How to Warm Up a SendGrid Sending Domain
To warm up a SendGrid sending domain, authenticate the domain, connect SendGrid SMTP with username apikey, add a real receiving inbox, and start at 3 warm-up emails per day. If you send campaign volume before DNS, replies, and spam placement look stable, mailbox providers have little reason to trust the domain. This guide gives the records, ramp, checks, and stop rules.
SendGrid is not a mailbox. It is a sending platform, so warm-up needs two parts: SendGrid for outbound mail and a receiving inbox for replies, spam checks, and thread activity. BobWork’s free email warm-up tool supports this route with SendGrid SMTP credentials plus a receiving inbox over IMAP.
This guide is for a sending domain. If you bought a dedicated IP, you also need SendGrid’s IP warm-up process. IP warm-up does not replace domain, content, and sending-identity warm-up.
What does SendGrid verify?
SendGrid first checks whether you are allowed to send for the domain. In SendGrid, start at Settings → Sender Authentication → Authenticate Your Domain.
The current SendGrid flow asks for your DNS host, then gives records to publish. Modern setups usually use CNAME records. Publish the exact host and value SendGrid gives you. Do not rewrite hostnames, proxy CNAMEs through a CDN, or remove domain parts unless your DNS provider’s UI requires it.
| Check | What it proves | Where to fix it |
|---|---|---|
| Domain authentication | SendGrid may send for your domain | SendGrid Sender Authentication and DNS |
| DKIM | Mail was signed by an authorised sender | SendGrid DNS CNAMEs, often s1 and s2 selectors |
| SPF / return-path | The bounce identity is authorised and can align | SendGrid CNAME or SPF include, depending on setup |
| DMARC | The visible From domain has a policy | DNS TXT record at _dmarc |
| SMTP authentication | Your app may relay through SendGrid | SendGrid API key and SMTP settings |
| Receiving inbox | Replies and spam placement can be checked | IMAP inbox connected beside SendGrid |
Mailbox providers judge more than DNS. They also look at sending consistency, bounces, complaint risk, engagement, spam-folder placement, and whether the message resembles bulk abuse.
For Gmail recipients, keep spam complaint rates under 0.1% and never above 0.3%, following Google’s sender guidelines. Treat that as a ceiling, not a target. During warm-up, complaints should be as close to zero as possible.
How do you connect SendGrid?
Use SMTP relay plus receiving inbox. SendGrid sends the warm-up email. Your connected inbox receives replies and lets the engine check whether its own warm-up mail landed in Spam.
Create the API key first. In SendGrid, go to Settings → API Keys → Create API Key. Use a key with Mail Send access. Copy it immediately, because secret keys are usually shown once.
| Setting | Value |
|---|---|
| SMTP host | smtp.sendgrid.net |
| Port | 587 |
| Encryption | STARTTLS |
| Username | apikey |
| Password | Your SendGrid API key |
| From domain | Your authenticated sending domain |
The username is literal. Do not use your SendGrid login email as the SMTP username. SendGrid’s SMTP relay documentation uses apikey as the username and the API key as the password.
Next, connect a receiving inbox. SendGrid does not provide an IMAP inbox, so warm-up needs another mailbox that can receive, reply, and let the engine inspect only its own warm-up messages.
| Receiving inbox | Connection route |
|---|---|
| Gmail or Google Workspace | Google sign-in with gmail.modify, or IMAP with an app password |
| Zoho Mail | Zoho Mail API with a Self Client code, or IMAP on Mail Lite+ |
| Lark Mail | IMAP with a mail-client password |
| Yahoo Mail | IMAP with an app password |
| iCloud Mail | IMAP with an app password |
| Other mailbox | Any IMAP mailbox |
Outlook and Microsoft 365 are not supported yet because Microsoft requires OAuth. Google may show an unverified-app notice because BobWork has not completed the CASA audit. If that is not acceptable for your workspace, use an IMAP app-password route where your provider allows it.
Each BobWork account warms in the shared network by default and can switch to a private pool where only your own mailboxes write to each other (at least two needed). One account can include up to 20 mailboxes. The warm-up network explainer explains how private pools differ from shared pools.
The engine only touches its own warm-up mail. It identifies messages by a hidden header, or by a known subject for Zoho API senders. Real mail is not read, moved, or answered.
Which DNS records matter?
Start in SendGrid, not in your DNS editor. SendGrid’s domain authentication guide gives the exact records for your account, domain, and security settings.
Most current SendGrid setups provide CNAME records. They often include one return-path style CNAME and two DKIM CNAMEs. DKIM commonly uses selectors such as s1 and s2.
| Record | Typical host | Typical value | Purpose |
|---|---|---|---|
| Return-path / SPF CNAME | em1234.yourdomain.com | SendGrid target ending in sendgrid.net | Lets SendGrid manage bounce identity and SPF alignment |
| DKIM CNAME 1 | s1._domainkey.yourdomain.com | SendGrid DKIM target | Lets receivers verify SendGrid’s DKIM signature |
| DKIM CNAME 2 | s2._domainkey.yourdomain.com | SendGrid DKIM target | Supports SendGrid’s DKIM setup and rotation |
| DMARC TXT | _dmarc.yourdomain.com | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com | Publishes your domain policy |
Some legacy or manual setups may ask for an SPF TXT include. The include is typically include:sendgrid.net. Add it to your existing SPF record only if your setup needs it. Do not create two SPF TXT records at the root domain.
A combined SPF record may look like this:
v=spf1 include:sendgrid.net include:_spf.google.com ~all
That is only an example. Your real SPF depends on every sender you use. If you also send from Google Workspace, Zoho, Amazon SES, Mailgun, or another platform, include all authorised senders in one SPF record.
Check the records before warm-up starts:
- Use the SPF checker to confirm one valid SPF record.
- Use the DKIM checker for
s1ands2, or the selectors SendGrid gave you. - Use the DMARC checker to confirm
_dmarcexists.
Start DMARC at p=none while testing. Move toward stricter policies only after all legitimate senders pass authentication. DMARC is not a warm-up trick; it is a domain control.
DNS can take time to propagate. If SendGrid still says a record is missing, compare the full host and value character by character. Common failures are doubled domains, copied quotes, proxied CNAMEs, or records added to the wrong DNS zone.
What SendGrid warm up ramp works?
Warm-up should look like normal, human-paced sending. A sudden jump from zero to campaign volume gives mailbox providers little evidence that the new sending pattern is wanted.
BobWork’s ramp starts at 3 emails per day, adds 2 per day, and caps at 30 per day by default. The cap is editable per mailbox, up to 100, but a higher cap is not the goal for cold outreach. During active campaigns, keep warm-up around 10–15 per day.
| Warm-up day | Warm-up target | Weekend target | Real cold outbound | What to check |
|---|---|---|---|---|
| 1 | 3/day | 30% of target | 0 | SendGrid SMTP works; DNS verified |
| 2 | 5/day | 30% of target | 0 | DKIM passes on received mail |
| 3 | 7/day | 30% of target | 0 | Replies start appearing |
| 4 | 9/day | 30% of target | 0 | No authentication failures |
| 5 | 11/day | 30% of target | 0 | