Home › Provider guides

How to Warm Up Mailgun Safely

By BobWorkUpdated 2026-10-0313 min read
Mailgun warm-up flow showing domain DNS records, SMTP credentials, receiving inboxes and a daily ramp schedule

Warm up Mailgun by verifying a sending domain, connecting Mailgun SMTP plus a real receiving inbox, then ramping from 3 to 30 messages per day per mailbox over about 14 days. If you skip the ramp, new-domain mail can hit spam or throttling before campaigns start. This guide gives the DNS, hosts, schedule, checks, and launch gates.

If you want warm-up running while you finish Mailgun setup, use the free warm-up tool. It supports Mailgun through the platform's SMTP credentials for sending, plus a receiving inbox over IMAP. That pairing matters because Mailgun can send, but warm-up also needs inbox placement checks and replies.

Mailgun is often used for transactional email. It can also send cold email when configured carefully. The risk is mixing those two jobs without enough separation. A password reset has different expectations from a sales opener. Use separate subdomains where possible, warm each route, and watch spam placement before increasing volume.

What does Mailgun check first?

Mailgun's first gate is domain verification. You add a sending domain or subdomain in Mailgun, then publish the DNS records it shows. Mailgun checks those records before it trusts the domain for sending.

Use a subdomain unless you have a strong reason not to. For example, use mg.example.com, mail.example.com, or outreach.example.com rather than the root domain. A subdomain keeps Mailgun-specific DNS away from your main website, Google Workspace, Microsoft 365, or other mail systems.

Mailgun also cares about the region you chose. For SMTP sending, use the host that matches your Mailgun region.

Mailgun regionSMTP hostTypical SMTP usernameWhat to check
USsmtp.mailgun.orgOften postmaster@your-domainDomain is verified in the US region
EUsmtp.eu.mailgun.orgOften postmaster@your-domainDomain is verified in the EU region

Copy the SMTP login from Mailgun. Do not assume it is always the same. The default credential is often a postmaster@ address for the sending domain, but the dashboard is the source of truth.

New Mailgun accounts can have low hourly caps. Check Mailgun's current limits before you plan volume. A slow ramp protects the domain and avoids hitting provider-side limits while the account is still new.

For cold email, the other early signal is behaviour. Avoid sudden jumps. Keep links, images, tracking, and attachments out of warm-up. BobWork warm-up mail is plain text, uses first-name greetings, and does not include links or images. That makes the warm-up pattern quieter and easier to interpret.

How do you connect Mailgun?

Mailgun is not an inbox provider. It is the SMTP sending side. Warm-up needs two parts: a sender and a receiver. For Mailgun, BobWork sends through Mailgun SMTP, then checks a real receiving inbox over IMAP.

The receiving inbox must be one you control. It should receive mail normally, expose the spam folder, and allow IMAP access. The warm-up engine then measures whether the sender's messages landed in spam across receiving mailboxes.

BobWork runs a shared network by default; switch the account to Private pool and only mailboxes inside your account write to each other (at least 2 needed). Each account can use up to 20 mailboxes.

Mailbox or platformHow BobWork connectsNotes
MailgunSMTP credentials for sending plus receiving inbox over IMAPUse the correct US or EU SMTP host
Gmail or Google WorkspaceGoogle sign-in or IMAP with an app passwordGoogle sign-in uses gmail.modify; Google shows an unverified-app notice
Zoho MailZoho Mail API with a Self Client code, or IMAP on Mail Lite+The Zoho API route works on the free plan
Lark MailIMAP plus mail-client passwordUse the mailbox's own client password
Yahoo Mail or iCloud MailIMAP plus app passwordApp passwords are required
Any IMAP+SMTP mailboxIMAP and SMTP credentialsCheck your provider's current limits

For Mailgun, create or copy SMTP credentials from the Mailgun dashboard. Then connect the receiving inbox in BobWork. That inbox lets the tool find spam placements, move warm-up mail back to Inbox, and label it.

