Home › Provider guides

Outlook Email Warm Up: Manual Microsoft 365 Ramp While OAuth Support Is Not Ready

By BobWorkUpdated 2026-10-0312 min read
Microsoft 365 email warm-up ramp, DNS records and verification checklist

Outlook email warm up needs a manual plan today because Microsoft 365 no longer supports Basic Authentication for Exchange Online and BobWork does not connect to Outlook yet. If you jump into cold volume, you can trigger junk placement, security challenges, or outbound restrictions. Use this guide to set DNS, ramp safely, check placement, and know when to send.

BobWork Email Warm-up supports several providers, but not Outlook or Microsoft 365 yet. If you can send from a supported mailbox, use the free email warm-up tool with that actual sender. If your campaign must send from Microsoft 365, follow the manual plan below and verify SPF, DKIM, and DMARC before increasing volume.

Microsoft’s connection requirement is the blocker. Microsoft has disabled Basic Authentication for Exchange Online, so a normal IMAP password is not enough for a modern warm-up app. Microsoft documents the change in its Basic Authentication deprecation guidance. OAuth is the route modern Microsoft 365 apps need.

Do not warm a different provider as a proxy. A clean Google Workspace or Zoho mailbox does not create Microsoft 365 mailbox history. Warm the mailbox that will actually send.

Can BobWork warm Outlook today?

No. BobWork cannot connect to Outlook or Microsoft 365 today. Microsoft requires OAuth, and Outlook support is not available in the product yet. Do not try to bypass that with an old IMAP password or a normal mailbox password.

For supported providers, BobWork handles scheduling, replies, spam rescue, and DNS checks automatically. Mailboxes warm in a shared network by default, or in a private pool per account where only your own mailboxes write to each other (at least two needed). Each account can add up to 20 mailboxes.

Current connection routes are:

Mailbox or senderConnection routeNotes
Outlook / Microsoft 365Not supported yetMicrosoft requires OAuth. Use the manual plan on this page.
Gmail / Google WorkspaceGoogle sign-in with gmail.modify, or IMAP with an app passwordGoogle shows an unverified-app notice because BobWork has not completed the CASA audit.
Zoho MailZoho Mail API using a Self Client code, or IMAP on Mail Lite+The Zoho API route works on the free plan. See the Zoho warm-up guide.
Lark MailIMAP plus mail-client passwordUse the mailbox’s mail-client password route.
Yahoo Mail / iCloud MailIMAP plus app passwordUse provider-generated app passwords.
Amazon SES, SendGrid, MailgunPlatform SMTP credentials for sending plus receiving inbox over IMAPThe platform sends; the inbox receives and verifies placement.
Any IMAP plus SMTP mailboxIMAP for receiving and SMTP for sendingCheck the provider’s current limits before ramping.

The workaround is simple. If your outreach can send from Google Workspace, Zoho Mail, Lark, Yahoo, iCloud, SES, SendGrid, Mailgun, or another IMAP plus SMTP mailbox, warm that real sending mailbox. If the campaign must send from Microsoft 365, warm the Microsoft mailbox manually.

If you are still choosing a provider, compare the setup work before migrating. The first-time warm-up guide shows what happens during the first two weeks. The email warm-up network guide explains the difference between private and shared warm-up pools.

What does Microsoft check?

Microsoft does not publish one simple inbox-placement score. You need to watch several signals together.

For mail sent to Outlook.com, Hotmail, and Microsoft-hosted recipients, Microsoft evaluates authentication, sending reputation, and recipient reaction. For mail sent from Microsoft 365, Microsoft also watches account security and outbound abuse patterns inside the tenant.

If you send from IPs you own or control, use Microsoft Smart Network Data Services. SNDS can expose Microsoft-facing reputation signals such as complaint data and spam-trap hits for eligible IPs. If you send only through Microsoft 365 shared infrastructure, SNDS may not provide useful mailbox-level data.

