Home › Fixes

New Domain Emails Going to Spam: A 28-Day Fix

By BobWorkUpdated 2026-10-0311 min read
28-day plan for fixing new domain emails going to spam

A new domain usually needs 28 days of clean authentication, low volume and gradual engagement before cold email stops landing in spam. If you send bursts before the domain has history, filters learn the wrong pattern. This guide gives you the diagnosis table, DNS records, warm-up rules, pause points and proof checks to fix it.

Start by separating the causes. A new domain can fail because it has no reputation, but it can also fail because SPF, DKIM, DMARC, content or list quality is wrong. Use the broader email spam causes guide if older domains are also affected.

What failed first?

Do not start by rewriting every email. First prove whether the problem is technical, behavioural or reputation-based.

Send three plain-text tests from the new mailbox: one to Gmail, one to Outlook or Microsoft 365, and one to another provider. Use no links, no signature images and no attachments.

Open the received message headers. Check SPF, DKIM and DMARC results. Also record where the message landed: Inbox, Promotions, Junk or Spam.

SymptomLikely cause5-minute checkFix
Email goes to spam everywhereBroken authenticationCheck SPF, DKIM and DMARC in headersPublish correct DNS records and wait for propagation
Gmail accepts but spam-places mailNew domain, low history or complaintsCheck Gmail Postmaster Tools if data existsWarm gradually; keep spam complaints under 0.1%, never 0.3%
Outlook junk placement onlyMicrosoft filtering or reputationSend plain text with no links to Microsoft inboxesReduce links, authenticate and check Microsoft guidance
Mail is rejectedDNS, policy or blocklist issueRead the SMTP bounce codeFix the exact rejection before sending again
Replies work, campaigns failList or campaign content issueCompare one-to-one mail with campaign mailClean lists and remove tracking-heavy content
One secondary domain failsDomain-specific reputationCompare headers and DNS across domainsPause the weak domain and rebuild slowly
Spam rate rises after a burstVolume spikeCheck sends per mailbox over 72 hoursPause or return to the last safe volume

Fix in this order: authentication, identity, volume, content, recipients, then warm-up.

Why are new domain emails going to spam?

New domains have no positive sending history. Mailbox providers have not seen consistent human replies, low complaint behaviour or stable authentication from that domain.

Domain age alone does not solve this. A six-month-old unused domain can still behave like a new sender. What matters is recent, authenticated mail that recipients accept and interact with.

Burst volume is the common mistake. You register a domain on Monday, connect mailboxes on Tuesday and send hundreds of cold emails on Wednesday. That pattern looks disposable.

Secondary domains add another risk. They protect your main business domain, which is sensible for cold outreach. But a secondary domain starts with its own reputation. It does not inherit trust from your main domain.

Keep secondary domains recognisable. Use a clear variation, not a deceptive lookalike. Add a simple website or redirect, real sender names and matching company details. If recipients feel tricked, complaints rise.

Content can make a new domain fail faster. Heavy link tracking, URL shorteners, image-only signatures, attachments and overused sales phrases give filters more reasons to distrust a sender with no history.

Recipient quality matters as much as volume. Old scraped lists, role accounts and unverified addresses create bounces and complaints. New domains have little reputation buffer, so mistakes show quickly.

Are the DNS records correct?

Authentication is the first fix because it is binary. You either pass, fail or create alignment problems. Warm-up cannot compensate for broken DNS.

Use provider values from your admin console. Do not copy records from another domain. SPF, DKIM and DMARC are domain-specific, and some records include unique selectors or tokens.

RecordDNS host/nameWhat it doesHow to verify
SPFUsually @Authorises sending serversSPF passes in received headers
DKIMProvider selector, such as google._domainkeySigns each messageDKIM passes with the expected selector
DMARC_dmarcTells receivers how to handle alignment failuresDMARC is visible and aligned mail passes

SPF

SPF is a TXT record at the root domain, often shown as @ in DNS.

Common patterns look like this:

ProviderDNS host/nameExample value patternCheck
Google Workspace@v=spf1 include:_spf.google.com ~allSPF passes in message headers
Microsoft 365@v=spf1 include:spf.protection.outlook.com ~allSPF passes in Microsoft and Gmail headers
Zoho Mail@v=spf1 include:zohomail.com ~allZoho send passes SPF
SendGrid@ or subdomainUse the value shown in SendGridAuthenticated domain shows verified
MailgunDomain or subdomainUse the value shown in MailgunDomain verification passes
Amazon SESDomain or MAIL FROM domainUse SES-provided TXT/MX recordsSES identity shows verified

Use one SPF record per domain. Do not create two TXT records starting with v=spf1. Merge includes into one record.

Use the free SPF checker after saving. DNS may take minutes or hours to propagate, depending on your TTL and provider.

DKIM

DKIM signs each message and ties it to your domain. It is usually a TXT or CNAME record at a selector host.