The rescue behaviour is limited to warm-up mail. BobWork only touches mail carrying its own hidden header, or a known subject for Zoho API senders. It never reads, moves, or answers real mail.

You can see the detailed ramp logic in the exact engine behaviour. The short version is simple: low start, daily increases, random timing during business hours, and no repeated pair too soon.

Which DNS records must pass?

Mailgun domain verification usually involves SPF and DKIM. You should also publish DMARC, even when Mailgun does not require it for the first send.

Open your Mailgun sending domain and copy the DNS records exactly as shown. Mailgun's own documentation on verifying domains is the primary reference. Your DNS host may call TXT records Text, TXT, or DNS TXT. The value must still match Mailgun.

SPF is a TXT record that authorises Mailgun to send for the domain. Mailgun commonly uses this include:

v=spf1 include:mailgun.org ~all

If the domain already has SPF, do not publish a second SPF record. Merge Mailgun into the existing SPF record. A domain should have one SPF TXT record at that host. For example, if you already authorise Google and now need Mailgun, combine both includes in one record.

DKIM proves Mailgun signed the message for your domain. Mailgun will show the selector and TXT value. The selector may be something like k1, but use the exact selector Mailgun gives you. BobWork checks common DKIM selectors daily, including k1, s1, mail, dkim, default, google, zmail, selector1, selector2, lark, feishu, and zoho.

DMARC is published at _dmarc.your-domain. It tells receivers what policy you want for mail that fails authentication alignment. Start with a monitoring policy if you are unsure:

v=DMARC1; p=none; rua=mailto:dmarc@your-domain

Tighten later when you are confident all legitimate senders are aligned. DMARC is defined in RFC 7489. Google also publishes sender guidance that includes authentication and complaint-rate expectations. For bulk senders, Google says to keep spam complaint rates below 0.1% and avoid ever reaching 0.3%; see Google's email sender guidelines.

Use tools after publishing. Check SPF with the SPF checker, DKIM with the DKIM checker, and DMARC with the DMARC checker. BobWork also checks SPF, DKIM, and DMARC daily per domain and shows the result in the app.

RecordHost or nameValue to expectHow to verify
SPFYour Mailgun sending domainIncludes Mailgun, commonly include:mailgun.orgMailgun verification and SPF checker
DKIMSelector shown by Mailgun, such as k1._domainkeyLong TXT value from MailgunMailgun verification and DKIM checker
DMARC_dmarc on the sending domainStarts with v=DMARC1DMARC checker
SMTP hostMailgun SMTP settingsUS: smtp.mailgun.org; EU: smtp.eu.mailgun.orgSuccessful SMTP login and test send

Do not warm up until DNS is correct. If SPF or DKIM is missing, receivers have less reason to trust the mail. If DMARC is missing, you lose a useful reporting and policy layer.

What Mailgun warm up schedule works?

The safe Mailgun warm up pattern is controlled growth, not a fixed blast. Start low, spread sends through the workday, and hold volume when spam placement rises.

BobWork's default engine starts at 3 emails per day, adds 2 per day, and caps at 30 per day. Weekends run at 30% of weekday volume. Sends are spread between 09:00 and 18:00 in the mailbox's own time zone, with randomness every 15 minutes.

A pair never writes to each other twice within 3 hours. Peers on a different domain or provider are picked twice as often. About 40% of received warm-up mail gets a reply, and threads end after 3 messages.

Day rangeWarm-up targetWeekend behaviourWhat to watchAction
Days 1–33–7/day30% of weekday levelSMTP login, DNS pass, first spam landingsFix authentication before increasing
Days 4–79–15/day30%7-day spam trend starts formingHold if spam rises quickly
Days 8–1417–29/day30%Sender spam rate, replies, Mailgun capsKeep ramping only if stable
Day 15+30/day default cap30%7-day spam rate and received countAdd real outbound carefully
During campaigns10–15/day warm-up30%Complaint risk and inbox placementKeep warm-up active, avoid spikes

You can set a different cap per mailbox, up to 100. For Mailgun, do not raise it just because the tool allows it. Check Mailgun's current limits and account status first, especially on new accounts with low hourly caps.

