Cold Email Domain Setup Checklist
Introduction
A cold email domain is ready to send when it is registered to you, separate from your primary domain, forwarding to your main website, verified in Google Workspace, and passing SPF, DKIM, and DMARC with MX pointing to Google. On top of that it needs a small number of mailboxes with complete profiles, a few weeks of warmup, and a clean handoff to your sequencer. Skip a step and the domain usually still sends; it just sends worse, and you find out weeks later.
Use this as a working checklist for each new domain. Copy it into your tracker and mark each step done per domain.
Phase 1: Plan
Size first. Work out daily total sends, a conservative cap per mailbox, and mailboxes per domain. Common operator practice is two or three mailboxes per domain and roughly 20 to 40 cold sends per mailbox per day once warmed. That gives you the number of domains to buy, plus 10 to 20 percent spare. See How Many Mailboxes Per Domain for Cold Email.
Keep the primary domain out. Cold email never runs on the domain your customers, invoices, and hiring mail depend on. See Primary Domain Isolation for Cold Email.
Decide on separation. Agencies: one pool of domains per client. Multi brand teams: one pool per brand. Never mix two clients on one domain.
Phase 2: Choose and register the domain
Pick names close to your brand. Variations such as getyourbrand, yourbrandhq, or tryyourbrand on a common extension read as legitimate. Avoid hyphens, strings of digits, and anything that imitates another company's brand.
Register to an account you control. If a provider buys domains for you, confirm whose account they sit in and how you would move them later.
Turn on auto renew. An expired sending domain breaks authentication and loses the history you built.
Log it. Domain, registrar, renewal date, client or brand, purpose.
Phase 3: Make the domain look real
Forward the domain to your main website. Anyone who types the domain should land on your real site, not a parking page.
Remove parking page records. Leftover MX or A records from the registrar's default setup cause confusion later.
Phase 4: Add it to Google Workspace
Add the domain to your Workspace organization (as a secondary domain or its own organization, depending on how you separate clients).
Verify ownership with the TXT record Google gives you, then complete verification in the Admin console.
Google's help pages are the source of truth for every step below, and they change over time. Check them before you copy a value.
Phase 5: DNS and authentication
MX. Google's current guidance for new setups is a single MX record pointing to smtp.google.com with priority 1. Remove any other MX records. Google notes the change can take up to 72 hours to be recognized. Older setups may still use legacy values that start with aspmx; Google still supports those.
SPF. One TXT record at the root:
v=spf1 include:_spf.google.com ~all
This is the value in Google's SPF help. Only one SPF record per domain; a second record breaks SPF checks. Add other includes only if another service truly sends from this domain.
DKIM. In the Admin console, go to Menu, Apps, Google Workspace, Gmail, Authenticate email (Google's DKIM help). Generate a key (2048 bit if your DNS provider supports it), publish the TXT record at the host shown (usually google._domainkey), wait for DNS to update, then click Start authentication. In a brand new organization, Google says you may need to wait 24 to 72 hours before you can generate the key, and authentication can take up to 48 hours to start working. Publishing without starting is a common DKIM miss.
DMARC. One TXT record at _dmarc:
v=DMARC1; p=none; rua=mailto:dmarc@yourbrand.com
Start at p=none, as Google's DMARC help recommends, and add the record only after SPF and DKIM have been authenticating for at least 48 hours. Reports can be high volume, so Google suggests a dedicated mailbox or group rather than a personal address. Make sure someone reviews them.
Custom tracking domain (only if you track links). Your sequencer documents a CNAME to add, so tracked links use your domain instead of a shared one. Follow the exact host and target from its help docs.
Full detail and common mistakes: SPF DKIM DMARC Setup for Cold Email.
Phase 6: Verify
DNS lookup. One SPF record, DKIM resolving at the right host, DMARC at _dmarc, MX pointing to Google.
Test send. From a new mailbox to a personal Gmail address, open "Show original," and confirm SPF PASS, DKIM PASS, DMARC PASS. Repeat to an Outlook address.
Blocklist check. Run the new domain through a public blocklist lookup. A previously owned domain can carry history.
Google's sender guidelines require SPF or DKIM from everyone sending to Gmail accounts, and all three from senders above 5,000 messages a day. Do not start warmup until all three checks pass.
Phase 7: Create the mailboxes
Two or three mailboxes with real sounding names that match how your team signs emails.
Complete the profile. Display name, profile photo, and a plain signature.
Enforce 2FA from the Admin console, and store credentials in a password manager your team controls.
Prepare the connection method your sequencer documents: sign in with Google (OAuth), or IMAP and SMTP with app passwords. App passwords require 2 Step Verification on the account, and Google recommends Sign in with Google wherever the tool offers it.
Phase 8: Warm up
Start warmup on each mailbox only after authentication passes.
Wait a few weeks before campaign volume, then ramp slowly. Common operator practice is two to three weeks of warmup, then roughly 10 to 20 cold sends per mailbox per day before moving toward the steady state.
Use one warmup approach per mailbox (your sequencer's feature or a separate add on) and record which. See Inbox Warmup Setup on Google Workspace.
Phase 9: Hand off to the sequencer
Connect mailboxes using the method your sequencer supports.
Set conservative per mailbox limits and a sending window that matches your prospects' time zone.
Rotate across domains, not just mailboxes. Thirty mailboxes on three domains still share three domain reputations.
Add an easy opt out to every sequence.
Phase 10: Monitor
Weekly review per domain: human replies, bounces, complaints, mailbox connection status.
Postmaster Tools for domains sending meaningful volume to Gmail users (Google Postmaster Tools).
Recheck DNS after any change to records or tools.
One page tracker columns
| Column | Example value |
|---|---|
| Domain | tryyourbrand.com |
| Client or brand | Client A |
| Registrar and renewal date | Your registrar, renewal month |
| Forwarding | yourbrand.com |
| MX / SPF / DKIM / DMARC | Pass / Pass / Pass / Pass |
| Mailboxes | 3 |
| Warmup start | Date |
| Campaign start | Date |
| Status | Warming, live, resting |
Doing this for many domains
Ten phases for one domain is manageable. For twenty domains it is hundreds of steps, and one typo in a DKIM record can quietly weaken a slice of a campaign. Teams usually choose between a strict spreadsheet process, scripting DNS through a registrar API, or infrastructure that does the repetitive parts automatically.
Where ColdMail fits
ColdMail automates the middle of this checklist. It provisions official Google Workspace mailboxes on dedicated domains, either yours or ones you buy through ColdMail, and publishes SPF, DKIM, DMARC, and MX automatically. You keep an official admin panel per domain with 2FA, so every record and account stays visible, and provider health indicators for Gmail, Outlook, and Yahoo support the monitoring phase. AI warmup is available as an optional add on; see coldmail.app for current add on pricing.
ColdMail is not a sequencer. Mailboxes are ready to connect in Instantly and Smartlead using the methods those tools support, and they work with n8n and other tools.
Get started at coldmail.app, or Book a Strategy Call to plan domains for your volume.