How to Warm Up Mailgun Safely
Warm up Mailgun by verifying a sending domain, connecting Mailgun SMTP plus a real receiving inbox, then ramping from 3 to 30 messages per day per mailbox over about 14 days. If you skip the ramp, new-domain mail can hit spam or throttling before campaigns start. This guide gives the DNS, hosts, schedule, checks, and launch gates.
If you want warm-up running while you finish Mailgun setup, use the free warm-up tool. It supports Mailgun through the platform's SMTP credentials for sending, plus a receiving inbox over IMAP. That pairing matters because Mailgun can send, but warm-up also needs inbox placement checks and replies.
Mailgun is often used for transactional email. It can also send cold email when configured carefully. The risk is mixing those two jobs without enough separation. A password reset has different expectations from a sales opener. Use separate subdomains where possible, warm each route, and watch spam placement before increasing volume.
What does Mailgun check first?
Mailgun's first gate is domain verification. You add a sending domain or subdomain in Mailgun, then publish the DNS records it shows. Mailgun checks those records before it trusts the domain for sending.
Use a subdomain unless you have a strong reason not to. For example, use mg.example.com, mail.example.com, or outreach.example.com rather than the root domain. A subdomain keeps Mailgun-specific DNS away from your main website, Google Workspace, Microsoft 365, or other mail systems.
Mailgun also cares about the region you chose. For SMTP sending, use the host that matches your Mailgun region.
| Mailgun region | SMTP host | Typical SMTP username | What to check |
|---|---|---|---|
| US | smtp.mailgun.org | Often postmaster@your-domain | Domain is verified in the US region |
| EU | smtp.eu.mailgun.org | Often postmaster@your-domain | Domain is verified in the EU region |
Copy the SMTP login from Mailgun. Do not assume it is always the same. The default credential is often a postmaster@ address for the sending domain, but the dashboard is the source of truth.
New Mailgun accounts can have low hourly caps. Check Mailgun's current limits before you plan volume. A slow ramp protects the domain and avoids hitting provider-side limits while the account is still new.
For cold email, the other early signal is behaviour. Avoid sudden jumps. Keep links, images, tracking, and attachments out of warm-up. BobWork warm-up mail is plain text, uses first-name greetings, and does not include links or images. That makes the warm-up pattern quieter and easier to interpret.
How do you connect Mailgun?
Mailgun is not an inbox provider. It is the SMTP sending side. Warm-up needs two parts: a sender and a receiver. For Mailgun, BobWork sends through Mailgun SMTP, then checks a real receiving inbox over IMAP.
The receiving inbox must be one you control. It should receive mail normally, expose the spam folder, and allow IMAP access. The warm-up engine then measures whether the sender's messages landed in spam across receiving mailboxes.
BobWork runs a shared network by default; switch the account to Private pool and only mailboxes inside your account write to each other (at least 2 needed). Each account can use up to 20 mailboxes.
| Mailbox or platform | How BobWork connects | Notes |
|---|---|---|
| Mailgun | SMTP credentials for sending plus receiving inbox over IMAP | Use the correct US or EU SMTP host |
| Gmail or Google Workspace | Google sign-in or IMAP with an app password | Google sign-in uses gmail.modify; Google shows an unverified-app notice |
| Zoho Mail | Zoho Mail API with a Self Client code, or IMAP on Mail Lite+ | The Zoho API route works on the free plan |
| Lark Mail | IMAP plus mail-client password | Use the mailbox's own client password |
| Yahoo Mail or iCloud Mail | IMAP plus app password | App passwords are required |
| Any IMAP+SMTP mailbox | IMAP and SMTP credentials | Check your provider's current limits |
For Mailgun, create or copy SMTP credentials from the Mailgun dashboard. Then connect the receiving inbox in BobWork. That inbox lets the tool find spam placements, move warm-up mail back to Inbox, and label it.
The rescue behaviour is limited to warm-up mail. BobWork only touches mail carrying its own hidden header, or a known subject for Zoho API senders. It never reads, moves, or answers real mail.
You can see the detailed ramp logic in the exact engine behaviour. The short version is simple: low start, daily increases, random timing during business hours, and no repeated pair too soon.
Which DNS records must pass?
Mailgun domain verification usually involves SPF and DKIM. You should also publish DMARC, even when Mailgun does not require it for the first send.
Open your Mailgun sending domain and copy the DNS records exactly as shown. Mailgun's own documentation on verifying domains is the primary reference. Your DNS host may call TXT records Text, TXT, or DNS TXT. The value must still match Mailgun.
SPF is a TXT record that authorises Mailgun to send for the domain. Mailgun commonly uses this include:
v=spf1 include:mailgun.org ~all
If the domain already has SPF, do not publish a second SPF record. Merge Mailgun into the existing SPF record. A domain should have one SPF TXT record at that host. For example, if you already authorise Google and now need Mailgun, combine both includes in one record.
DKIM proves Mailgun signed the message for your domain. Mailgun will show the selector and TXT value. The selector may be something like k1, but use the exact selector Mailgun gives you. BobWork checks common DKIM selectors daily, including k1, s1, mail, dkim, default, google, zmail, selector1, selector2, lark, feishu, and zoho.
DMARC is published at _dmarc.your-domain. It tells receivers what policy you want for mail that fails authentication alignment. Start with a monitoring policy if you are unsure:
v=DMARC1; p=none; rua=mailto:dmarc@your-domain
Tighten later when you are confident all legitimate senders are aligned. DMARC is defined in RFC 7489. Google also publishes sender guidance that includes authentication and complaint-rate expectations. For bulk senders, Google says to keep spam complaint rates below 0.1% and avoid ever reaching 0.3%; see Google's email sender guidelines.
Use tools after publishing. Check SPF with the SPF checker, DKIM with the DKIM checker, and DMARC with the DMARC checker. BobWork also checks SPF, DKIM, and DMARC daily per domain and shows the result in the app.
| Record | Host or name | Value to expect | How to verify |
|---|---|---|---|
| SPF | Your Mailgun sending domain | Includes Mailgun, commonly include:mailgun.org | Mailgun verification and SPF checker |
| DKIM | Selector shown by Mailgun, such as k1._domainkey | Long TXT value from Mailgun | Mailgun verification and DKIM checker |
| DMARC | _dmarc on the sending domain | Starts with v=DMARC1 | DMARC checker |
| SMTP host | Mailgun SMTP settings | US: smtp.mailgun.org; EU: smtp.eu.mailgun.org | Successful SMTP login and test send |
Do not warm up until DNS is correct. If SPF or DKIM is missing, receivers have less reason to trust the mail. If DMARC is missing, you lose a useful reporting and policy layer.
What Mailgun warm up schedule works?
The safe Mailgun warm up pattern is controlled growth, not a fixed blast. Start low, spread sends through the workday, and hold volume when spam placement rises.
BobWork's default engine starts at 3 emails per day, adds 2 per day, and caps at 30 per day. Weekends run at 30% of weekday volume. Sends are spread between 09:00 and 18:00 in the mailbox's own time zone, with randomness every 15 minutes.
A pair never writes to each other twice within 3 hours. Peers on a different domain or provider are picked twice as often. About 40% of received warm-up mail gets a reply, and threads end after 3 messages.
| Day range | Warm-up target | Weekend behaviour | What to watch | Action |
|---|---|---|---|---|
| Days 1–3 | 3–7/day | 30% of weekday level | SMTP login, DNS pass, first spam landings | Fix authentication before increasing |
| Days 4–7 | 9–15/day | 30% | 7-day spam trend starts forming | Hold if spam rises quickly |
| Days 8–14 | 17–29/day | 30% | Sender spam rate, replies, Mailgun caps | Keep ramping only if stable |
| Day 15+ | 30/day default cap | 30% | 7-day spam rate and received count | Add real outbound carefully |
| During campaigns | 10–15/day warm-up | 30% | Complaint risk and inbox placement | Keep warm-up active, avoid spikes |
You can set a different cap per mailbox, up to 100. For Mailgun, do not raise it just because the tool allows it. Check Mailgun's current limits and account status first, especially on new accounts with low hourly caps.
For real cold outreach, keep volume conservative. A typical safe working range is 30–50 real outbound emails per mailbox per day, assuming the domain is healthy and replies are normal. Add mailboxes instead of forcing more volume through one sender.
Use the warm-up schedule generator if you need a written plan for a new domain, existing domain, or campaign launch. For a broader timeline, see how long email warm-up takes.
What blocks Mailgun warm-up?
Most Mailgun warm-up problems come from mismatched setup, not from the ramp itself. Fix the base before increasing volume.
The first mistake is using the wrong region host. If your domain is in Mailgun EU, send through smtp.eu.mailgun.org. If it is in the US region, use smtp.mailgun.org. A wrong host or credential can fail authentication, block sending, or make troubleshooting harder.
The second mistake is warming a domain before verification completes. Mailgun may let you configure credentials before every DNS check is green. Receivers still judge the message. SPF, DKIM, and DMARC should be in place before any serious ramp.
The third mistake is publishing two SPF records. This often happens when teams add Mailgun after Google Workspace, Microsoft 365, or another platform. Merge includes into one SPF record. Multiple SPF TXT records at the same host can break SPF evaluation.
The fourth mistake is mixing transactional and cold traffic on one sender. Use separate subdomains where possible. Keep password resets, receipts, product notifications, and cold outreach apart. If cold outreach has a problem, your transactional stream should not inherit that reputation issue.
The fifth mistake is sending campaign mail while warm-up is still unstable. BobWork's spam rate is the share of a sender's warm-up mail that receiving mailboxes found in Spam over the last 7 days. If a mailbox goes above 5%, pause it for a few days and fix the cause.
The sixth mistake is assuming warm-up replaces good sending practice. It does not. You still need relevant copy, low complaint risk, clean recipients, working unsubscribe handling where required, and a sending identity that matches the message.
If your mail keeps landing in spam, use the same diagnostic order every time: DNS, SMTP region, account limits, domain age, content, list quality, then volume. The guide on why emails go to spam walks through those causes in more detail.
What should you do now?
Use this checklist before starting Mailgun warm-up. Do not move to the next step until the verification column passes.
| Step | Action | How to verify |
|---|---|---|
| 1 | Choose a Mailgun sending subdomain, such as mg.example.com or outreach.example.com | The domain appears in Mailgun under your chosen region |
| 2 | Publish Mailgun's SPF TXT record | Mailgun marks SPF verified; SPF checker shows Mailgun included |
| 3 | Publish Mailgun's DKIM TXT record | Mailgun marks DKIM verified; DKIM checker finds the selector |
| 4 | Publish DMARC at _dmarc | DMARC checker returns a valid v=DMARC1 policy |
| 5 | Copy SMTP credentials from Mailgun | Username, password, and host match the Mailgun region |
| 6 | Use smtp.mailgun.org or smtp.eu.mailgun.org correctly | A test SMTP login succeeds |
| 7 | Connect a real receiving inbox over IMAP | The inbox can receive, show spam, and allow warm-up checks |
| 8 | Add the mailbox to BobWork | It shows active and exchanges mail |
| 9 | Start at the default ramp | Day 1 begins at 3 emails per day |
| 10 | Watch 7-day spam rate | Healthy trend stays at or below 3% before outbound |
| 11 | Keep campaign warm-up active | Warm-up stays around 10–15/day during campaigns |
| 12 | Pause if spam rises above 5% | Mailbox is paused while you fix DNS, content, or volume |
Treat the checklist as a launch gate. If one item fails, fix that item instead of increasing volume.
If DKIM is missing, do not compensate by warming longer. Publish the correct DKIM record. If the SMTP login fails, do not rotate passwords blindly. Check the region host, the postmaster@ credential, and whether the account has current sending restrictions.
If DNS passes but spam placement remains high, look at the domain and message. A brand-new domain usually needs a longer ramp than an established domain. Use 3–4 weeks for a new domain. Use at least 14 days for an existing domain.
When is Mailgun ready?
A Mailgun sender is ready for outbound only when the signals agree. Do not rely on one successful test message.
In BobWork, Ready for outbound means 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Health scores are shown from 0 to 100: Healthy is 85 or above, Watch is 60–84, At risk is below 60, and Blocked means the login or permission failed.
Once ready, start real mail below your intended daily volume. Keep warm-up running at 10–15 messages per day during campaigns. If real replies are low, spam placement rises, or Mailgun caps sending, hold volume instead of pushing through.
Cold and transactional traffic should be judged separately. Transactional mail often has expected recipients and clear user intent. Cold mail usually has lower familiarity and higher complaint risk. Separate subdomains make those patterns easier to see.
Before a larger campaign, run one last check: SPF, DKIM, DMARC, Mailgun region host, receiving inbox access, warm-up health, and current Mailgun limits. Then increase in small steps.
BobWork Email Warm-up is free, requires no credit card, and has no time limit. For Mailgun, it uses SMTP credentials for sending and a receiving inbox over IMAP, with up to 20 mailboxes per account, on the shared network or in a private pool. Start with the free warm-up tool when your DNS records are ready.
What else should you know?
How long should Mailgun warm-up take?
Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Move slower if warm-up mail lands in spam, if the domain is new, or if Mailgun applies low hourly caps on a new account.
Which SMTP host should I use?
Use smtp.mailgun.org for the US region and smtp.eu.mailgun.org for the EU region. Match the host to the region where your Mailgun domain is configured. Copy the SMTP username and password from Mailgun rather than typing them from memory.
Can I warm up without an inbox?
No. Mailgun is the sending relay. Warm-up also needs a real inbox that can receive, find spam placements, and reply. With BobWork, Mailgun uses SMTP credentials for sending plus the receiving inbox over IMAP.
What SPF record does Mailgun use?
Mailgun commonly asks for an SPF TXT record that includes include:mailgun.org. Use the exact value shown in your Mailgun domain verification screen. If your domain already has SPF, merge Mailgun into the existing record instead of publishing two SPF records.
Should cold and transactional share?
Usually, separate them. Use different subdomains for cold outreach and transactional mail, such as outreach.example.com and mail.example.com. That keeps reputation, complaint patterns, and troubleshooting clearer.
When can I start outbound?
For BobWork warm-up, a mailbox is ready after 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Keep real outreach low at first and pause if spam rate rises above 5%.
Frequently asked questions
How long should Mailgun warm-up take?
Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Move slower if warm-up mail lands in spam, if the domain is new, or if Mailgun applies low hourly caps on a new account.
Which SMTP host should I use for Mailgun warm-up?
Use smtp.mailgun.org for the US region and smtp.eu.mailgun.org for the EU region. Match the host to the region where your Mailgun domain is configured. Copy the SMTP username and password from Mailgun rather than typing them from memory.
Can I warm up Mailgun without a receiving inbox?
No. Mailgun is the sending relay. Warm-up also needs a real inbox that can receive, find spam placements, and reply. With BobWork, Mailgun uses SMTP credentials for sending plus the receiving inbox over IMAP.
What SPF record does Mailgun use?
Mailgun commonly asks for an SPF TXT record that includes include:mailgun.org. Use the exact value shown in your Mailgun domain verification screen. If your domain already has SPF, merge Mailgun into the existing record instead of publishing two SPF records.
Should I use the same Mailgun domain for cold and transactional email?
Usually, separate them. Use different subdomains for cold outreach and transactional mail, such as outreach.example.com and mail.example.com. That keeps reputation, complaint patterns, and troubleshooting clearer.
When is a Mailgun mailbox ready for outbound?
For BobWork warm-up, a mailbox is ready after 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Keep real outreach low at first and pause if spam rate rises above 5%.
Warm this mailbox up for free
Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.