For real cold outreach, keep volume conservative. A typical safe working range is 30–50 real outbound emails per mailbox per day, assuming the domain is healthy and replies are normal. Add mailboxes instead of forcing more volume through one sender.

Use the warm-up schedule generator if you need a written plan for a new domain, existing domain, or campaign launch. For a broader timeline, see how long email warm-up takes.

What blocks Mailgun warm-up?

Most Mailgun warm-up problems come from mismatched setup, not from the ramp itself. Fix the base before increasing volume.

The first mistake is using the wrong region host. If your domain is in Mailgun EU, send through smtp.eu.mailgun.org. If it is in the US region, use smtp.mailgun.org. A wrong host or credential can fail authentication, block sending, or make troubleshooting harder.

The second mistake is warming a domain before verification completes. Mailgun may let you configure credentials before every DNS check is green. Receivers still judge the message. SPF, DKIM, and DMARC should be in place before any serious ramp.

The third mistake is publishing two SPF records. This often happens when teams add Mailgun after Google Workspace, Microsoft 365, or another platform. Merge includes into one SPF record. Multiple SPF TXT records at the same host can break SPF evaluation.

The fourth mistake is mixing transactional and cold traffic on one sender. Use separate subdomains where possible. Keep password resets, receipts, product notifications, and cold outreach apart. If cold outreach has a problem, your transactional stream should not inherit that reputation issue.

The fifth mistake is sending campaign mail while warm-up is still unstable. BobWork's spam rate is the share of a sender's warm-up mail that receiving mailboxes found in Spam over the last 7 days. If a mailbox goes above 5%, pause it for a few days and fix the cause.

The sixth mistake is assuming warm-up replaces good sending practice. It does not. You still need relevant copy, low complaint risk, clean recipients, working unsubscribe handling where required, and a sending identity that matches the message.

If your mail keeps landing in spam, use the same diagnostic order every time: DNS, SMTP region, account limits, domain age, content, list quality, then volume. The guide on why emails go to spam walks through those causes in more detail.

What should you do now?

Use this checklist before starting Mailgun warm-up. Do not move to the next step until the verification column passes.

StepActionHow to verify
1Choose a Mailgun sending subdomain, such as mg.example.com or outreach.example.comThe domain appears in Mailgun under your chosen region
2Publish Mailgun's SPF TXT recordMailgun marks SPF verified; SPF checker shows Mailgun included
3Publish Mailgun's DKIM TXT recordMailgun marks DKIM verified; DKIM checker finds the selector
4Publish DMARC at _dmarcDMARC checker returns a valid v=DMARC1 policy
5Copy SMTP credentials from MailgunUsername, password, and host match the Mailgun region
6Use smtp.mailgun.org or smtp.eu.mailgun.org correctlyA test SMTP login succeeds
7Connect a real receiving inbox over IMAPThe inbox can receive, show spam, and allow warm-up checks
8Add the mailbox to BobWorkIt shows active and exchanges mail
9Start at the default rampDay 1 begins at 3 emails per day
10Watch 7-day spam rateHealthy trend stays at or below 3% before outbound
11Keep campaign warm-up activeWarm-up stays around 10–15/day during campaigns
12Pause if spam rises above 5%Mailbox is paused while you fix DNS, content, or volume

Treat the checklist as a launch gate. If one item fails, fix that item instead of increasing volume.

If DKIM is missing, do not compensate by warming longer. Publish the correct DKIM record. If the SMTP login fails, do not rotate passwords blindly. Check the region host, the postmaster@ credential, and whether the account has current sending restrictions.

If DNS passes but spam placement remains high, look at the domain and message. A brand-new domain usually needs a longer ramp than an established domain. Use 3–4 weeks for a new domain. Use at least 14 days for an existing domain.

