Outlook Email Warm Up: Manual Microsoft 365 Ramp While OAuth Support Is Not Ready
Outlook email warm up needs a manual plan today because Microsoft 365 no longer supports Basic Authentication for Exchange Online and BobWork does not connect to Outlook yet. If you jump into cold volume, you can trigger junk placement, security challenges, or outbound restrictions. Use this guide to set DNS, ramp safely, check placement, and know when to send.
BobWork Email Warm-up supports several providers, but not Outlook or Microsoft 365 yet. If you can send from a supported mailbox, use the free email warm-up tool with that actual sender. If your campaign must send from Microsoft 365, follow the manual plan below and verify SPF, DKIM, and DMARC before increasing volume.
Microsoft’s connection requirement is the blocker. Microsoft has disabled Basic Authentication for Exchange Online, so a normal IMAP password is not enough for a modern warm-up app. Microsoft documents the change in its Basic Authentication deprecation guidance. OAuth is the route modern Microsoft 365 apps need.
Do not warm a different provider as a proxy. A clean Google Workspace or Zoho mailbox does not create Microsoft 365 mailbox history. Warm the mailbox that will actually send.
Can BobWork warm Outlook today?
No. BobWork cannot connect to Outlook or Microsoft 365 today. Microsoft requires OAuth, and Outlook support is not available in the product yet. Do not try to bypass that with an old IMAP password or a normal mailbox password.
For supported providers, BobWork handles scheduling, replies, spam rescue, and DNS checks automatically. Mailboxes warm in a shared network by default, or in a private pool per account where only your own mailboxes write to each other (at least two needed). Each account can add up to 20 mailboxes.
Current connection routes are:
| Mailbox or sender | Connection route | Notes |
|---|---|---|
| Outlook / Microsoft 365 | Not supported yet | Microsoft requires OAuth. Use the manual plan on this page. |
| Gmail / Google Workspace | Google sign-in with gmail.modify, or IMAP with an app password | Google shows an unverified-app notice because BobWork has not completed the CASA audit. |
| Zoho Mail | Zoho Mail API using a Self Client code, or IMAP on Mail Lite+ | The Zoho API route works on the free plan. See the Zoho warm-up guide. |
| Lark Mail | IMAP plus mail-client password | Use the mailbox’s mail-client password route. |
| Yahoo Mail / iCloud Mail | IMAP plus app password | Use provider-generated app passwords. |
| Amazon SES, SendGrid, Mailgun | Platform SMTP credentials for sending plus receiving inbox over IMAP | The platform sends; the inbox receives and verifies placement. |
| Any IMAP plus SMTP mailbox | IMAP for receiving and SMTP for sending | Check the provider’s current limits before ramping. |
The workaround is simple. If your outreach can send from Google Workspace, Zoho Mail, Lark, Yahoo, iCloud, SES, SendGrid, Mailgun, or another IMAP plus SMTP mailbox, warm that real sending mailbox. If the campaign must send from Microsoft 365, warm the Microsoft mailbox manually.
If you are still choosing a provider, compare the setup work before migrating. The first-time warm-up guide shows what happens during the first two weeks. The email warm-up network guide explains the difference between private and shared warm-up pools.
What does Microsoft check?
Microsoft does not publish one simple inbox-placement score. You need to watch several signals together.
For mail sent to Outlook.com, Hotmail, and Microsoft-hosted recipients, Microsoft evaluates authentication, sending reputation, and recipient reaction. For mail sent from Microsoft 365, Microsoft also watches account security and outbound abuse patterns inside the tenant.
If you send from IPs you own or control, use Microsoft Smart Network Data Services. SNDS can expose Microsoft-facing reputation signals such as complaint data and spam-trap hits for eligible IPs. If you send only through Microsoft 365 shared infrastructure, SNDS may not provide useful mailbox-level data.
Watch these areas instead:
| Signal | What Microsoft may use it for | What you can check |
|---|---|---|
| SPF, DKIM, DMARC | Sender authentication and alignment | DNS records, message headers, DMARC reports |
| Complaint behavior | Recipient trust and reputation | SNDS for controlled IPs, unsubscribe replies, manual feedback |
| Sudden volume changes | Outbound abuse detection | Daily send count per mailbox |
| Bounce patterns | List quality and abuse risk | Non-delivery reports and campaign logs |
| Account security | Compromise detection | MFA status, risky sign-ins, security prompts |
| Content pattern | Spam classification | Plain text, relevance, link count, attachment use |
| Recipient engagement | Inbox or junk placement | Replies, manual test inboxes, thread behavior |
Warm-up is not a trick. Microsoft is trying to identify whether a mailbox behaves like a normal sender. Normal senders start slowly, contact real people, receive replies, avoid repeated hard bounces, and do not send identical messages across many mailboxes.
For Microsoft 365 outbound issues, also check the Microsoft 365 admin center and Defender portal. If a mailbox is restricted, pause sending before changing copy or DNS. A restricted sender problem is not solved by sending more.
Which DNS records must pass?
Set DNS before you ramp. Warm-up cannot compensate for broken authentication.
Use one SPF record only. Enable DKIM for the custom domain, not just the tenant domain. Publish DMARC at _dmarc. If you have not reviewed alignment yet, start DMARC in monitoring mode.
| Record | Microsoft 365 setup | How to verify |
|---|---|---|
| SPF | v=spf1 include:spf.protection.outlook.com -all for Microsoft 365-only sending | Use the SPF checker. Microsoft documents SPF for Microsoft 365. |
| DKIM | Two CNAME records, usually selector1._domainkey and selector2._domainkey, pointing to Microsoft-generated targets | Use the DKIM checker, then confirm DKIM is enabled in Microsoft Defender. Microsoft documents DKIM setup. |
| DMARC | Start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com while monitoring | Use the DMARC checker, then inspect headers and reports for alignment. |
For DKIM, get the exact CNAME targets from Microsoft. In the Microsoft Defender portal, go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. Select your domain, publish the two CNAME records shown there, then enable signing.
A common Microsoft 365 DKIM pattern looks like this:
| Host | Type | Target pattern |
|---|---|---|
selector1._domainkey.yourdomain.com | CNAME | selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com |
selector2._domainkey.yourdomain.com | CNAME | selector2-yourdomain-com._domainkey.yourtenant.onmicrosoft.com |
Do not copy that pattern blindly. Your tenant and domain values may differ. Use Microsoft’s generated values.
If you also send through Amazon SES, SendGrid, Mailgun, a CRM, or a campaign tool, merge those senders into the same SPF record. Do not create multiple SPF TXT records at the root. Multiple SPF records can cause authentication failures.
After DNS changes, wait for propagation and send a test message to a mailbox you control. Open the headers and check that SPF, DKIM, and DMARC pass. If one fails, fix it before sending more mail.
How should Outlook email warm up work?
Use the same shape as a safe automated ramp: start at 3 messages per day, add 2 per day, and cap normal warm-up at 30 per day. On weekends, send about 30% of the listed volume. Keep messages plain, short, and human.
This table is per mailbox. If you have five Microsoft 365 mailboxes, each mailbox needs its own ramp. Do not make one mailbox carry the whole domain.
| Day | Warm-up conversations to send | Real outreach cap | What to check before increasing |
|---|---|---|---|
| 1 | 3 | 0 | SPF, DKIM, and DMARC pass |
| 2 | 5 | 0 | No security challenge or NDR pattern |
| 3 | 7 | 0 | Replies arrive in Inbox |
| 4 | 9 | 5 | No repeated junk placement |
| 5 | 11 | 5 | No restricted sender warning |
| 6 | 13, or 30% if weekend | 5 | Bounce reasons look normal |
| 7 | 15, or 30% if weekend | 10 | At least some natural replies |
| 8 | 17 | 10 | No sudden complaint feedback |
| 9 | 19 | 10 | Test mail reaches Gmail and Yahoo inboxes |
| 10 | 21 | 15 | Microsoft recipients do not consistently junk it |
| 11 | 23 | 15 | No outbound spam policy warning |
| 12 | 25 | 20 | Sending pattern still looks human |
| 13 | 27, or 30% if weekend | 20 | No block or throttling message |
| 14 | 30, or 30% if weekend | 25 | Ready gates pass |
Use office-style messages only. Ask colleagues, secondary mailboxes, and trusted contacts to reply naturally. Keep threads short. Three-message threads are enough: opener, reply, closer.
