A lot of cold email audits stop too early.
The domains are authenticated. The mailboxes are connected. The sending tool reports no errors. Everything looks fine, so the team assumes the message or offer must be the problem.
Maybe it is. But passing the technical checks only means your email is allowed to compete for inbox placement. It does not mean the mailbox provider trusts the sender.
That distinction matters because a campaign can be technically correct and still be practically invisible.
Authentication gets you admitted
SPF, DKIM and DMARC help receiving servers verify where a message came from and whether it was altered along the way.
In plain language:
- SPF identifies which servers can send mail for your domain.
- DKIM adds a signature that helps verify the message.
- DMARC tells receiving servers what to do when those checks fail and gives the domain owner reporting options.
You need all three. I would not run a cold email campaign without them.
But they answer a narrow question: is this sender authorized to use this domain?
They do not answer the next question: should this message go to the inbox, a filtered folder, or spam?
Gmail and Microsoft 365 still look at how mail from your sending setup behaves. That includes bounces, complaints, engagement patterns, sending consistency and the history attached to the domain and mailbox.
So a green authentication screen is useful. It is not a deliverability result.
Sender reputation is built by campaign behaviour
Inbox placement depends on what you send, who receives it and how those people react.
Think about two campaigns using identical technical settings.
Campaign A sends 30 relevant emails a day to verified contacts in a narrow market. The offer fits, the targeting makes sense and negative replies are reviewed.
Campaign B sends 150 emails a day to an older list pulled from several sources. Titles are loosely matched, addresses have not been checked recently and every mailbox follows the same sending pattern.
Both campaigns can pass SPF, DKIM and DMARC.
They should not expect the same result.
The second campaign creates more opportunities for hard bounces, spam complaints, uninterested replies and long stretches of no engagement. Those outcomes tell mailbox providers something the DNS records cannot: recipients do not appear to want this mail.
This is why deliverability cannot sit with the person who set up the domains and disappear from the weekly campaign review. It is an operating responsibility.
More volume spends more reputation
Every outbound campaign has a reputation budget, even if the team has never named it that.
Each message creates some exposure. A valid, relevant email to the right person is a reasonable use of that exposure. A stale address or poor-fit contact spends it without giving the business much chance of a useful conversation.
The simple mistake is to treat available sending capacity as a target.
If five mailboxes can technically send 50 emails each per day, that does not mean the campaign should immediately send 250. Capacity tells you what the setup can do. It does not tell you what the list deserves.
For example, imagine an illustrative list of 1,000 contacts:
- 600 match the account criteria and hold a relevant role.
- 250 work at plausible companies but their role or need is unclear.
- 150 are stale, outside the target market or poorly matched.
Sending to all 1,000 creates 400 questionable attempts before copy even enters the discussion.
I would rather start with the 600, split them into smaller groups and watch what happens. Review bounce patterns, negative replies, positive replies and mailbox placement before increasing volume.
You can always send the next batch. You cannot take back a complaint or make a damaged domain history disappear overnight.
Watch the campaign, not just the setup
A useful weekly deliverability review should connect technical health with recipient behaviour.
Start with these checks:
- Are SPF, DKIM and DMARC passing for every sending domain?
- Are hard bounces rising in one list source, segment or mailbox?
- Are negative replies pointing to poor targeting or excessive follow-up?
- Has sending volume changed suddenly?
- Are one provider's results weaker than the other, especially Gmail versus Microsoft 365?
- Are replies falling across every message, or only in one segment?
- Are mailboxes continuing to send while a problem is being investigated?
That last question catches a lot of damage.
When a campaign weakens, teams often keep it running while they debate new subject lines. By the time they pause, another few hundred contacts have received the same weak campaign.
Set pause rules before launch. The exact limits depend on your sending history, market, list source and normal results, so I would not pretend one number fits every business. The rule itself is more important: decide which changes require a review, who owns that review and what must be true before sending resumes.
Fix the inputs before rewriting the email
Weak inbox placement is often blamed on copy because copy is easy to change.
Changing two lines feels productive. It is also useless if the contact list is stale, daily volume jumped too quickly or one mailbox has developed a poor history.
Check the campaign in this order:
- Confirm that authentication still passes.
- Compare performance by sending domain and mailbox.
- Compare Gmail and Microsoft 365 recipients separately.
- Review hard bounces and complaints by list source.
- Inspect whether the weakest segment belongs in the campaign.
- Reduce or pause sending while you isolate the problem.
- Test copy only after the sending and targeting issues are understood.
This order helps you avoid solving the wrong problem.
If one mailbox has fallen off while the others remain stable, rewriting the campaign for everyone makes little sense. If one data source produces most of the bounces, the list needs work. If every segment is reaching the inbox but nobody cares, then the message and offer deserve attention.
The point is to diagnose before you edit.
Deliverability is ongoing work
A technically correct setup can still produce poor placement because authentication and reputation do different jobs.
Authentication proves identity. Reputation is earned through sending behaviour and recipient response.
You need both.
So, when replies drop, do not ask only, "Are SPF, DKIM and DMARC set up?"
Ask a second question: "What has this campaign been teaching Gmail and Microsoft 365 about us?"
Then pick one manageable next step. Review the last two weeks by mailbox, recipient provider and list source. Where did the decline actually begin?
