Home › Blog

SendGrid Warm Up: Domain, SMTP and IP Setup

By BobWork05 Oct 202611 min read
SendGrid domain warm-up workflow with DNS authentication, SMTP API key and daily sending ramp

For SendGrid warm up, authenticate the sending domain first, then start around 10–20 real outbound emails per day unless your SendGrid limits are lower. If you skip DNS alignment or jump volume, Gmail, Yahoo and Outlook can treat the sender as unknown or risky. This guide gives the records, SMTP setup, warm-up schedule and monitoring checks.

SendGrid can send high volume, but it does not create reputation for you. A new domain, subdomain or dedicated IP still needs predictable sending before heavier campaigns. If you need mailbox-level placement data, pair SendGrid with a receiving inbox and BobWork Email Warm-up, which supports SendGrid SMTP credentials plus an IMAP inbox.

This guide assumes you send from a domain or subdomain through SendGrid. It covers transactional-style sending and cautious outbound patterns. It does not replace SendGrid’s current plan limits, policy rules, suppression settings or compliance requirements.

What must be set first?

Start with domain authentication. Do not warm up an unauthenticated SendGrid sender unless you are only testing inside your own team. Authentication tells mailbox providers that SendGrid is allowed to send for your domain.

In SendGrid, go to Settings → Sender Authentication → Authenticate Your Domain. SendGrid asks for your DNS host, domain and automated security preference. The usual setup creates CNAME records for DKIM and return-path alignment. Use the exact hostnames and values shown inside your account.

SendGrid’s primary source is the Twilio SendGrid domain authentication documentation. Use that over any blog post if the interface changes.

You should also have SPF and DMARC on the sending domain. With SendGrid domain authentication, SendGrid normally handles the SPF alignment it needs through the generated DNS records. Your domain can still use SPF for other services, but keep only one SPF TXT record per domain.

DMARC should exist before you ramp. Many teams start warm-up with p=none so they can monitor authentication results without rejecting legitimate mail. Tighten the policy later, after you know every valid sender for the domain.

Use a subdomain if your main domain reputation matters. For example, send from mail.example.com or news.example.com, not the root domain. Keep the visible From address, authenticated domain and reply handling consistent.

ItemTypical valueWhere to set itHow to verify
DKIMSendGrid CNAME recordsDNS hostSendGrid shows the domain as verified
Return-pathSendGrid CNAME recordDNS hostSendGrid shows the authenticated domain
SPFOne TXT record per domainDNS hostSPF check passes for your senders
DMARCStart with p=none for monitoringDNS hostDMARC checker finds the record
Existing domain warm-up14+ daysSending planSpam placement stays low
New domain warm-up3–4 weeksSending planVolume rises without spikes
Google complaint targetUnder 0.1%, never 0.3%+Postmaster monitoringComplaint rate stays below threshold
Campaign warm-up level10–15/dayWarm-up toolBackground traffic stays steady
Real outreach ceilingTypically 30–50/day/mailboxSending planReplies, bounces and spam stay stable

For DNS checks, use our SPF checker, DKIM checker and DMARC checker. Check the exact domain or subdomain used in the visible From address.

Which SMTP settings does SendGrid use?

SendGrid SMTP uses an API key, not your account password. This is a common setup mistake.

Go to Settings → API Keys → Create API Key. Give the key a clear name, such as warmup-sendgrid-domain or outbound-mailer. Grant the smallest permissions your sending setup needs. For SMTP sending, Mail Send is the core permission.

Use these SMTP values:

SMTP settingValue
Hostsmtp.sendgrid.net
Usernameapikey
PasswordYour SendGrid API key value
Common port587 with TLS
Other ports465 for SSL, 25 where allowed
From domainYour authenticated SendGrid domain
Reply addressA real mailbox you monitor

SendGrid documents this in its SMTP API key guide. The username is literally apikey. Do not use your SendGrid account email address as the SMTP username.

Store the API key when you create it. SendGrid will not show the full value again. If you lose it, create a new key and revoke the old one.

Do not share one API key across every product, environment and domain. Separate keys make revocation safer. They also help you identify which system caused a volume spike, bounce issue or policy problem.

Before warm-up, send a few internal test emails. Open the full headers in Gmail, Yahoo or another mailbox. SPF, DKIM and DMARC should pass. The visible From domain should match the domain you plan to build reputation for.

What are you warming?

SendGrid warm-up can mean domain warm-up, IP warm-up or mailbox-level warm-up. Keep them separate or you will optimize the wrong layer.

Domain warm-up builds reputation for the domain or subdomain in your From address. Mailbox providers watch whether recipients accept, ignore, delete, report or reply to mail from that identity.

IP warm-up applies when you use a dedicated IP address. You increase traffic through that IP gradually so receiving providers see a predictable sending pattern.

Mailbox-level warm-up uses real receiving inboxes to send, receive, reply and detect spam placement. It is common in cold outbound because it measures inbox behavior directly.

