month 4, with nobody able to say exactly when it broke.

A managed infrastructure provider folds most of that labor into a monthly fee per mailbox, usually at a real premium over the raw license cost. That premium buys speed and someone else on call when a domain gets flagged. It does not buy you out of watching your own numbers. A provider can hand you clean infrastructure and you can still burn it in a month by ignoring what it tells you.

Build it yourself or buy it from a provider

Build it yourself if you have the hours to own DNS, warmup, and weekly monitoring, and you want full control of every domain's reputation. Buy from a managed infrastructure provider if speed matters more than control and you are fine paying a premium for someone else to carry the maintenance load.

Either path fails the exact same way: nobody watching bounce rate and spam complaints on a weekly cadence. A tool did not build our infrastructure and a tool will not maintain yours. This is the unglamorous half of GTM engineering, the part that never makes it into a highlight reel because there is nothing to screenshot.

What breaks cold email infrastructure

When infrastructure fails, it is almost always one of these 5 things:

  1. Sending cold from the primary business domain. One bad send and the domain your whole company depends on is compromised, not just an outbound channel.
  2. Skipping or rushing warmup. A domain bought Monday and sending cold Tuesday reads as spam to every provider on the receiving end, because it is exactly what spam looks like.
  3. Stacking too many inboxes on one domain. It does not raise the safe ceiling much. It just moves all the eggs into one basket.
  4. Confusing the provider's technical limit with a safe cold-send number. 2,000 a day on paper does not mean 2,000 a day is safe from a fresh inbox.
  5. No weekly monitoring. Bounce and spam-complaint rates drift for weeks before anyone notices, and by the time someone does, the domain is already flagged.

None of these are copy problems or list problems. They sit underneath both, which is why a campaign can have a great offer and a precise list and still die quietly in spam. We covered what a working campaign looks like once the plumbing holds in cold email reply rate benchmarks.

tl;dr: size the system in inboxes at 20 to 30 cold sends each, then convert to domains at your provider's ratio (2 to 3 mailboxes per Google domain, up to 100 per Microsoft tenant), get SPF, DKIM, and DMARC live before day 1, warm up 2-4 weeks per inbox, and never touch your primary business domain. More field data like this lives on the blog index.

FAQ

What is cold email infrastructure?

The domains, mailboxes, DNS authentication (SPF, DKIM, DMARC), warmup, and monitoring that let cold volume land in an inbox instead of spam. It is not the sending tool. Instantly, Smartlead, and the rest sit on top of infrastructure, they are not the infrastructure itself.

How many domains do I need for cold email?

Size the system in inboxes first, then convert to domains at your provider's ratio, because the two are nothing alike. 1,000 emails a day is roughly 40 inboxes at 20-30 cold sends each. On Google that is 15 to 20 domains at 2-3 mailboxes apiece. On Microsoft, where the standard build is one domain to one tenant to 100 mailboxes, the same volume can sit on a single tenant. Never send cold from your primary business domain either way.

How many inboxes per domain should I run for cold email?

It depends on the provider. On Google, 2 to 3: everything rides on that one domain's reputation, so stacking mailboxes concentrates risk without buying much more safe volume. On Microsoft, up to 100, because the standard build is one domain to one tenant to 100 mailboxes billed flat. Quoting either number as universal is the most common mistake in cold email infrastructure.

How much does cold email infrastructure setup cost?

Budget roughly $10-15 a year per domain plus a per-mailbox license on Google Workspace or Microsoft 365, multiplied by however many domains the volume math above gives you. The license fee is rarely the real cost. The real cost is the hours spent on DNS records, warmup schedules, and blacklist monitoring that a broken setup demands later.

Do I need a separate domain for cold email?

Yes, always. A bounce spike or spam flag on a cold-sending domain should never be able to touch the domain your invoices, your website, and your real inbox live on. Buy alt domains for outbound and keep your primary domain out of it entirely.

Should I build my own cold email infrastructure or use a provider?

Build it yourself if you have the time to own DNS, warmup, and monitoring and want full control of the reputation. Use a managed infrastructure provider if you want it live faster and are fine paying a premium for someone else to carry the maintenance. Both fail the same way if nobody watches bounce and spam-complaint rates weekly.

We build and hand over this exact infrastructure layer as part of the foundation build, the same system behind the lead generation work we run for consulting firms. Bring your current setup to a call and we will tell you honestly whether the problem is the plumbing or something upstream of it. Book a time here.

PS - most "deliverability problems" we get called in to fix turn out to be a domain that never warmed up in the first place.