Watch these areas instead:

SignalWhat Microsoft may use it forWhat you can check
SPF, DKIM, DMARCSender authentication and alignmentDNS records, message headers, DMARC reports
Complaint behaviorRecipient trust and reputationSNDS for controlled IPs, unsubscribe replies, manual feedback
Sudden volume changesOutbound abuse detectionDaily send count per mailbox
Bounce patternsList quality and abuse riskNon-delivery reports and campaign logs
Account securityCompromise detectionMFA status, risky sign-ins, security prompts
Content patternSpam classificationPlain text, relevance, link count, attachment use
Recipient engagementInbox or junk placementReplies, manual test inboxes, thread behavior

Warm-up is not a trick. Microsoft is trying to identify whether a mailbox behaves like a normal sender. Normal senders start slowly, contact real people, receive replies, avoid repeated hard bounces, and do not send identical messages across many mailboxes.

For Microsoft 365 outbound issues, also check the Microsoft 365 admin center and Defender portal. If a mailbox is restricted, pause sending before changing copy or DNS. A restricted sender problem is not solved by sending more.

Which DNS records must pass?

Set DNS before you ramp. Warm-up cannot compensate for broken authentication.

Use one SPF record only. Enable DKIM for the custom domain, not just the tenant domain. Publish DMARC at _dmarc. If you have not reviewed alignment yet, start DMARC in monitoring mode.

RecordMicrosoft 365 setupHow to verify
SPFv=spf1 include:spf.protection.outlook.com -all for Microsoft 365-only sendingUse the SPF checker. Microsoft documents SPF for Microsoft 365.
DKIMTwo CNAME records, usually selector1._domainkey and selector2._domainkey, pointing to Microsoft-generated targetsUse the DKIM checker, then confirm DKIM is enabled in Microsoft Defender. Microsoft documents DKIM setup.
DMARCStart with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com while monitoringUse the DMARC checker, then inspect headers and reports for alignment.

For DKIM, get the exact CNAME targets from Microsoft. In the Microsoft Defender portal, go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. Select your domain, publish the two CNAME records shown there, then enable signing.

A common Microsoft 365 DKIM pattern looks like this:

HostTypeTarget pattern
selector1._domainkey.yourdomain.comCNAMEselector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com
selector2._domainkey.yourdomain.comCNAMEselector2-yourdomain-com._domainkey.yourtenant.onmicrosoft.com

Do not copy that pattern blindly. Your tenant and domain values may differ. Use Microsoft’s generated values.

If you also send through Amazon SES, SendGrid, Mailgun, a CRM, or a campaign tool, merge those senders into the same SPF record. Do not create multiple SPF TXT records at the root. Multiple SPF records can cause authentication failures.

After DNS changes, wait for propagation and send a test message to a mailbox you control. Open the headers and check that SPF, DKIM, and DMARC pass. If one fails, fix it before sending more mail.

How should Outlook email warm up work?

Use the same shape as a safe automated ramp: start at 3 messages per day, add 2 per day, and cap normal warm-up at 30 per day. On weekends, send about 30% of the listed volume. Keep messages plain, short, and human.

This table is per mailbox. If you have five Microsoft 365 mailboxes, each mailbox needs its own ramp. Do not make one mailbox carry the whole domain.

DayWarm-up conversations to sendReal outreach capWhat to check before increasing
130SPF, DKIM, and DMARC pass
250No security challenge or NDR pattern
370Replies arrive in Inbox
495No repeated junk placement
5115No restricted sender warning
613, or 30% if weekend5Bounce reasons look normal
715, or 30% if weekend10At least some natural replies
81710No sudden complaint feedback
91910Test mail reaches Gmail and Yahoo inboxes
102115Microsoft recipients do not consistently junk it
112315No outbound spam policy warning
122520Sending pattern still looks human
1327, or 30% if weekend20No block or throttling message
1430, or 30% if weekend25Ready gates pass

Use office-style messages only. Ask colleagues, secondary mailboxes, and trusted contacts to reply naturally. Keep threads short. Three-message threads are enough: opener, reply, closer.

Good warm-up messages are boring. They look like normal internal or partner email. Use plain text. Avoid links, images, attachments, tracking pixels, and repeated templates.