SendGrid’s automated IP warm-up is for dedicated IPs. It controls traffic sent through the dedicated IP according to SendGrid’s system. Read the current SendGrid IP warm-up documentation before enabling it.

If you use shared IPs, you usually cannot warm the IP yourself. You can still warm the domain by sending low, steady, wanted mail with correct authentication.

Do not assume a dedicated IP is safer. A dedicated IP starts with little or no reputation. If your volume is low or inconsistent, a shared IP can sometimes be easier. If your volume is high and stable, a dedicated IP gives more control.

Warm-up layerApplies toControlled inWhat it provesMain risk
DomainDomain or subdomainYour sending plan and DNSThe domain sends wanted mailVolume spikes damage reputation
Dedicated IPSendGrid dedicated IPSendGrid IP settingsThe IP can carry growing volumeToo much volume too early
Mailbox levelReal inboxesWarm-up tool and IMAP inboxReceiving inboxes accept and replyFake-looking traffic or poor setup
ContentMessage templatesYour app or campaign toolRecipients engage with messagesLinks, images and spam-like copy
List qualityRecipient dataCRM or databaseAddresses are valid and relevantBounces and complaints

For the mailbox side, read what an email warm-up network does. Inbox placement data is different from a platform’s sending allowance.

What sendgrid warm up schedule is safe?

Use a boring ramp. Mailbox providers should see a sender that behaves predictably.

For a new domain, plan 3–4 weeks. For an existing domain with good sending history, use at least 14 days. If the domain has previous spam issues, treat it like a new reputation and move slower.

This starting schedule is for one SendGrid sending domain. Adjust downward if your SendGrid plan, policy or account limits are lower. Increase only after delivery is stable, bounces stay low and complaints do not rise.

Day rangeReal outbound/dayWarm-up traffic/dayWhat to sendMove on when
1–310–203–7Internal tests and safe contactsAuthentication passes
4–720–307–15Recent opt-ins or known contactsEngagement looks normal
8–1430–5010–15Small segmented campaignsBounces and spam stay low
15–2150–8010–15Wider targeted sendsComplaints do not climb
22–2880–12010–15Normal low-volume campaignsMetrics remain stable
After 28Check current limits10–15Scale by mailbox or segmentProvider signals stay healthy

These numbers are cautious outbound guidance, not SendGrid’s maximum technical capacity. SendGrid may allow more sending than your domain reputation can safely handle. Reputation usually fails before the platform limit.

Send more only when the previous step is clean. If bounces rise, fix the list. If complaints rise, fix targeting and consent. If spam placement rises, pause or step back.

Do not send the same template to every recipient. Avoid link-heavy first emails, image-only messages, URL shorteners and misleading subjects. Plain text or simple HTML is safer while you establish reputation.

Send during business hours for the audience where possible. Spread messages across the day. A sharp batch looks less natural than steady office-hour sending.

Which signals should you watch?

There are two kinds of limits.

The first is SendGrid’s account, plan, rate and policy limit. Check your SendGrid account and current SendGrid documentation. Do not rely on a number copied from an old article.

The second is reputation capacity. This is not shown as one number. You infer it from bounces, blocks, spam placement, replies, unsubscribes and complaints.

Google’s sender guidance says to keep spam complaint rates below 0.1% and avoid reaching 0.3%. Use the current Google email sender guidelines as a primary source, especially if you send to Gmail or Google Workspace users.

Watch these signals daily during warm-up:

SignalHealthy patternWarning patternWhat to do
SPF/DKIM/DMARCPassingAny fail or alignment issueFix DNS before scaling
Hard bouncesRareRepeated invalid addressesStop that list source
BlocksNone or isolatedSame provider blockingPause that segment
ComplaintsBelow provider thresholdsAny visible climbReduce volume and improve targeting
Spam placementLow and fallingAbove 5% in warm-upPause for a few days
RepliesSome natural repliesNone across many sendsRecheck targeting and copy
VolumeGradualSudden jumpReturn to the prior level

Keep SendGrid suppression handling active for bounces, blocks, spam reports and unsubscribes unless you have a specific reason and understand the consequence.

Warm-up cannot repair a bad list. If recipients did not expect your message, the domain will show it eventually. Authentication helps providers identify you. It does not make unwanted mail wanted.

If you send from multiple domains, warm each one separately. Reputation does not fully transfer. If you add a new subdomain, treat it as a new sender until it proves otherwise.

How does mailbox warm-up work?

SendGrid is a sending platform. It is not usually the receiving inbox where warm-up replies land. For mailbox-level warm-up, you need SendGrid SMTP for sending and a real inbox that can receive over IMAP.

This differs from Gmail or Zoho warm-up. With Gmail, the mailbox can send and receive. With SendGrid, the sending side is SendGrid SMTP. The receiving side is usually Google Workspace, Zoho, Yahoo, iCloud, Lark or another IMAP provider.

