Deliverability
Cold Email Deliverability Checklist: 18 Pre-Send Checks for 2026
A practical pre-send checklist for authentication, sender identity, list quality, copy, unsubscribe handling, complaint risk, and post-send monitoring.
A cold email is ready to send only when the sender, audience, message, opt-out process, and monitoring plan all pass review. Authentication alone cannot make irrelevant outreach safe, and polished copy cannot rescue broken authentication. Use this 18-point checklist as a launch gate, then test a small segment before increasing volume.
Start by running the draft through the AI Cold Email Deliverability Checker. Use the Email Authentication Analyzer as a domain-setup checklist, then verify live DNS records and received-message results with the relevant providers.
The 18-point cold email deliverability checklist
| Area | Check | Pass condition |
|---|---|---|
| Identity | From address | Recognizable, monitored, and able to receive replies |
| Authentication | SPF | Sending service is authorized and the record passes |
| Authentication | DKIM | Outgoing mail carries a valid DKIM signature |
| Authentication | DMARC | A policy and reporting address are published |
| Alignment | From domain | Aligns with SPF or DKIM for DMARC |
| Infrastructure | DNS | Sending domain and IP have valid forward and reverse DNS where applicable |
| Transport | TLS | Sending service uses encrypted transport |
| Audience | Source | Every address has a documented, lawful source |
| Audience | Verification | Invalid, role-risk, and stale addresses are reviewed |
| Relevance | Trigger | The message names a real reason for contact now |
| Copy | Subject | Accurate, specific, and free from false thread signals |
| Copy | Body | Scannable, concrete, and built around one problem |
| Copy | CTA | One low-friction next step |
| Compliance | Identity | Sender and commercial purpose are not disguised |
| Compliance | Opt-out | Visible and easy to act on |
| Operations | Suppression | Bounces, opt-outs, and objections stop future sends |
| Risk | Complaint budget | Planned volume is checked against a strict complaint target |
| Monitoring | Feedback | Reputation, authentication, bounces, and complaints have owners |
Gate 1: prove the sender is real
The first six checks establish identity. Gmail requires all senders to use SPF or DKIM and requires senders above its bulk threshold to use SPF, DKIM, and DMARC. Microsoft applies SPF, DKIM, and DMARC requirements to high-volume senders reaching Outlook consumer domains. Yahoo also expects authentication and a low complaint rate.
Do not stop at seeing a DNS record. Send a real test message and inspect the authentication results in the received message. A record can exist while the message still fails because the sending service, selector, alignment, or forwarding path is wrong.
For a plain-language explanation, read SPF, DKIM, and DMARC for sales teams and compare the result with the cold email deliverability benchmarks.
Gate 2: prove the audience is defensible
List quality is not a one-time cleaning task. It is the connection between the source of an address, the reason for contact, and the likelihood that the recipient will recognize the message as relevant.
Before launch:
- record where each contact came from
- remove obvious invalid and duplicated addresses
- separate corporate addresses from personal, sole-trader, or individual-subscriber addresses where local law treats them differently
- suppress previous bounces, opt-outs, objections, and negative replies
- keep the first segment narrow enough to diagnose
A verified address is not permission, and a public address is not automatically fair game. Verification reduces bounce risk; it does not replace targeting or legal review.
Gate 3: make the message easy to trust or decline
The safest first-touch draft gives the recipient three answers quickly: why me, why now, and what happens if I reply. It does not create false familiarity or hide behind broad claims.
Use this copy check:
- one observable signal, not a generic compliment
- one plausible problem, not a list of capabilities
- one mechanism or proof point, not an unsupported superlative
- one CTA, usually a reply question
- one clear way to opt out
The Cold Email Roast is useful when a draft sounds polished but interchangeable. The AI cold email patterns guide shows the phrases and structures that most often need rewriting.
Gate 4: calculate complaint exposure before volume
Google recommends keeping Postmaster Tools spam rate below 0.1% and avoiding 0.3% or higher. That makes the complaint budget small: at 5,000 Gmail recipients, 0.1% represents five complaints.
Run the audience mix through the Email Complaint Rate Calculator. If the campaign cannot survive a handful of negative reactions, narrow the list, improve the message, and test at lower volume.
Do not use opens as the main safety signal. Google says it does not track open rate and cannot verify third-party open-rate accuracy. Replies, bounces, opt-outs, complaints, and provider reputation dashboards are more actionable.
Gate 5: assign a post-send owner
The checklist does not end at launch. Someone must review the first segment and decide whether to pause, change, or scale.
The owner should monitor:
- authentication failures
- hard and soft bounces
- spam complaints and provider reputation
- opt-outs and negative replies
- repeated copy issues by segment
- sudden changes in sending volume or format
If a signal deteriorates, pause expansion. A slower campaign is cheaper than a damaged sending identity.
What should you check before sending a cold email campaign?
Check SPF, DKIM, DMARC, alignment, DNS, TLS, address source, verification, relevance, subject accuracy, body specificity, CTA count, sender identity, opt-out handling, suppression, complaint exposure, and monitoring ownership. Then send a small diagnostic segment and expand only when the real feedback remains healthy.
Can a deliverability checklist guarantee inbox placement?
No. Inbox placement depends on history, reputation, recipient behavior, infrastructure, content, and provider-specific filtering. A checklist reduces avoidable risk and exposes unknowns; it cannot guarantee where every mailbox provider will place a message.
Sources and next step
This checklist is grounded in Google's email sender guidelines, Yahoo Sender Hub best practices, and Microsoft's high-volume sender requirements.
Copy the 18 checks into your launch review, then test the actual draft with the Folderly deliverability checker.
Folderly Research
Deliverability and cold email strategy team
Folderly Research studies cold email quality, sender reputation, and deliverability patterns across outbound workflows so teams can ship sharper messages without guessing.
Next step
Check the draft before the campaign goes live.
Run copy, AI-template, compliance, complaint-budget, and sender setup guidance in the public Folderly checker.