Good warm-up messages are boring. They look like normal internal or partner email. Use plain text. Avoid links, images, attachments, tracking pixels, and repeated templates.
During live campaigns, keep warm-up running at 10–15 messages per day. Keep real outreach around 30–50 messages per day per mailbox. If you need more volume, add mailboxes instead of pushing one Outlook account harder.
If manual checks show more than a few warm-up or test messages landing in junk, pause real outreach. A useful rule is to pause a mailbox above 5% spam placement for a few days, fix the cause, then resume lower.
If you want a custom ramp, use the email warm-up schedule generator. It helps when you have weekends, holidays, multiple mailboxes, or a slower new-domain plan.
Avoid these Microsoft 365 blocks
Most Outlook warm-up problems come from authentication gaps, security controls, sudden volume, or recipient reaction.
Basic IMAP no longer works
Old IMAP username-and-password access is not a safe assumption for Exchange Online. Microsoft disabled Basic Authentication. If a warm-up service says it can connect to Microsoft 365 with only a password, verify the method before trusting it.
Use manual warm-up until the app supports Microsoft OAuth properly.
DKIM is not enabled
A domain can send through Microsoft 365 with SPF passing but DKIM missing. That is weaker than it needs to be.
Enable DKIM for the custom domain in Microsoft Defender. Then send test messages and check headers. Do not assume DKIM works because the CNAME records exist.
SPF is duplicated
Many domains collect SPF records over time. One is from Microsoft. Another is from a CRM. Another is from a newsletter tool. That breaks SPF because the domain publishes multiple SPF TXT records.
Merge senders into one SPF record. Keep it readable. Check provider documentation when you add a new sender.
The mailbox sends too fast
New Microsoft 365 mailboxes should not jump from zero to campaign volume. A sudden pattern can look like compromise or abuse.
Start at 3 warm-up messages per day. Add real outreach only after replies and placement look normal. Keep one mailbox within normal cold outreach ranges and add mailboxes for scale.
Bounces are ignored
Hard bounces tell providers that your list quality is poor. Remove invalid addresses quickly. Do not keep mailing a bad segment because the mailbox is warming.
If a campaign creates many bounces, stop that campaign. Warm-up traffic cannot offset a bad list.
Recipients mark spam
Complaints are stronger than opens. Microsoft can see negative recipient actions inside its ecosystem. If you use your own or dedicated IP, SNDS can help you monitor Microsoft-facing complaint data.
Make unsubscribe or opt-out handling easy. Do not send follow-ups to people who say no. Reduce frequency before changing tools.
The account looks compromised
Microsoft 365 protects mailboxes with sign-in risk checks, MFA prompts, and outbound restrictions. These are good controls.
Use MFA. Avoid shared passwords. Keep sign-ins consistent. If a mailbox is restricted, resolve the security issue first. Do not create a new mailbox just to continue the same pattern.
For broader diagnosis, use the spam troubleshooting guide. It separates authentication, reputation, content, list quality, and volume problems.
Do this now
Use this checklist before the first campaign. It is designed for Microsoft 365 senders who cannot use automated Outlook warm-up yet.
| Step | Action | How to verify |
|---|---|---|
| 1 | Confirm the mailbox sends through Microsoft 365 | Send a test email and inspect headers for Microsoft 365 routing |
| 2 | Publish or clean up SPF | The SPF checker shows one valid SPF record with Microsoft 365 included |
| 3 | Enable DKIM for the custom domain | A test message shows dkim=pass for your domain |
| 4 | Publish DMARC at _dmarc | The DMARC checker returns a valid record |
| 5 | Turn on MFA for the mailbox | Microsoft 365 admin center shows MFA or conditional access coverage |
| 6 | Send 3 warm-up messages on day 1 | All messages are plain text and sent to real controlled recipients |
| 7 | Ask for natural replies | Replies land in Inbox and threads look normal |
| 8 | Increase by 2 per day | Your log matches the ramp table and weekends are reduced |
| 9 | Add real outreach slowly | Campaign mail starts only after clean warm-up replies |
| 10 | Watch Microsoft warnings | No restricted sender, outbound spam, or risky sign-in alerts appear |
| 11 | Check placement across providers | Test messages reach Outlook, Gmail, Yahoo, and one business domain where possible |
| 12 | Pause if junk rises | If spam placement exceeds about 5%, stop real outreach for a few days |
Keep a simple sheet with date, warm-up sent, real outreach sent, replies, bounces, junk placements, and alerts. You do not need a complex dashboard. You need enough evidence to know whether the next increase is safe.