Common selectors include google, zmail, default, selector1, selector2, k1, s1, mail, dkim, lark, feishu and zoho.

Do not guess the selector. Open your provider admin panel and copy the exact host and value.

For Google Workspace, go to Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generate the DKIM record, add it in DNS, then return and start authentication. Google’s email sender guidelines explain its authentication expectations.

Use the free DKIM checker to confirm the selector is visible.

DMARC

DMARC tells receivers what to do when SPF or DKIM alignment fails. For a new domain, start with monitoring before enforcement.

Create this TXT record:

FieldValue
Host/name_dmarc
TypeTXT
Starter valuev=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; pct=100

Replace the reporting address with a real mailbox or reporting service address. Make sure it exists.

A p=none policy does not tell receivers to quarantine or reject. It lets you collect reports while you confirm alignment. After stable authentication, you can move to stricter policies if your business needs them.

Yahoo also publishes sender requirements covering authentication, low complaints and easy unsubscribe for bulk senders. Use the free DMARC checker before campaigns.

What is the 28-day plan?

For a new domain, use 3–4 weeks. Four weeks is safer if you plan cold outreach. You are teaching filters that this domain sends normal, authenticated mail to real inboxes.

This is not permission to send unlimited messages after day 28. It is a controlled ramp to a modest daily baseline.

DaysWarm-up volumeReal emailsWhat to sendStop condition
1–33–7/day0–5/dayInternal, partner or known-contact mailAny authentication failure
4–79–15/day5–10/dayPlain text, no tracking-heavy templatesSpam placement across multiple providers
8–1417–30/day10–20/daySmall batches to verified recipientsWarm-up spam rate above 5%
15–2130/day20–30/dayLimited outbound testsComplaints or rising bounces
22–2830/day30–50/dayStable campaign patternRejections, blocklists or domain-level junking
After 2810–15/day during campaigns30–50/dayKeep volume steadySustained deterioration

Those warm-up numbers match a conservative ramp: start at 3 emails per day, add 2 per day, and cap at 30 per day. Weekends should be lighter. A 30% weekend schedule is safer than seven identical sending days.

Do not jump from 20 real emails to 200. Add mailboxes instead of forcing one mailbox to carry all volume. Most cold outreach programmes work better when each mailbox stays modest.

If you use Gmail or Google Workspace, follow a provider-specific setup before ramping. The Gmail warm-up guide covers mailbox connection and authentication checks.

For more detail on timing, use the day-by-day warm-up timeline. The short version: existing domains may need about 14 days, but new domains should get 3–4 weeks.

When does warm-up help?

Warm-up helps when the domain is technically correct but has little positive history. It creates low-volume, normal-looking conversations before you ask the domain to carry campaigns.

It can also help after a pause, if the original cause is fixed. If you sent too fast in week one, stop, reduce volume and rebuild gradually.

Warm-up is not a repair tool for broken infrastructure. It will not fix duplicate SPF records, unsigned DKIM, DMARC alignment failures, bad lists, misleading content, malware, phishing-like pages or blocklisted sending infrastructure.

A useful warm-up pattern has these traits:

SignalGood patternBad pattern
AuthenticationSPF, DKIM and DMARC passOne or more fail
VolumeGradual daily increaseSudden campaign burst
TimingSpread through business hoursAll sent in one short window
ContentPlain text, normal office languageLinks, images and sales-heavy copy
RepliesSome natural repliesOne-way only
RecipientsReal, varied providersSame inboxes only
RecoveryOnly identified warm-up mail is movedReal mail is moved or altered

BobWork Email Warm-up runs a shared network by default, with a private-pool switch per account. The free pool does this step automatically: it starts at 3 emails per day, adds 2 per day, caps at 30 by default, spreads sends between 09:00 and 18:00 in each mailbox’s time zone, and replies to about 40% of warm-up mail. One mailbox is enough; a private pool needs two.

The private-pool option is useful for secondary domains because strangers do not receive your addresses. It also means you need enough of your own mailboxes to create movement.

BobWork supports Gmail and Google Workspace, Zoho Mail, Lark Mail, Yahoo Mail, iCloud Mail, Amazon SES, SendGrid, Mailgun and generic IMAP plus SMTP. Outlook and Microsoft 365 are not supported yet because Microsoft requires OAuth.

When should you pause?

Pausing is not failure. It prevents filters from learning more bad signals.

Pause the mailbox or domain when any of these happen:

TriggerWhy it mattersWhat to do
SPF, DKIM or DMARC failsAuthentication failure damages trustStop sending until headers pass
Warm-up spam rate exceeds 5%Inbox placement is deterioratingPause for a few days, then restart lower
Hard bounces rise sharplyList quality is poorClean the list and remove risky sources
Complaint rate approaches 0.3%Google says stay under 0.1% and avoid 0.3%Stop campaign traffic and review targeting
A major blacklist lists the domainFiltering may spread across providersCheck evidence, fix the cause, request delisting if appropriate
Rejections mention policy or abuseThe receiver is not just filteringRead the code and correct the stated issue
Replies say “not relevant” oftenTargeting is wrongNarrow the audience and rewrite the offer

Use the free blacklist checker if delivery changes suddenly. A listing is not always the cause, but it is fast to rule out.

Microsoft’s anti-spam guidance is useful when Outlook or Microsoft 365 is the main problem. Look for policy rejections, not only junk placement.

Do not resume at the old volume. Restart below the last stable point. If 30 real emails per day caused trouble, restart at 10–15 and hold for several days.

What should you do now?

Work fastest to slowest. You can complete the first five checks in under an hour if you have DNS access.

StepActionHow to verify
1Send a plain-text test to Gmail, Outlook and another providerCheck placement and authentication results
2Fix SPF so there is one valid recordSPF shows pass in headers and in the checker
3Enable DKIM in your mail providerDKIM shows pass with the expected selector
4Add DMARC at _dmarcDMARC is visible and aligned mail passes
5Remove risky contentTest email has no short links, images, attachments or heavy tracking
6Check recent volume per mailboxNo new mailbox jumped into campaign-level sending
7Verify the recipient listInvalid, role-based and unverified addresses are removed
8Start or restart warm-upVolume begins low and increases gradually
9Keep weekends lighterWeekend sending is reduced
10Pause above the danger lineMailbox stops if spam rate exceeds 5% or authentication fails
11Add mailboxes instead of volumeEach mailbox stays around 30–50 real emails per day
12Review after 28 daysSpam rate, bounces, replies and complaints are stable

If a step fails, do not skip it. A new domain needs clean basics more than clever copy.

How do you prove recovery?

You need proof from several angles. One inbox test is not enough, and a single reply does not prove healthy deliverability.

First, inspect headers again. SPF, DKIM and DMARC should pass on mail received by Gmail, Microsoft and another provider. Alignment should match the visible sending domain or the provider-approved sending domain.

Second, monitor placement over seven days. A mailbox can look fine on Tuesday and degrade by Friday after a campaign. Use a rolling view, not one test.

Third, compare warm-up spam rate with campaign results. BobWork defines spam rate as the share of a sender’s warm-up mail found in Spam by receiving mailboxes over seven days. That direct mailbox measurement is more useful than guessing from opens.

Fourth, confirm campaign behaviour. Bounces should be low, complaints should stay below provider danger levels, and replies should not be mostly negative. Google’s published guidance says to keep spam complaint rates under 0.1% and avoid ever reaching 0.3%.

Fifth, look for stability before scaling. In BobWork, a mailbox is ready for outbound after 14 or more days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. For a new domain, still use the full 3–4 week plan before meaningful cold volume.

Finally, scale sideways. If you need more sends, add properly configured mailboxes and domains. Do not turn one new mailbox into a high-volume sender.

You can run the 28-day plan manually, but it is easy to send too much too soon. BobWork Email Warm-up is free, has no credit card and no time limit, and lets you warm up to 20 mailboxes per account in a shared network or a private pool. Use it after DNS is correct, then confirm the numbers before you restart campaigns.

Frequently asked questions

How long do new domain emails go to spam?

Plan for 3–4 weeks before a new domain behaves normally. Some domains recover sooner after SPF, DKIM and DMARC are fixed. Others take longer if you send too fast, use poor lists or receive spam complaints.

Should I use my main domain for cold email?

Usually not. Use a separate, recognisable secondary domain for outbound campaigns. Keep your main domain for normal business mail. Do not use deceptive lookalike domains, and configure SPF, DKIM and DMARC before sending.

Can warm-up fix a missing DKIM record?

No. Warm-up cannot repair broken authentication. Fix SPF, DKIM and DMARC first, then warm the mailbox. If authentication fails, mailbox providers have a strong reason to filter or reject your mail.

What sending volume is safe on a new domain?

Start with manual-looking volume, typically 5–10 real emails per mailbox per day, then increase slowly. Keep real outreach at or below 30–50 per mailbox per day once the domain is stable.

When should I pause a new mailbox?

Pause if warm-up spam rate rises above 5% for a few days, authentication breaks, the domain appears on a major blacklist, or complaints rise. Fix the cause before you resume sending.

Do I need SPF, DKIM and DMARC for low volume?

Yes. SPF and DKIM authenticate the sender, and DMARC tells receivers how to evaluate alignment. Google and Yahoo publish sender requirements that include authentication, especially for bulk senders.

Does a new domain need a website?

It helps. A simple real website, matching company identity and working contact page make the domain look less disposable. It does not replace authentication, list quality or a controlled sending schedule.

Records fixed? Rebuild the reputation

Warm-up is the part you cannot do by hand for two weeks. The free pool sends, replies and rescues from Spam for you.

Start free