BobWork Email Warm-up supports this setup: SendGrid SMTP credentials for sending plus the receiving inbox over IMAP. The free pool starts at 3 emails/day, adds 2 per day and caps at 30/day unless you edit the cap. It uses a shared warm-up network by default, or a private pool per account if you prefer.

Keep the receiving mailbox real. It should receive prospect replies and system messages. Its reply-to behavior should match your campaign setup.

BobWork only touches warm-up mail carrying the engine’s hidden header, or a known warm-up subject for specific provider routes. Real mail is not read, moved or answered. Warm-up mail found in Spam is moved to Inbox, marked read, labelled Warm-up and archived after 24 hours.

You still need to read campaign replies yourself. A warm-up tool does not handle objections, unsubscribes or support messages.

For the exact BobWork ramp, read the engine strategy. For a broader daily plan, use the email warm-up schedule guide.

Do this now

Use this checklist before you send more than a small test batch. Each step depends on the one before it.

StepActionHow to verify
1Choose the exact sending domain or subdomainThe From address uses that domain
2Authenticate the domain in SendGridSendGrid shows the domain as verified
3Add or confirm SPF, DKIM and DMARCDNS checks return pass or found
4Create a SendGrid API keyYou can send through smtp.sendgrid.net
5Use apikey as SMTP usernameTest mail sends successfully
6Send internal tests firstHeaders show SPF, DKIM and DMARC pass
7Decide shared or dedicated IPSendGrid account shows your IP setup
8If dedicated, review IP warm-upSendGrid IP warm-up settings are understood
9Start real outbound at low volumeFirst days stay around 10–20/day
10Add mailbox-level warm-up if neededReplies and spam placement are visible
11Monitor bounces and complaints dailySuppression and provider dashboards stay clean
12Pause when spam placement risesVolume returns only after recovery

Do not skip verification. The worst warm-up plan is one that sends for a week before anyone checks headers.

If DNS is not passing, fix DNS. If the list is bouncing, fix the list. If recipients complain, fix targeting. Sending more will not solve those problems.

A safe SendGrid domain warm-up has a simple shape: authenticated domain, valid SMTP key, small daily sends, no sudden jumps and daily monitoring. The hard part is resisting the urge to scale as soon as the first test works.

If you also run cold outreach from normal mailboxes, compare this with Gmail warm-up, Zoho warm-up or Amazon SES warm-up. The setup changes by provider, but the reputation logic is similar.

For SendGrid, keep warm-up traffic and campaign traffic consistent. Do not warm one domain and switch to another for the actual campaign. Do not authenticate one domain and send from a different visible From identity.

If a mailbox or sender crosses a 5% warm-up spam rate, pause it for a few days. Resume at a lower level after placement improves. If a domain repeatedly lands in spam, check DNS, list source, content and prior reputation before blaming SendGrid.

When you are ready to add mailbox-level warm-up, connect SendGrid SMTP and a receiving IMAP inbox in the free warm-up tool. It is free, needs no credit card, supports up to 20 mailboxes per account, and can use the shared warm-up network or a private pool per account. Keep the ramp steady, then scale by adding clean sending identities instead of forcing one domain too hard.

Frequently asked questions

Can I warm up a SendGrid domain without a dedicated IP?

Yes, but you are warming the sending domain and sending pattern, not a dedicated IP. Shared IP reputation is controlled by SendGrid and other senders. A dedicated IP gives you more control, but it also gives you more responsibility.

What SMTP username does SendGrid use?

Use apikey as the SMTP username. Use the actual SendGrid API key value as the password. The SMTP host is smtp.sendgrid.net, usually on port 587 with TLS.

Does SendGrid IP warm-up replace mailbox warm-up?

No. SendGrid IP warm-up manages traffic on a dedicated IP. Mailbox-level warm-up tests whether receiving inboxes place your messages in Inbox or Spam. They measure different parts of deliverability.

How long should SendGrid warm-up take?

For an existing domain, plan at least 14 days before heavier outbound. For a new domain, use 3–4 weeks. Increase volume slowly and pause if spam placement, bounces or complaints rise.

Can I send cold outreach from SendGrid?

SendGrid can send SMTP email, but you still need consent, suppression handling, unsubscribe handling and safe volume. Check SendGrid’s current policies and your local rules before using any platform for outreach.

Why are my authenticated SendGrid emails still going to spam?

Authentication proves identity. It does not guarantee inbox placement. Content, complaint rate, bounces, list quality, domain age, volume spikes and previous reputation can still push mail to Spam.

Do I need a real inbox for warm-up?

Yes, if you want mailbox-level warm-up. SendGrid is a sending platform. You need a receiving mailbox over IMAP so warm-up replies, spam placement and inbox recovery can be measured.

Warm up your mailboxes free

Connect Gmail, Google Workspace, Zoho or Lark. Your mailboxes warm on a shared network, or in a private pool of your own, starting today.

Start free