The operational rules we run on every client campaign, and the panic reflexes that quietly make deliverability worse.
By Joel Wylie, Founder · Last updated 7 August 2026
Cold email deliverability in 2026 comes down to a short list of operational rules: send plain text, switch open tracking off, exclude domains behind strict corporate filters at the MX level, judge bounce rates as a sustained trend rather than a daily number, and scale sender volume only after a campaign has proven replies. The baseline underneath all of it is the authentication stack, SPF, DKIM and DMARC, that Google's sender guidelines now require of anyone sending at volume, and Google Postmaster Tools will show you how your domain is actually being scored. Almost everything else you read is superstition. We run cold outbound for clients every day, and the gap between what actually moves inbox placement and what people panic about is enormous.
This post splits the two apart. First the rules we enforce on every single campaign. Then the panic reflexes we see operators reach for, and what we do instead.
Cold emails should be plain text, full stop. HTML templates, images, styled signatures, and buttons pattern-match to marketing mail, and marketing mail is exactly what corporate filters are built to catch. A cold email should look like something a real person typed to one other person, because that is the only category of mail that reliably lands.
We enforce plain-text sending as a hard setting on every cold campaign we run. It is checked at launch and re-checked after every settings change, because sending platforms can quietly flip it.
There is exactly one exception in our system: post-reply follow-up emails. Once a prospect has replied, the conversation is no longer cold, and those follow-ups carry a real clickable calendar link. That needs HTML, so follow-up campaigns run HTML and cold campaigns never do. If your cold email needs a button, the problem is the email, not the format. Links do not belong in cold email at all, which we cover in detail in our post on links in cold email.
No. Open tracking works by inserting a hidden pixel image into every email, and tracking pixels hurt cold deliverability. You are volunteering a marketing-mail fingerprint on every send in exchange for data that is unreliable anyway, since security scanners and image proxies fire opens that no human ever saw.
We run open tracking switched off on every campaign as a standing rule. The trade is not close. The metrics that actually tell you whether a campaign works are replies and interested replies, and you get those without a pixel. If you want to know what good reply numbers look like, see our cold email reply rate benchmarks.
Never send cold email to domains protected by strict corporate mail gateways like Mimecast and Barracuda. Mimecast rejects mail from new sending domains at close to 100% on policy. It does not matter how valid the address is or how good the copy is; the gateway refuses the connection because your domain is unknown to it.
The numbers are brutal. On one campaign we analysed, Mimecast-protected domains were 7% of the list but 77% of all bounces. On another, they were around 4% of the list and 64% of the bounces, bouncing at roughly a 35% rate, a 16x over-index against the rest of the list. Barracuda was the second-worst gateway in the same analysis. For contrast, Microsoft 365 bounced at 0.6%, Google at 0.9%, and Proofpoint at 1.2%. Those providers are fine to send to. The appliance-style gateways are not.
You find these domains with an MX lookup. Every domain publishes MX records saying which mail server receives its email, and if that server is Mimecast or Barracuda, we drop the lead before it is ever uploaded. We check every unique domain on every list, never a sample, because a spot check on one build came back clean while the full sweep still found protected domains hiding in the send set. The exclusion happens silently at list build. No verification tool fixes this, because it is receiver policy, not address validity. The full detection method sits in our email deliverability playbook.
A bounce rate is only a problem when it is sustained above roughly 6% across two or more consecutive days. A single-day spike is noise, and we never act on one. That threshold and that two-day rule are how our own monitoring is wired, and the reasoning matters more than the number.
Dead addresses bounce exactly once. The sending platform then suppresses them, so a bounce spike driven by dead addresses burns itself out over a few days as the deadwood clears. Panicking on day one means reacting to a problem that is already fixing itself.
The type of bounce matters more than the count. Bounces caused by non-existent mailboxes are tolerated by mailbox providers as normal mailflow; every list carries some. Bounces caused by policy and reputation blocks are the ones that actually damage your sending domains, and they call for slowing down and letting domains age, not for touching the list at all. Same headline number, opposite fixes. That is why we diagnose the composition of the bounces before choosing a lever, every time.
Start every new sender at 1 email per day, and hold there until the campaign has proven replies. Once real replies are coming in, scale to around 3 per day per sender. That is the whole rule.
The logic is that volume is fuel, not the fix. Scaling a campaign that has not proven it can generate replies just burns sender reputation faster on a message that does not work. Scaling one that has proven replies is pouring fuel on a fire that is already lit. Deliverability rewards patience at the start far more than any warm-up gadget does.
