← All posts · Deliverability

Cold Email Deliverability Audit: How to Check If Your Domains, DNS, and Mailboxes Are Actually Healthy

By · · 9 min read

A cold email deliverability audit is a structured check of your domains, DNS records, mailbox setup, and sending behavior because inbox placement fails long before reply rates drop. At OutboundPros, where we run 36 active campaigns and have shipped 200+ outbound systems, we use a simple audit process to catch broken SPF, weak DKIM, missing tracking domains, overworked mailboxes, and bad list inputs before they turn into 2% reply rates and burned infrastructure.

What Is a Cold Email Deliverability Audit?

A cold email deliverability audit is a full inspection of the technical and operational pieces that decide whether your emails land in inboxes because deliverability problems usually come from infrastructure, not copy.

Most teams look at open rates, see a drop, and assume the market is tired or the offer is weak. That is backward. If your domains, DNS, forwarding, authentication, and mailbox usage are off, your campaign can look dead even when the targeting and messaging are fine.

At OutboundPros we treat audits as pre-launch and mid-campaign maintenance. We do them before sending, again after the first 7 to 14 days, and any time a client sees a sudden change in opens, positive replies, or bounce patterns. That timing matters because a domain can look healthy on day 1 and still get damaged by bad list hygiene, aggressive ramping, or sloppy mailbox rotation by week 3.

A real audit checks four layers:

- Domain health
- DNS and authentication setup
- Mailbox-level reputation and sending behavior
- List quality and campaign configuration

An honest limitation: no audit gives you a perfect inbox-placement score across every recipient environment. Google, Microsoft, and corporate filters all score mail differently. The goal is not certainty. The goal is removing obvious failure points before they compound.

How Do You Check If Your Domains Are Actually Healthy?

Domain health is the condition of your sending domains and subdomains because reputation starts at the domain layer before the mailbox even gets evaluated.

The first thing to check is whether you are sending cold email from the right type of domain. Your main company domain should usually not carry all outbound volume. In most cases, you want adjacent domains or subdomains dedicated to outbound so you can protect the primary brand domain.

A practical domain audit includes:

- Domain age
- Whether the domain has a clean history
- Whether the domain is indexed and looks real
- Whether it has a basic site, legal pages, and inboxes that make sense
- Whether multiple mailboxes are distributed across domains instead of stacked into one

At OutboundPros we usually prefer aged domains over brand-new ones when possible, and we spread volume conservatively. A common working range is 2 to 5 mailboxes per domain, depending on provider, setup quality, and campaign risk. If someone is trying to run 10 mailboxes on one fresh domain and push 50 emails per mailbox per day immediately, that is not scaling. That is just burning inventory faster.

You should also look for obvious inconsistencies. If the domain is called something close to your brand but has no website, no real inbox naming convention, and no presence beyond outbound, filters notice that. Prospects do too.

Useful checks include:

1. Confirm each sending domain resolves properly.
2. Confirm the website loads and is not broken or blank.
3. Confirm the domain is not on major public blacklists.
4. Confirm the domain is not being reused across unrelated tools or old campaigns.
5. Confirm sending volume per domain is still within the original design.

One operator detail that gets missed: forwarded inboxes can create hidden problems. We have seen teams set up outbound domains correctly, then forward all replies into a main workspace in a way that muddies routing or causes missed responses. Domain health is not just reputation. It is whether the domain works cleanly in your real workflow.

How Do You Audit SPF, DKIM, DMARC, and DNS Records?

DNS deliverability records are the trust signals that prove your sending system is authorized because inbox providers need technical evidence that your email is legitimate.

If SPF, DKIM, and DMARC are missing, misaligned, or conflicting, your emails can still send but perform far worse. This is one of the most common hidden failures in cold email setups.

Your DNS audit should verify:

- SPF exists and includes the right sending services
- DKIM is enabled and passing for each mailbox provider and sending platform
- DMARC exists and aligns with the domain in the From address
- MX records are correct
- Custom tracking domain, if used, is configured correctly
- There are no duplicate or conflicting SPF records

Here is the simple version of what each record does:

| Record | What it checks | Common failure |
|---|---|---|
| SPF | Which servers can send for your domain | Multiple SPF records or missing sender include |
| DKIM | Whether the message was cryptographically signed | DKIM not enabled in the mailbox provider |
| DMARC | How SPF and DKIM should align and how failures are handled | No record at all or wrong alignment |
| MX | Where incoming mail should be routed | Broken reply handling or mailbox errors |

At OutboundPros we regularly find setups where a tool was connected but DNS was only half-finished. The campaign technically launched, but DKIM was not aligned or the tracking domain was pointed wrong. On paper, everything looked active. In reality, the infrastructure was leaking trust from day one.

A practical limitation: a passing SPF, DKIM, and DMARC setup does not guarantee inboxing. It only removes technical distrust. You still need sane sending behavior, decent copy, and clean data.

For tools, we typically verify records in the domain host first, then cross-check inside the mailbox provider and sending platform. If you use Google Workspace, Microsoft 365, Smartlead, Instantly, or Salesforge, make sure the records match what the actual sending path requires, not what someone copied from an old tutorial.