During live campaigns, keep warm-up running at 10–15 messages per day. Keep real outreach around 30–50 messages per day per mailbox. If you need more volume, add mailboxes instead of pushing one Outlook account harder.

If manual checks show more than a few warm-up or test messages landing in junk, pause real outreach. A useful rule is to pause a mailbox above 5% spam placement for a few days, fix the cause, then resume lower.

If you want a custom ramp, use the email warm-up schedule generator. It helps when you have weekends, holidays, multiple mailboxes, or a slower new-domain plan.

Avoid these Microsoft 365 blocks

Most Outlook warm-up problems come from authentication gaps, security controls, sudden volume, or recipient reaction.

Basic IMAP no longer works

Old IMAP username-and-password access is not a safe assumption for Exchange Online. Microsoft disabled Basic Authentication. If a warm-up service says it can connect to Microsoft 365 with only a password, verify the method before trusting it.

Use manual warm-up until the app supports Microsoft OAuth properly.

DKIM is not enabled

A domain can send through Microsoft 365 with SPF passing but DKIM missing. That is weaker than it needs to be.

Enable DKIM for the custom domain in Microsoft Defender. Then send test messages and check headers. Do not assume DKIM works because the CNAME records exist.

SPF is duplicated

Many domains collect SPF records over time. One is from Microsoft. Another is from a CRM. Another is from a newsletter tool. That breaks SPF because the domain publishes multiple SPF TXT records.

Merge senders into one SPF record. Keep it readable. Check provider documentation when you add a new sender.

The mailbox sends too fast

New Microsoft 365 mailboxes should not jump from zero to campaign volume. A sudden pattern can look like compromise or abuse.

Start at 3 warm-up messages per day. Add real outreach only after replies and placement look normal. Keep one mailbox within normal cold outreach ranges and add mailboxes for scale.

Bounces are ignored

Hard bounces tell providers that your list quality is poor. Remove invalid addresses quickly. Do not keep mailing a bad segment because the mailbox is warming.

If a campaign creates many bounces, stop that campaign. Warm-up traffic cannot offset a bad list.

Recipients mark spam

Complaints are stronger than opens. Microsoft can see negative recipient actions inside its ecosystem. If you use your own or dedicated IP, SNDS can help you monitor Microsoft-facing complaint data.

Make unsubscribe or opt-out handling easy. Do not send follow-ups to people who say no. Reduce frequency before changing tools.

The account looks compromised

Microsoft 365 protects mailboxes with sign-in risk checks, MFA prompts, and outbound restrictions. These are good controls.

Use MFA. Avoid shared passwords. Keep sign-ins consistent. If a mailbox is restricted, resolve the security issue first. Do not create a new mailbox just to continue the same pattern.

For broader diagnosis, use the spam troubleshooting guide. It separates authentication, reputation, content, list quality, and volume problems.

Do this now

Use this checklist before the first campaign. It is designed for Microsoft 365 senders who cannot use automated Outlook warm-up yet.

StepActionHow to verify
1Confirm the mailbox sends through Microsoft 365Send a test email and inspect headers for Microsoft 365 routing
2Publish or clean up SPFThe SPF checker shows one valid SPF record with Microsoft 365 included
3Enable DKIM for the custom domainA test message shows dkim=pass for your domain
4Publish DMARC at _dmarcThe DMARC checker returns a valid record
5Turn on MFA for the mailboxMicrosoft 365 admin center shows MFA or conditional access coverage
6Send 3 warm-up messages on day 1All messages are plain text and sent to real controlled recipients
7Ask for natural repliesReplies land in Inbox and threads look normal
8Increase by 2 per dayYour log matches the ramp table and weekends are reduced
9Add real outreach slowlyCampaign mail starts only after clean warm-up replies
10Watch Microsoft warningsNo restricted sender, outbound spam, or risky sign-in alerts appear
11Check placement across providersTest messages reach Outlook, Gmail, Yahoo, and one business domain where possible
12Pause if junk risesIf spam placement exceeds about 5%, stop real outreach for a few days

Keep a simple sheet with date, warm-up sent, real outreach sent, replies, bounces, junk placements, and alerts. You do not need a complex dashboard. You need enough evidence to know whether the next increase is safe.