Related: a handful of disconnected senders in a workspace is normal churn, not a crisis. Mailbox connections drop for mundane reasons and get reconnected. We do not treat routine sender maintenance as a deliverability signal at all.
The difference between operators who keep campaigns healthy and operators who wreck them is what they do in the first hour after seeing a scary number. Here is the honest comparison.
| Signal | The panic response | What we actually do |
|---|---|---|
| One-day bounce spike | Pause everything, re-verify the whole list | Nothing yet. Dead addresses bounce once then get suppressed, so the rate self-corrects. We only act on a sustained trend above roughly 6% across 2+ days. |
| Sustained bounce rate above 6% | Re-verify the entire list and resume | Diagnose first: break bounces down by mail provider and by bounce code. Re-verification fixes only one of the five bounce causes, so we identify which cause we have before pulling any lever. |
| One mail gateway dominating bounces | Blame the sending tool or "the algorithm" | MX-check the list and hard-exclude that gateway. When strict corporate filters like Mimecast over-index, no amount of verification helps, because rejection is policy-based. |
| Policy and reputation rejections on young domains | Buy more domains and blast harder | Slow down, confirm warm-up is on and daily caps are sane, and let the domains age. Reputation blocks are the one bounce type that genuinely kills deliverability. |
| A few senders showing disconnected | Declare an infrastructure crisis | Reconnect them and move on. A handful of disconnected senders is routine churn. |
| Low reply rate with clean deliverability | Blame spam folders | Fix the offer. When mail is landing and nobody replies, the message is the problem, not the infrastructure. |
A one-day bounce spike means almost nothing. Bounce rate is a trend metric, and the trend only matters above roughly 6% held across two or more consecutive days. Below that, or for a single day, the correct response is to keep sending and watch.
Re-verification is the most common reflex and it fixes only one narrow case: a genuine verifier miss on a normal domain. It does nothing for policy blocks from corporate gateways, nothing for reputation rejections on young domains, nothing for catch-all domains that accept every address and bounce the dead ones later, and nothing for content-triggered filtering. We learned this the hard way, spending money re-verifying a list where the diagnosis showed most bounces were coming from one corporate gateway that rejects new senders on policy. Verification could never have caught a single one of them. Diagnose first, then pick the lever. We wrote a full companion guide on when verification actually helps: how to verify an email list.
When deliverability checks out clean and replies are still flat, the offer is the problem. "The algorithm" is where accountability goes to die. Mail providers are not conspiring against your domain; your message is landing and being ignored, which is worse news and better news at the same time, because the fix is entirely in your hands.
Deliverability is not bought with more domains and more senders. New senders start at 1 email per day and earn their volume by producing replies. Infrastructure scales behind a proven message. Stacking sending capacity in front of an unproven one just spreads the damage across more domains.
A bounce rate above roughly 6% sustained across two or more consecutive days is a real problem worth diagnosing. A single-day spike is noise, because dead addresses bounce exactly once, get suppressed, and the rate self-corrects as the deadwood burns off.
Cold emails should be plain text. HTML templates, images, and styled buttons pattern-match to marketing mail. We reserve HTML for one place only: post-reply follow-up emails, where a clickable calendar link genuinely helps someone who already wants to book.
Yes. Open tracking inserts a hidden pixel into every email, and tracking pixels hurt cold deliverability. Open data is also unreliable. We run open tracking switched off on every cold campaign as a standing rule.
No. Mimecast rejects cold mail from new sending domains at close to 100% on policy, regardless of whether the address is valid. We detect Mimecast and Barracuda at the MX level and silently exclude those domains at list build.
Start each new sender at 1 email per day until the campaign has proven replies. Once real replies are coming in, scale to around 3 per day per sender. Volume follows proof, not the other way round.
No. A handful of disconnected senders in a workspace is normal churn, not a crisis. Reconnect them and move on. The signals worth acting on are sustained bounce rates and policy-level rejections, not routine account maintenance.
Want outbound like this run for you, end to end?
Book A Call
No URLs, no email addresses, no domain names in cold copy. The two reasons, and what to do instead.

Real benchmark tiers from an agency sending 50,000 cold emails a month per client, and why the reply rate everyone quotes is measuring the wrong thing.

Verification is not optional for scraped or built lists. Here is exactly when to verify, what verifiers can and cannot catch, and how not to overpay for it.