How Do You Know If Your Mailboxes Are Healthy?

Mailbox health is the reputation and operating condition of each sender inbox because inbox providers score behavior at the mailbox level as well as the domain level.

A domain can be fine while one or two mailboxes are damaged. That is why looking only at domain setup is not enough.

Healthy mailboxes usually show a few patterns:

- Stable open rates relative to the audience and provider mix
- Low hard bounce rates, typically under 3%
- Low spam complaint signals
- Consistent sending volume instead of spikes
- Human-like sending windows and reply handling

Warning signs include:

- Open rates crashing across one mailbox but not the others
- Messages landing in spam seeds or internal tests
- Temporary blocks or provider warnings
- Unusual bounce language tied to reputation or policy
- One mailbox producing almost all unsubscribes or negative replies

At OutboundPros we audit mailbox health by comparing performance inbox by inbox, not just campaign by campaign. If one mailbox in a batch of four suddenly drops from 45% opens to 18% while the others hold steady, that is usually a mailbox problem, not a market problem.

A practical operating range many teams can handle safely is 20 to 35 cold emails per mailbox per day once the mailbox is warmed and stable. Some setups can go higher. Some should stay lower. Anyone promising a universal number is guessing.

Also check basic hygiene details:

- Display name matches the sender identity
- Signature is simple and consistent
- Time zone matches the persona and market
- Replies are being monitored daily
- Calendar links and links in general are not overused

One honest trade-off: replacing a damaged mailbox is sometimes faster than trying to rehabilitate it. If a mailbox has weeks of poor engagement and obvious filtering issues, we often cut it, swap in a fresh one on healthy infrastructure, and protect the rest of the system.

What Metrics Should You Look At During a Deliverability Audit?

Deliverability metrics are directional signals of inbox placement quality because cold email health shows up in patterns, not in one vanity number.

Do not audit with open rate alone. Privacy protection and provider behavior make opens noisy. You need a broader view.

The metrics we care about most are:

- Hard bounce rate
- Soft bounce rate
- Positive reply rate
- Negative reply rate
- Unsubscribe rate
- Spam or provider block indicators
- Mailbox-level variation
- Domain-level variation over time

Here is a practical interpretation table:

| Metric | Healthy range | What a problem can mean |
|---|---|---|
| Hard bounce rate | Under 3% | Bad data, poor verification, or catch-all issues |
| Positive reply rate | Often 0.5% to 5% depending on market | Low if targeting, offer, or inboxing is weak |
| Negative reply rate | Usually under 1% to 3% | Misaligned messaging or too much volume |
| Unsubscribe rate | Usually low and stable | Copy, targeting, or frequency issue |
| Open rate | Context dependent | Useful only when compared across mailboxes and time |

At OutboundPros we also compare metrics by source list, by sending domain, and by copy variant. That matters because bad data can masquerade as bad deliverability. We have seen campaigns where one enrichment source caused bounce pressure across only half the mailboxes, making the whole setup look broken when the real issue was upstream list quality.

If you want one operator rule, use this: sudden change is more important than absolute number. If a mailbox that was stable for 3 weeks sharply drops while volume and targeting stay constant, investigate infrastructure first.

How Do You Spot Problems Caused by Sending Tools, Tracking, and Automation?

Tool-level deliverability issues are failures created by your sending software and automations because configuration choices change email fingerprints, tracking behavior, and sending patterns.

A lot of teams set up domains correctly and still hurt deliverability through the tool layer. The most common reasons are overly aggressive ramping, broken custom tracking domains, sending windows that look robotic, and automations that trigger too many follow-ups too quickly.

Your audit should review:

- Which sending platform is being used
- Whether open tracking is enabled and necessary
- Whether click tracking is enabled and necessary
- Whether a custom tracking domain is configured
- Whether sending is randomized within a realistic window
- Whether follow-up timing is sane
- Whether unsubscribe and stop conditions are working

At OutboundPros we are conservative with tracking. In many cold email environments, extra tracking can create unnecessary risk, especially click tracking. If a team is heavily measuring every click but struggling to inbox, the cleaner setup usually wins.

Common tool mistakes include:

- Turning on tracking without custom domain alignment
- Sending too many steps too close together
- Running multiple tools from the same mailbox stack without coordination
- Forgetting to pause mailboxes after bounce spikes or provider warnings
- Pushing high volume immediately after mailbox creation

An honest limitation here: no sending tool is magic. Smartlead, Instantly, Salesforge, and similar platforms can all work. They can all also be misconfigured. The tool matters less than whether the sending pattern is believable and the infrastructure is clean.

How Do You Separate Deliverability Problems From List and Copy Problems?

Separating deliverability from targeting and copy means isolating the true cause of low performance because fixing the wrong layer wastes weeks.

If your campaign is underperforming, ask three questions in order. Are emails being delivered? Are they reaching the right people? Are they giving those people a reason to reply?