If you use a supported provider for outreach, BobWork shows daily DNS checks for SPF, DKIM, and DMARC. It also measures spam landings directly in receiving mailboxes rather than using third-party seed lists.

When is it ready?

You are ready when the mailbox has history, authentication passes, and negative signals are quiet. Do not use only the calendar.

For BobWork-supported mailboxes, the ready rule is explicit: 14 or more days warming, a 7-day spam rate of 3% or less, and at least 30 warm-up emails received. The health score is Healthy at 85 or above, Watch from 60–84, and At risk below 60.

For Outlook manual warm-up, use the closest practical version:

GateReady signNot ready sign
TimeAt least 14 days for an existing domainFewer than 14 days, or a brand-new domain rushed early
AuthenticationSPF, DKIM, and DMARC passAny authentication failure or missing DKIM
Warm-up historyAt least 30 tracked warm-up messages receivedOnly outbound messages, with no replies
PlacementControlled tests usually land in InboxRepeated Junk placement at Microsoft or Gmail
SecurityNo risky sign-in or restricted sender alertsMicrosoft blocks, throttles, or challenges the mailbox
OutreachReplies and bounces look normalHard bounces, complaints, or opt-outs rise quickly

A new domain should usually take 3–4 weeks. That extra time gives the domain and mailbox a more natural pattern before real campaigns carry the load.

Once ready, keep watching. Keep warm-up at 10–15 per day during campaigns. Keep real outreach around 30–50 per day per mailbox. If you need 300 daily sends, use more mailboxes and domains rather than forcing one Outlook account to do all of it.

If you can send from Gmail, Google Workspace, Zoho, Lark, Yahoo, iCloud, SES, SendGrid, Mailgun, or another IMAP plus SMTP mailbox, you can use BobWork Email Warm-up free with no card and no time limit. If you must use Outlook, follow this manual plan and use the SPF, DKIM, DMARC, and schedule tools until Microsoft OAuth support is available.

Frequently asked questions

Can I use BobWork Email Warm-up with Outlook today?

No. Outlook and Microsoft 365 are not supported yet because Microsoft requires OAuth. BobWork supports Gmail, Google Workspace, Zoho Mail, Lark, Yahoo, iCloud, Amazon SES, SendGrid, Mailgun, and any IMAP plus SMTP mailbox.

Why can’t an app just use Outlook IMAP with a password?

Microsoft disabled Basic Authentication for Exchange Online. Modern connections need OAuth. App passwords and basic IMAP are not a reliable route for Microsoft 365 mailboxes.

How long should Microsoft 365 warm-up take?

Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain, new tenant, or mailbox with no sending history. Increase volume only when replies, bounces, junk placement and security alerts stay clean.

Does warming a Google Workspace alias help my Outlook mailbox?

Not directly. It only helps if that Google Workspace mailbox is the actual sender for outreach. If your campaign sends from Microsoft 365, warm the Microsoft mailbox manually until Outlook support is available.

What SPF record should Microsoft 365 use?

For Microsoft 365-only sending, the usual SPF TXT record is v=spf1 include:spf.protection.outlook.com -all. If you also send through SES, SendGrid, Mailgun or another service, merge all senders into one SPF record.

Should I use SNDS for Microsoft 365 warm-up?

Use SNDS when you send from IPs you own or control. It shows Microsoft-facing reputation signals such as complaint data and spam-trap hits. If you send through Microsoft 365 shared infrastructure, focus on Microsoft 365 admin reports, NDRs and recipient placement tests.

What should I do if Outlook warm-up messages land in junk?

Slow down for a few days. Check SPF, DKIM and DMARC, reduce real outreach, send plain text, ask real recipients to reply when appropriate, and move only your own test or warm-up messages from Junk to Inbox. Never interact with real spam.

Warm this mailbox up for free

Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.

Start free