How to Run a Cold Email Deliverability Audit
On this page
Why Audit Your Deliverability
Cold email deliverability degrades silently. You send emails, see no bounce notifications and assume everything is working. Meanwhile, your emails are landing in spam folders, your domain reputation is dropping and your response rate is declining for reasons that have nothing to do with your copy.
A deliverability audit catches problems before they become severe. Run one quarterly, or immediately when you notice:
- Response rates dropping below your baseline.
- Bounce rates rising above 2%.
- A sudden drop in open rates.
- Recipients telling you they found your email in spam.
- A new domain or IP address that has not been warmed up.
The Audit Checklist
1. DNS Authentication Records
DNS authentication is the foundation. Without proper SPF, DKIM and DMARC records, mailbox providers have no way to verify that you are who you claim to be.
SPF (Sender Policy Framework)
SPF tells receiving servers which IP addresses are authorised to send email for your domain.
Check your SPF record:
dig TXT yourdomain.com | grep "v=spf1"
| What to check | Pass | Fail |
|---|---|---|
| SPF record exists | Record returned | No record found |
| Includes your sending service | Your ESP's include is present | ESP not listed |
| Does not exceed 10 DNS lookups | 10 or fewer | More than 10 (causes permerror) |
| Ends with -all or ~all | Explicit fail or soft fail | ?all or missing qualifier |
| No duplicate SPF records | One v=spf1 record | Multiple records (causes failure) |
DKIM (DomainKeys Identified Mail)
DKIM adds a cryptographic signature to your emails, proving they were not modified in transit.
Check your DKIM record:
dig TXT selector._domainkey.yourdomain.com
(Replace "selector" with your ESP's DKIM selector, which your ESP provides.)
| What to check | Pass | Fail |
|---|---|---|
| DKIM record exists | Record returned with public key | No record found |
| Key length is 2048-bit | k=rsa with 2048-bit key | 1024-bit key (weaker, some providers flag) |
| Signature aligns with From domain | d= matches or is subdomain of From | d= is a different domain |
DMARC (Domain-based Message Authentication, Reporting and Conformance)
DMARC tells receiving servers what to do when SPF or DKIM checks fail, and where to send reports.
Check your DMARC record:
dig TXT _dmarc.yourdomain.com
| What to check | Pass | Fail |
|---|---|---|
| DMARC record exists | Record returned | No record found |
| Policy is not p=none (for production) | p=quarantine or p=reject | p=none (monitoring only, no enforcement) |
| Reporting address is set | rua= is present and valid | No rua= tag |
| Alignment mode is appropriate | adkim=s and aspf=s (strict) or r (relaxed) | Missing alignment tags |
Starting fresh: If you are setting up a new domain, start with p=none and a reporting address. Monitor reports for 2-4 weeks to confirm legitimate email passes authentication before moving to p=quarantine and eventually p=reject.
2. Domain Reputation
Your domain reputation is how mailbox providers (Gmail, Outlook, Yahoo) perceive your sending history.
Google Postmaster Tools
If you send to Gmail addresses, register your domain at Google Postmaster Tools. It shows:
| Metric | Healthy | Problem |
|---|---|---|
| Domain reputation | High or Medium | Low or Bad |
| Spam rate | Below 0.1% | Above 0.3% |
| Authentication | SPF, DKIM, DMARC all passing | Any failing |
| Encryption | TLS on all connections | Some unencrypted |
Microsoft SNDS (Smart Network Data Services)
For Outlook/Hotmail deliverability, register at Microsoft SNDS to see how Microsoft perceives your sending IPs.
Blacklist checks
Check your domain and sending IP addresses against major blacklists:
| Blacklist | Impact | How to check |
|---|---|---|
| Spamhaus | Very high (used by most major providers) | Check at check.spamhaus.org |
| Barracuda | High (used by many corporate filters) | Check at barracudacentral.org |
| SORBS | Medium | Check at sorbs.net |
| SpamCop | Medium | Check at spamcop.net |
| URIBL | High (checks domains in email body) | Check at uribl.com |
If you are listed on any blacklist, follow the blacklist's delisting procedure. Being listed on Spamhaus is particularly severe and should be addressed immediately.
3. Sending Infrastructure
Sending domains
| What to check | Recommendation |
|---|---|
| Main domain vs subdomain | Use a subdomain for cold email (e.g., outreach.yourdomain.com) to protect your main domain's reputation |
| Domain age | At least 30 days old, preferably 90+; new domains have no reputation |
| Domain warm-up status | Gradually increase volume over 2-4 weeks for new domains |
| Number of sending domains | Rotate across 3-5 domains to distribute volume |
Sending volume
| What to check | Recommendation |
|---|---|
| Daily volume per domain | 30-50 emails per domain per day for cold outreach |
| Volume consistency | Avoid spikes; keep daily volume within 20% of your average |
| Warm-up progression | Start at 5-10 per day, increase by 5-10 per day each week |
| Weekend volume | Reduce or pause; large weekend sends look automated |
Email accounts
| What to check | Recommendation |
|---|---|
| Emails per account per day | 20-30 for cold outreach |
| Number of accounts per domain | 2-3 accounts per domain |
| Account age | At least 14 days with normal activity before cold sending |
| Account warm-up | Send and receive normal emails for 2 weeks before cold outreach |
4. Email Content
Content issues are often overlooked in deliverability audits because they are harder to measure than technical settings.