A simple diagnosis framework looks like this:

1. If bounce rates are high, fix data and mailbox setup first.
2. If opens suddenly drop across healthy campaigns, inspect infrastructure and mailbox reputation.
3. If opens hold but replies are weak, inspect targeting, offer, and copy.
4. If one list segment performs much worse than another, inspect data source and persona fit.

At OutboundPros we often run controlled comparisons. Same copy, same offer, two mailbox groups. Or same list, two copy angles. That isolates the variable faster than guessing.

Some useful clues:

- Low opens plus low replies usually point to deliverability or severe targeting mismatch.
- Normal opens plus low replies usually point to list quality, weak relevance, or bad positioning.
- Good replies from one mailbox cluster and poor results from another usually point to mailbox health.
- High bounce rates from one data vendor usually point to enrichment quality.

The honest trade-off is that real campaigns are messy. Sometimes two things are broken at once. A mediocre offer can hide under deliverability issues, and shaky infrastructure can hide under a bad list. The audit process works when you test one layer at a time.

What Should You Fix First After the Audit?

Post-audit prioritization is the order you repair issues by impact because not all deliverability problems deserve equal urgency.

Fix technical blockers first, then reputation risks, then optimization items. If SPF is broken, that comes before debating whether your second follow-up is too long.

A practical priority order is:

1. Broken DNS and authentication
2. High bounce sources and unverified data inputs
3. Damaged mailboxes or overloaded domains
4. Tool misconfiguration and tracking issues
5. Ramp schedule and send-volume problems
6. Copy and sequence cleanup

Here is a simple repair table:

| Issue | Priority | Typical fix |
|---|---|---|
| Missing DKIM or bad SPF | Immediate | Correct DNS and revalidate sending path |
| Hard bounce rate above 3% | Immediate | Pause list source, reverify leads, remove risky segments |
| One mailbox underperforming badly | High | Pause, test seed placement, replace if needed |
| Too many mailboxes on one domain | High | Redistribute volume across more domains |
| Tracking setup looks suspicious | Medium | Disable unnecessary tracking, align custom domain |
| Weak reply rates with healthy infra | Medium | Rework offer, targeting, and copy |

At OutboundPros we usually prefer making a few meaningful fixes, then measuring for 5 to 7 sending days before changing more variables. The fastest way to lose the plot is to rebuild domains, rewrite copy, change tools, and swap lead sources all in one afternoon. You will not know what actually worked.

How Often Should You Run a Deliverability Audit?

Deliverability audits should run on a schedule and after major changes because cold email infrastructure degrades gradually and sometimes fails suddenly.

A good baseline schedule is:

- Before launching any new domain or mailbox cluster
- After the first 7 to 14 days of sending
- Monthly for stable ongoing campaigns
- Immediately after major drops in opens or reply patterns
- Immediately after provider warnings, bounce spikes, or DNS edits

At OutboundPros we also re-audit when clients change list vendors, add a new sending tool, or ask to scale volume quickly. Those are common moments when hidden risk enters the system.

If you run only a few mailboxes, a monthly audit is usually enough if performance is stable. If you operate multiple domains across several campaigns, check core health weekly. It does not need to be a big production. A 20-minute review of DNS status, bounce trends, mailbox spread, and tool settings can save weeks of damage.

The operator mindset is simple: deliverability is not a one-time setup task. It is ongoing maintenance. The teams that treat it that way keep inboxing longer.

Frequently Asked Questions

How long does a cold email deliverability audit take?

A basic audit takes 30 to 60 minutes because most of the work is checking domains, DNS, mailbox metrics, and sending settings systematically.

A deeper audit across multiple domains, tools, and campaigns can take 2 to 4 hours, especially if you need to trace bounce causes or compare mailbox-level performance.

Can I send cold email from my main company domain?

You can, but it is usually a bad risk decision because outbound issues can affect the domain your team uses for real customer and partner communication.

Most serious operators use adjacent domains or controlled subdomains for cold outreach and keep the core brand domain protected.

What is a safe hard bounce rate for cold email?

A safe hard bounce rate is generally under 3% because higher bounce levels signal poor data quality or risky sending.

If you are consistently above that, pause the source, reverify the list, and inspect catch-all handling before sending more volume.

Should I turn off open and click tracking?

Tracking should be used only when it helps more than it hurts because every extra layer can affect deliverability.

Open tracking is sometimes acceptable if the setup is clean, but click tracking is often unnecessary for cold email. If inboxing is unstable, simpler usually performs better.

How many emails should one mailbox send per day?

A common working range is 20 to 35 cold emails per mailbox per day because that is usually sustainable once the mailbox is warmed and healthy.

Some setups can go above that, but there is no universal safe number. Domain quality, provider, targeting, and campaign behavior all matter.

What is the first thing to fix if deliverability drops suddenly?

The first thing to fix is the technical and mailbox layer because sudden drops usually come from infrastructure changes, reputation damage, or bad data hitting the system.

Check DNS, bounce spikes, mailbox-level performance, recent tool changes, and volume increases before rewriting your sequence.