If you use a supported provider for outreach, BobWork shows daily DNS checks for SPF, DKIM, and DMARC. It also measures spam landings directly in receiving mailboxes rather than using third-party seed lists.
When is it ready?
You are ready when the mailbox has history, authentication passes, and negative signals are quiet. Do not use only the calendar.
For BobWork-supported mailboxes, the ready rule is explicit: 14 or more days warming, a 7-day spam rate of 3% or less, and at least 30 warm-up emails received. The health score is Healthy at 85 or above, Watch from 60–84, and At risk below 60.
For Outlook manual warm-up, use the closest practical version:
| Gate | Ready sign | Not ready sign |
|---|---|---|
| Time | At least 14 days for an existing domain | Fewer than 14 days, or a brand-new domain rushed early |
| Authentication | SPF, DKIM, and DMARC pass | Any authentication failure or missing DKIM |
| Warm-up history | At least 30 tracked warm-up messages received | Only outbound messages, with no replies |
| Placement | Controlled tests usually land in Inbox | Repeated Junk placement at Microsoft or Gmail |
| Security | No risky sign-in or restricted sender alerts | Microsoft blocks, throttles, or challenges the mailbox |
| Outreach | Replies and bounces look normal | Hard bounces, complaints, or opt-outs rise quickly |
A new domain should usually take 3–4 weeks. That extra time gives the domain and mailbox a more natural pattern before real campaigns carry the load.
Once ready, keep watching. Keep warm-up at 10–15 per day during campaigns. Keep real outreach around 30–50 per day per mailbox. If you need 300 daily sends, use more mailboxes and domains rather than forcing one Outlook account to do all of it.
If you can send from Gmail, Google Workspace, Zoho, Lark, Yahoo, iCloud, SES, SendGrid, Mailgun, or another IMAP plus SMTP mailbox, you can use BobWork Email Warm-up free with no card and no time limit. If you must use Outlook, follow this manual plan and use the SPF, DKIM, DMARC, and schedule tools until Microsoft OAuth support is available.
Frequently asked questions
Can I use BobWork Email Warm-up with Outlook today?
No. Outlook and Microsoft 365 are not supported yet because Microsoft requires OAuth. BobWork supports Gmail, Google Workspace, Zoho Mail, Lark, Yahoo, iCloud, Amazon SES, SendGrid, Mailgun, and any IMAP plus SMTP mailbox.
Why can’t an app just use Outlook IMAP with a password?
Microsoft disabled Basic Authentication for Exchange Online. Modern connections need OAuth. App passwords and basic IMAP are not a reliable route for Microsoft 365 mailboxes.
How long should Microsoft 365 warm-up take?
Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain, new tenant, or mailbox with no sending history. Increase volume only when replies, bounces, junk placement and security alerts stay clean.
Does warming a Google Workspace alias help my Outlook mailbox?
Not directly. It only helps if that Google Workspace mailbox is the actual sender for outreach. If your campaign sends from Microsoft 365, warm the Microsoft mailbox manually until Outlook support is available.
What SPF record should Microsoft 365 use?
For Microsoft 365-only sending, the usual SPF TXT record is v=spf1 include:spf.protection.outlook.com -all. If you also send through SES, SendGrid, Mailgun or another service, merge all senders into one SPF record.
Should I use SNDS for Microsoft 365 warm-up?
Use SNDS when you send from IPs you own or control. It shows Microsoft-facing reputation signals such as complaint data and spam-trap hits. If you send through Microsoft 365 shared infrastructure, focus on Microsoft 365 admin reports, NDRs and recipient placement tests.
What should I do if Outlook warm-up messages land in junk?
Slow down for a few days. Check SPF, DKIM and DMARC, reduce real outreach, send plain text, ask real recipients to reply when appropriate, and move only your own test or warm-up messages from Junk to Inbox. Never interact with real spam.
Warm this mailbox up for free
Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.