Warm Up Google Workspace Email on a New Domain
Warm up Google Workspace email on a new domain for 3–4 weeks before serious outreach. If you send before SPF, DKIM, DMARC, and mailbox behaviour look normal, Gmail may treat the domain as untrusted. This guide shows the Admin console paths, DNS records, Postmaster Tools checks, and a safe ramp.
If you want a day-by-day plan while you set up the domain, use the free email warm-up schedule generator. For broader timing by mailbox age, read the new mailbox warm-up timeline. This guide is specific to Google Workspace on a new domain.
What should be ready first?
Google does not judge one message alone. It looks at your domain, mailbox history, authentication, sending pattern, complaints, and recipient engagement.
A new domain has little sending history. That does not mean every message goes to spam. It means your first weeks carry more weight. Sudden volume, missing DKIM, weak lists, and poor replies can create a bad pattern quickly.
Set up the basics before you send campaigns:
- Use Google Workspace users, not forwarding-only addresses.
- Create one mailbox per sender.
- Use real sender names, such as
maya@yourdomain.com. - Avoid early outreach from role accounts such as
sales1@orinfo@. - Add a normal profile photo if your team uses one.
- Start with plain, relevant messages.
- Keep early sending consistent across working days.
Google publishes sender requirements for bulk senders. The complaint-rate number matters most: keep spam complaints under 0.1%, and never reach 0.3%. You can monitor this in Google Postmaster Tools once the domain has enough mail volume for data.
Authentication comes before warm-up. Warm-up can build a normal sending pattern, but it cannot make an unsigned domain trustworthy. Set SPF, DKIM, and DMARC first, then let mailbox activity grow gradually.
If your emails already land in spam, fix the cause before adding volume. Check authentication, content, list quality, and recent sending spikes. The broader guide to why emails go to spam covers those causes.
How do you warm up Google Workspace email?
A Google Workspace warm-up should create believable mailbox activity: sends, receives, replies, and inbox placement checks over time.
For a new domain, use 3–4 weeks. An established domain can often move faster, but a new domain needs more patience. Your goal is not the highest possible daily limit. Your goal is stable behaviour before the mailbox carries business outreach.
A useful warm-up pattern has five parts:
- Low starting volume.
- Slow daily increases.
- Replies on some messages.
- Spam-folder rescue for warm-up mail only.
- Authentication and reputation monitoring.
BobWork Email Warm-up runs a shared network by default, with a private-pool switch per account. The free pool handles the activity automatically: plain-text office-style messages, some replies, and rescue only for its own warm-up messages that land in Spam.
One mailbox is enough on the shared network. For a private pool you need at least two: two users on the same domain, or one new Google Workspace mailbox paired with another mailbox you control. Peers on another domain or provider are useful because all activity should not look internal.
Warm every mailbox that will send outreach. If five people will send campaigns, do not warm one shared mailbox and assume the others inherit its pattern. Each sender builds mailbox-level history.
How do you connect it?
You can connect Google Workspace to a warm-up tool in two practical ways: Google sign-in or IMAP with an app password. Do not plan around normal password-based Gmail login. Google’s older less-secure app access is no longer the route.
Option 1: use Google sign-in. In BobWork Email Warm-up, Google sign-in requests the gmail.modify scope. The tool needs that scope to send warm-up mail, detect its own messages, move its own warm-up mail from Spam to Inbox, label it, mark it read, and archive it after 24 hours.
Google may show an unverified-app notice because BobWork has not completed the CASA audit. If your organisation blocks unverified apps, use the IMAP route where policy allows it, or wait until your policy changes.
BobWork does not read, move, or answer real mail. It only touches mail carrying the engine’s own hidden header. For Zoho API senders, it uses a known subject instead.
Option 2: use IMAP with an app password. First, check whether IMAP is allowed for the user.
In Google Admin, go to:
Apps → Google Workspace → Gmail → End User Access
Review the organisation’s POP and IMAP settings. Google’s labels can change, so search Admin console for IMAP if you do not see the same wording.
Then open Gmail for the mailbox:
Settings → See all settings → Forwarding and POP/IMAP → IMAP access
Enable IMAP if the admin policy allows it.
For app passwords, Google generally requires 2-Step Verification. Create the app password in Google Account security settings, then use it only for the IMAP connection. If your Workspace admin blocks app passwords, use Google sign-in instead.
Set the mailbox time zone correctly. BobWork sends between 09:00 and 18:00 in the mailbox’s own time zone, with decisions every 15 minutes and randomness. That avoids a robotic midnight sending pattern.
For more context on the model, read what an email warm-up network does. For the exact BobWork ramp and reply behaviour, see the warm-up strategy page.
Which DNS records matter?
Google Workspace needs SPF, DKIM, and DMARC on your sending domain. Add them before warm-up, not after the first spam problem.
DNS changes can take time to propagate. Many providers publish records within minutes, but caches can keep old answers longer. Check from outside your DNS host before assuming a record is live.
| Record | Host/name | Value to publish | Why it matters | How to check |
|---|---|---|---|---|
| SPF | @ or root domain | v=spf1 include:_spf.google.com ~all | Authorises Google to send mail for your domain | Use the SPF checker |
| DKIM | Usually google._domainkey | TXT value generated in Google Admin | Signs mail so receivers can verify it was not altered | Use the DKIM checker |
| DMARC | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com | Tells receivers how to handle mail that fails authentication | Use the DMARC checker |
Use Google’s own setup pages as the primary source: Google SPF documentation, Google DKIM documentation, and Google DMARC documentation.
Add SPF. In your DNS host, create one TXT record at the root domain:
v=spf1 include:_spf.google.com ~all
Do not create multiple SPF TXT records on the same domain. If you also send through another platform, merge the includes into one SPF record. Multiple SPF records can fail SPF validation.
SPF also has a 10-DNS-lookup limit. If you use many sending tools, the record can break even when the text looks valid.
Enable DKIM. In Google Admin, go to:
Apps → Google Workspace → Gmail → Authenticate email
Select the domain, generate the DKIM record, and publish the TXT value in DNS. Google commonly uses the selector google, which creates a host like google._domainkey.yourdomain.com.
After DNS propagates, return to the same Admin console screen and start authentication. Publishing the DNS record is not enough. Google must also sign outgoing mail.
Use a 2048-bit key where available. If your DNS provider struggles with long TXT values, follow Google’s instructions for splitting the record.
Publish DMARC. Start with a monitoring policy:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
This lets you receive reports without rejecting mail while you configure the domain. Later, after legitimate sources pass SPF or DKIM alignment, you can move toward a stricter policy.
Do not start a brand-new Google Workspace domain with an aggressive DMARC policy unless every sender is verified. You can reject your own valid mail if another platform is not aligned.
What ramp should you use?
New domains need a slower ramp than established domains. The table below follows the BobWork engine pattern and the sending practice we publish.
BobWork starts at 3 emails per day, adds 2 per day, and caps at 30 per day by default. The cap is editable per mailbox, up to 100. For a new Google Workspace domain, do not chase high warm-up volume early. Weekends run at 30%.
| Period | Warm-up volume per mailbox | Real outreach | What to watch | Action if spam rises |
|---|---|---|---|---|
| Days 1–3 | 3, 5, 7 per day | 0 | SPF, DKIM, DMARC pass; messages send normally | Stop and fix DNS or login errors |
| Days 4–7 | 9–15 per day | 0–5 personal emails only | Spam placement, replies, normal inbox activity | Hold volume for several days |
| Week 2 | 15–30 per day | 5–15 targeted emails | Postmaster Tools, bounces, replies | Pause mailbox above 5% warm-up spam rate |
| Week 3 | 20–30 per day | 15–30 careful outreach emails | Complaint risk, bounce patterns, content quality | Reduce outreach before warm-up |
| Week 4 | 10–30 per day | 30–50 outreach emails max | Stable placement and low complaints | Add mailboxes, not more volume |
| During campaigns | 10–15 per day | 30–50 per day typical range | Replies, complaints, bounce rate, Postmaster Tools | Pause or cut volume quickly |
The real outreach column is conservative. It is a typical safe range, not a Google guarantee. Google Workspace has account-level sending limits, but deliverability can fail before a new-domain sender reaches formal limits.
Keep threads natural. BobWork warm-up mail uses plain text, no links, no images, and first-name greetings. About 40% of received warm-up mail gets a reply, and threads end after three messages.
Do not send a large cold campaign on day five because the mailbox can technically send. Technical sending and inbox placement are different problems.
If a sender’s 7-day warm-up spam rate goes above 5%, pause that mailbox for a few days. BobWork defines spam rate as the share of that sender’s warm-up mail found in Spam by receiving mailboxes over seven days. This is direct mailbox measurement, not a third-party seed-list estimate.
What breaks warm-up fastest?
Most Google Workspace warm-up problems come from configuration, identity, or volume. Fix those before testing more copy.
DKIM is published but inactive. You added the TXT record in DNS, but did not return to Google Admin to start authentication. Go back to Apps → Google Workspace → Gmail → Authenticate email, then confirm DKIM is active. Send a test message to Gmail and check that DKIM passes in message details.
IMAP is blocked by policy. If IMAP login fails, do not keep retrying the same credentials. Check Apps → Google Workspace → Gmail → End User Access. If your organisation blocks IMAP or app passwords, use Google sign-in instead.
App passwords are unavailable. App passwords usually depend on 2-Step Verification and admin policy. If the option is missing, check both. Do not enable broad legacy access. Less-secure app access is not the modern Google Workspace route.
Aliases send too early. Warm the actual user mailbox first. If alex@yourdomain.com will send outreach, warm alex@yourdomain.com. Do not warm info@ and assume every salesperson inherits that pattern.
One mailbox sends for everyone. A single mailbox carrying all outreach creates a sharp behaviour pattern. Use one mailbox per sender and keep daily volume modest. After warm-up, a typical range is 30–50 real outreach emails per mailbox per day.
Links arrive too soon. New domains that immediately send tracked links, images, shortened URLs, attachments, and sales-heavy copy often create negative signals. Start with clean text, relevant targeting, and one clear reason to reply.
Postmaster Tools has no data. This is normal at low volume. Add and verify the domain anyway, then check again as volume grows. When data appears, watch complaint rate first. Stay under 0.1%, and never above 0.3%.
If placement is already poor, use the focused guide on fixing Google Workspace emails going to spam before increasing volume.
When are you ready?
BobWork marks a mailbox ready for outbound when it has warmed for at least 14 days, has a 7-day warm-up spam rate of 3% or lower, and has received at least 30 warm-up emails.
For a new domain, waiting closer to 3–4 weeks is safer. Use the first 14 days to establish authentication and mailbox behaviour. Use the next 1–2 weeks to introduce small, targeted outreach.
Keep warm-up running during campaigns at 10–15 emails per day per mailbox. Its job is to keep normal activity flowing while real replies and low complaints do the heavier reputation work.
Before increasing volume, check these signals:
- SPF, DKIM, and DMARC pass.
- Warm-up spam rate stays low.
- Google Postmaster Tools does not show complaint problems.
- Bounce rates are not climbing.
- Replies are genuine, not only automated responses.
- No mailbox is blocked or failing login.
Use this checklist in order. Do not start the ramp until DNS and Admin console checks pass.
| Step | Action | How to verify |
|---|---|---|
| 1 | Create individual Google Workspace users with real names | Each sender has a mailbox, display name, and login |
| 2 | Add SPF for Google | The SPF checker returns include:_spf.google.com on one SPF record |
| 3 | Generate DKIM in Google Admin | Admin path shows the domain under Gmail authentication |
| 4 | Publish the DKIM TXT record | The DKIM checker finds the google selector |
| 5 | Start DKIM authentication | A Gmail test message shows DKIM pass in message details |
| 6 | Publish DMARC at _dmarc | The DMARC checker finds a valid policy |
| 7 | Add the domain to Postmaster Tools | Google Postmaster Tools shows the domain as verified |
| 8 | Allow the connection route | Google sign-in works, or IMAP and app passwords are allowed by policy |
| 9 | Connect the mailbox | Warm-up can send and receive |
| 10 | Start the 3–4 week ramp | Daily warm-up volume increases gradually without login errors |
| 11 | Watch 7-day spam rate | Pause any mailbox above 5% warm-up spam rate |
| 12 | Start outreach slowly | Real outreach stays within a typical 30–50 per day per mailbox |
Keep a short log during the first month. Record DNS changes, warm-up start date, campaign start date, bounce issues, and any spam-rate spikes. When something changes, you can trace the cause faster.
If you need more daily outreach, add another mailbox and warm it. Do not push one new Google Workspace mailbox to carry a whole campaign.
You can start with BobWork Email Warm-up for free, with no credit card and no time limit. It supports Gmail and Google Workspace through Google sign-in or IMAP with an app password, allows up to 20 mailboxes per account, and lets you keep warm-up inside a private pool of your own mailboxes if you prefer that to the shared network. Outlook is not supported yet.
Frequently asked questions
How long should I warm up Google Workspace on a new domain?
Use 3–4 weeks for a new domain. Start at a few warm-up emails per day, increase gradually, and avoid real cold outreach until the mailbox has at least 14 days of warm-up, low spam placement, and enough received warm-up mail.
Does Google Workspace need DKIM before warm-up?
Yes. Set DKIM before meaningful warm-up. In Google Admin, go to Apps → Google Workspace → Gmail → Authenticate email, generate the DKIM record, publish it in DNS, then start authentication. Also publish SPF and DMARC.
Can I still use less secure apps with Gmail?
No. Google has removed less-secure app access. Use Google sign-in where available, or use IMAP with an app password when your account policy allows it. Do not use a normal Google password for IMAP.
What Google Postmaster Tools number matters most?
Keep spam complaint rate under 0.1% and never above 0.3%. Postmaster Tools also helps you watch domain reputation, IP reputation where applicable, authentication, encryption, and delivery errors.
How many cold emails can I send per Google Workspace mailbox?
A typical safe range is 30–50 real outreach emails per mailbox per day after warm-up. Keep warm-up running at 10–15 per day during campaigns, and add more mailboxes instead of pushing one mailbox too hard.
Should every user mailbox use a real name?
Yes. Use per-user mailboxes with real names, consistent profiles, and normal signatures. Avoid sending cold outreach from aliases, shared inboxes, or role accounts until the domain and mailbox reputation are stable.
Why are Google Workspace emails still going to spam after warm-up?
Common causes include missing DKIM, a weak DMARC setup, a new domain, poor list quality, high bounce rates, aggressive sending, spammy copy, or complaint rates above Google’s thresholds. Warm-up helps reputation, but it cannot fix bad targeting.
Warm this mailbox up for free
Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.