Subject lines
| What to check | Pass | Fail |
|---|---|---|
| Length | Under 60 characters | Over 60 characters (truncated on mobile) |
| Spam trigger words | No spam triggers | Contains "free", "guaranteed", "act now", "limited time" |
| ALL CAPS | No all-caps words | Subject contains all-caps words |
| Excessive punctuation | Normal punctuation | Multiple exclamation marks or question marks |
| Personalisation | Contains recipient's name or company | Generic, no personalisation |
Body content
| What to check | Pass | Fail |
|---|---|---|
| Text-to-HTML ratio | Mostly text with minimal HTML | Heavy HTML with images and formatting |
| Link count | 1-2 links | More than 3 links |
| Link domains | Links to your own domain | Links to shortened URLs, tracking domains or unrelated sites |
| Image count | 0-1 images | Multiple images or image-heavy layout |
| Unsubscribe mechanism | Clear unsubscribe link or reply-to-unsubscribe | No unsubscribe option |
| Tracking pixels | Single, well-known tracking pixel | Multiple tracking pixels |
| Footer | Physical address and company name | Missing required CAN-SPAM elements |
Spam score testing
Send test emails through a spam testing service before launching a campaign. These services analyse your email against common spam filters and return a score with specific issues to fix.
5. Email List Quality
A clean list is the single most impactful factor in cold email deliverability.
List composition
| What to check | Healthy | Problem |
|---|---|---|
| Bounce rate | Below 2% | Above 5% |
| Role-based addresses (info@, sales@) | Below 5% of list | Above 10% |
| Disposable addresses | Below 1% | Above 3% |
| Catch-all domains | Identified and handled separately | Treated the same as verified addresses |
| Duplicate addresses | None | Present (indicates poor list hygiene) |
List freshness
| What to check | Recommendation |
|---|---|
| Last verification date | Verified within the last 30 days |
| List age | Addresses collected within the last 6 months |
| Source tracking | Every address has a recorded source |
| Suppression list applied | Unsubscribes, bounces and complaints removed |
Building clean lists from extraction
When building prospect lists from extracted email addresses, the extraction step collects addresses but does not verify them. After extracting emails with Email Extractor:
- Download the deduplicated results as CSV.
- Run the list through an email verification service to remove invalid addresses.
- Remove role-based addresses (info@, admin@, support@) unless specifically targeting them.
- Check for disposable email domains.
- Apply your suppression list to remove any previously unsubscribed or bounced addresses.
6. Engagement Metrics
Track these metrics over rolling 30-day windows:
| Metric | Healthy | Warning | Critical |
|---|---|---|---|
| Open rate | Above 40% | 20-40% | Below 20% |
| Reply rate | Above 5% | 2-5% | Below 2% |
| Bounce rate | Below 2% | 2-5% | Above 5% |
| Spam complaint rate | Below 0.1% | 0.1-0.3% | Above 0.3% |
| Unsubscribe rate | Below 1% | 1-2% | Above 2% |
If any metric is in the critical range, pause sending and investigate before continuing. Continuing to send with critical metrics accelerates reputation damage.
The Audit Report
Document your findings in a structured format:
Domain: yourdomain.com
Audit date: YYYY-MM-DD
DNS Authentication:
SPF: [PASS/FAIL] - [details]
DKIM: [PASS/FAIL] - [details]
DMARC: [PASS/FAIL] - [details]
Domain Reputation:
Google Postmaster: [High/Medium/Low/Bad]
Blacklists: [Clean/Listed on X]
Spam rate: [X%]
Infrastructure:
Sending domains: [list]
Daily volume: [X per domain]
Warm-up status: [Complete/In progress/Not started]
List Quality:
Total addresses: [X]
Verified: [X%]
Last verified: [date]
Bounce rate: [X%]
Engagement (30-day):
Open rate: [X%]
Reply rate: [X%]
Complaint rate: [X%]
Issues Found:
1. [Issue and recommended fix]
2. [Issue and recommended fix]
Priority Actions:
1. [Highest priority fix]
2. [Second priority fix]
Audit Frequency
| Situation | Frequency |
|---|---|
| Established sending domain with stable metrics | Quarterly |
| New domain or recently warmed domain | Monthly |
| After a blacklisting event | Immediately, then weekly until resolved |
| After a significant drop in open/reply rates | Immediately |
| After adding a large batch of new addresses | Before the next send |
| After changing ESP or sending infrastructure | Before resuming sends |