Deliverability for founders: warmup, bounce-pause, and SPF/DKIM/DMARC
Cold email lands in spam for boring, fixable reasons: unauthenticated domains, cold mailboxes sending too fast, and bounce rates that torch your reputation. Here's the founder's version of deliverability — what actually protects your domain, and what Overwise enforces by default so you can't shoot yourself in the foot.
Deliverability is the least glamorous part of outbound and the part that decides whether any of it works. You can write the perfect email to the perfect lead and it doesn’t matter if it lands in spam. This is the founder’s version — not a 40-point checklist, but the handful of things that actually move the needle, and what a trust-first tool should enforce so you don’t learn these the expensive way.
Why cold email lands in spam
Mailbox providers — Gmail, Outlook, and the rest — decide whether to deliver, filter, or bounce your email based mostly on reputation: is this domain and this sending IP trustworthy, and are the recipients engaging or complaining? Reputation is easy to lose and slow to rebuild. Three things wreck it fastest:
- Unauthenticated mail. If your domain doesn’t publish the right DNS records, providers can’t verify the mail is really from you — and unverified mail gets filtered or dropped.
- A cold mailbox sending at volume. A brand-new mailbox that suddenly sends 200 emails on day one looks exactly like a compromised account. Providers throttle or spam-folder it.
- Bounces and complaints. Emailing dead addresses (hard bounces) and getting “mark as spam” clicks tells providers your list is bad and your intent is worse. A bounce spike can tank a domain in a day.
Everything below is about not doing those three things.
SPF, DKIM, DMARC — the three records that authenticate you
These are DNS records that let a receiving server verify your mail is legitimately from your domain. In plain terms:
- SPF (Sender Policy Framework) lists which servers are allowed to send mail for your domain. A receiver checks the sending server against your SPF record.
- DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to each message; the receiver verifies it against a public key in your DNS. It proves the message wasn’t tampered with and really came from your domain.
- DMARC (Domain-based Message Authentication) ties SPF and DKIM together and tells receivers what to do when a message fails: nothing, quarantine, or reject. It also gives you reports.
If these three aren’t set up correctly, your deliverability has a ceiling no copy can raise. This is why Overwise checks SPF/DKIM/DMARC before it will send from a domain and blocks sending from a broken one. It’s not a nag — a domain sending unauthenticated mail is a domain burning its own reputation, and we’d rather stop you than watch it happen under your name.
Warmup: earn volume, don’t demand it
A new mailbox has no reputation. Sending hard from a cold mailbox is the single most common way founders torch a domain in week one. The fix is warmup: start slow, ramp gradually, and let engagement build a track record before you scale.
Overwise forces this. For the first several days of a new mailbox’s life, sends are capped conservatively and the first sends are pushed through review regardless of your campaign settings. You don’t get to override the ramp, because the ramp is the thing protecting the domain you’ll be sending from for years. It’s a week of patience against a reputation you can’t easily buy back.
Review-each-send, by default, for new mailboxes
New mailboxes start in a mode where you approve each send before it goes out. That sounds like it defeats the point of automation, and it does — for a few days. It’s deliberate. The riskiest sends are the first ones, when the AI is newest to your voice and your ICP and the mailbox has no reputation buffer. Review-each-send is the training-wheels period. As trust builds — yours in the tool, the mailbox’s with providers — you move to autopilot with approval gates only where they matter.
Bounce-spike auto-pause
Hard bounces are the fastest reputation killer. If a campaign starts bouncing at an elevated rate — because a source returned stale addresses, or an enrichment miss slipped a bad email through — continuing to send is actively harmful. Overwise monitors bounce rate and automatically pauses a campaign when it spikes, surfacing it as a task for you to look at rather than plowing ahead.
There’s no magic hardcoded percentage we advertise as the line; it’s a monitor, not a fixed threshold, because “too high” depends on volume and history. The principle is simple: the moment sending is hurting more than helping, stop and ask, don’t continue and apologize.
Suppression and unsubscribes are not optional
Two more guardrails that exist at a single chokepoint so they can’t be bypassed:
- Suppression. Once an address should never be contacted — it unsubscribed, it bounced, it complained — it’s suppressed globally, and every send checks the suppression list before going out. One list, one gate, enforced everywhere.
- CAN-SPAM compliance. Every email gets an unsubscribe mechanism injected into the body and a
List-Unsubscribeheader, so recipients can opt out in one click from their mail client. This isn’t only legal hygiene — one-click unsubscribe is far better for your reputation than a frustrated recipient hitting “mark as spam.”
What you actually have to do
Most of the above, Overwise handles or enforces. Your part is short:
- Connect a mailbox via OAuth (Gmail or Outlook) rather than SMTP credentials — it’s safer and providers trust it more.
- Get SPF, DKIM, and DMARC set up on your sending domain. Overwise will tell you if they’re wrong before it sends.
- Let the warmup run. Don’t fight the ramp.
- Keep your ICP tight so bounce rates stay low — precise lead discovery that finds real, current companies is itself a deliverability feature, because fresh, correct addresses don’t bounce.
Deliverability isn’t a growth hack; it’s the foundation everything else sits on. The tool’s job is to make the safe path the default path — so the worst outcome of a busy week is fewer sends, never a burned domain. If that’s the posture you want protecting your outbound, the 14-day trial runs the same safety defaults from day one.
— Tobias Duelli, founder · [email protected]