Warming a sending domain: the reputation you can't buy back
This update was drafted on a schedule by the AI I build with, from real project notes — part of the vibecoding experiment this blog documents.
Let me pick up a thread I left loose. I've written about why my outreach bot can draft but never send — the human-approval gate, the refusal to auto-fire cold email. Part of that argument was that volume quietly kills cold email and that a sending domain is a reputation asset you can burn without noticing. I said it in one line and moved on. This is me going back for the mechanics of that line, because they're the part that actually changed how I think about it.
Here's the thing I didn't understand at first. I thought of a sending domain the way I think of a server — a resource I own, that does what I tell it. It isn't. It's a reputation, held by companies I don't control, that I can only ever spend down. Gmail and Outlook keep a running opinion of the domain you send from. You don't get to see the score. You can't log in and read it. You can only infer it from where your mail lands — inbox, promotions, spam, or nowhere — and by the time you can infer it's bad, it's already bad. That's the "silently" part. There's no error. The message says "sent." It just quietly goes to a folder nobody opens, for everybody, from then on.
So before you send anything, there's table stakes, and it's three acronyms that I resented having to learn. SPF, DKIM, DMARC. In plain terms: SPF is a list, published in your DNS, of which servers are allowed to send mail as your domain. DKIM is a cryptographic signature on each message that proves it really came from you and wasn't altered. DMARC is the policy that ties the two together and tells the receiving server what to do when a message fails — and, the useful bit, where to send you reports about who's sending as you. None of these make your email good. They make it legible. Without them you're an anonymous stranger, and anonymous strangers go to spam by default now. With them you're at least a known entity whose reputation can be tracked — which is the privilege of getting to build a reputation at all, good or bad.
That's the setup. The part people skip is the warmup, and skipping it is how the burn happens.
A brand-new domain has no reputation, and "no reputation" is treated a lot like "bad reputation," because spammers love fresh domains — they burn one, register another, repeat. So a new domain that suddenly sends a big batch of cold mail looks exactly like the thing the filters are built to stop. You've told on yourself on day one. Warming is the opposite move: you start tiny, you send to people who actually open and reply, and you let the volume climb slowly while the inbox providers build up a picture of you as something people want to hear from. Engagement is the signal that matters — opens, replies, mail getting dragged out of spam into the inbox. Not volume. Volume without engagement is just the spammer pattern at a slower frame rate.
I'm deliberately not going to print a "send X on day one, Y by week three" schedule, because I'd be making the numbers up and the real answer is that it depends on the domain, the provider mix, and how warm your list already is. TODO: if I ever run a long enough real warmup through Cadence to have honest numbers, they go here — until then the shape is the lesson, not a ramp table I invented.
But the shape is the lesson. And once you see the shape, two things fall out that change the whole posture.
The first is that warmup is slow and burning is fast, and that asymmetry is the entire game. It takes weeks of patient, engaged sending to build a domain the providers trust. It takes about one bad batch to undo it — a big blast to a cold, scraped list where half the addresses bounce and nobody replies, and the score craters. You cannot sprint the warmup and you cannot un-crater the reputation on demand. There's no "buy it back." You'd start over on a new domain, from zero, weeks behind. A reputation you can only ever lose quickly and rebuild slowly is a reputation you protect like it's irreplaceable, because operationally it nearly is.
The second thing — and this is where it loops back to the outreach bot — is a trick I only half-appreciated until I understood the warmup. You don't warm up and protect the domain you actually live in. The sending domain is a separate thing from your real one. If you're sending real outreach, you do it from a dedicated domain — often a close variant of your main one — specifically so that if it burns, the fire is contained. Your primary domain, the one your actual business email and your customers' trust live on, never touches cold send volume. Because if that burns, it's not a cold-email problem anymore. It's your invoices going to spam. Your password resets. Your reply to a warm lead who reached out to you. The blast radius of a burned domain is the thing you're really managing, and the move is to make sure the thing that can burn is never the thing you can't afford to lose.
Which is, honestly, the same instinct as the approval gate, just one layer down. The gate is me not trusting a machine to decide who gets sent to. The sending-domain split is me not trusting the channel to stay clean no matter how careful I am — so I isolate it, keep the volume low and engaged, and treat the whole apparatus as something I'm renting from Gmail's opinion of me, not something I own. You don't own your sending reputation. You're a tenant. And the rent is: don't be the thing the filters were built to catch.