When is Mailgun ready?

A Mailgun sender is ready for outbound only when the signals agree. Do not rely on one successful test message.

In BobWork, Ready for outbound means 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Health scores are shown from 0 to 100: Healthy is 85 or above, Watch is 60–84, At risk is below 60, and Blocked means the login or permission failed.

Once ready, start real mail below your intended daily volume. Keep warm-up running at 10–15 messages per day during campaigns. If real replies are low, spam placement rises, or Mailgun caps sending, hold volume instead of pushing through.

Cold and transactional traffic should be judged separately. Transactional mail often has expected recipients and clear user intent. Cold mail usually has lower familiarity and higher complaint risk. Separate subdomains make those patterns easier to see.

Before a larger campaign, run one last check: SPF, DKIM, DMARC, Mailgun region host, receiving inbox access, warm-up health, and current Mailgun limits. Then increase in small steps.

BobWork Email Warm-up is free, requires no credit card, and has no time limit. For Mailgun, it uses SMTP credentials for sending and a receiving inbox over IMAP, with up to 20 mailboxes per account, on the shared network or in a private pool. Start with the free warm-up tool when your DNS records are ready.

What else should you know?

How long should Mailgun warm-up take?

Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Move slower if warm-up mail lands in spam, if the domain is new, or if Mailgun applies low hourly caps on a new account.

Which SMTP host should I use?

Use smtp.mailgun.org for the US region and smtp.eu.mailgun.org for the EU region. Match the host to the region where your Mailgun domain is configured. Copy the SMTP username and password from Mailgun rather than typing them from memory.

Can I warm up without an inbox?

No. Mailgun is the sending relay. Warm-up also needs a real inbox that can receive, find spam placements, and reply. With BobWork, Mailgun uses SMTP credentials for sending plus the receiving inbox over IMAP.

What SPF record does Mailgun use?

Mailgun commonly asks for an SPF TXT record that includes include:mailgun.org. Use the exact value shown in your Mailgun domain verification screen. If your domain already has SPF, merge Mailgun into the existing record instead of publishing two SPF records.

Should cold and transactional share?

Usually, separate them. Use different subdomains for cold outreach and transactional mail, such as outreach.example.com and mail.example.com. That keeps reputation, complaint patterns, and troubleshooting clearer.

When can I start outbound?

For BobWork warm-up, a mailbox is ready after 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Keep real outreach low at first and pause if spam rate rises above 5%.

Frequently asked questions

How long should Mailgun warm-up take?

Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Move slower if warm-up mail lands in spam, if the domain is new, or if Mailgun applies low hourly caps on a new account.

Which SMTP host should I use for Mailgun warm-up?

Use smtp.mailgun.org for the US region and smtp.eu.mailgun.org for the EU region. Match the host to the region where your Mailgun domain is configured. Copy the SMTP username and password from Mailgun rather than typing them from memory.

Can I warm up Mailgun without a receiving inbox?

No. Mailgun is the sending relay. Warm-up also needs a real inbox that can receive, find spam placements, and reply. With BobWork, Mailgun uses SMTP credentials for sending plus the receiving inbox over IMAP.

What SPF record does Mailgun use?

Mailgun commonly asks for an SPF TXT record that includes include:mailgun.org. Use the exact value shown in your Mailgun domain verification screen. If your domain already has SPF, merge Mailgun into the existing record instead of publishing two SPF records.

Should I use the same Mailgun domain for cold and transactional email?

Usually, separate them. Use different subdomains for cold outreach and transactional mail, such as outreach.example.com and mail.example.com. That keeps reputation, complaint patterns, and troubleshooting clearer.

When is a Mailgun mailbox ready for outbound?

For BobWork warm-up, a mailbox is ready after 14+ days warming, a 7-day spam rate at or below 3%, and at least 30 warm-up emails received. Keep real outreach low at first and pause if spam rate rises above 5%.

Warm this mailbox up for free

Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.

Start free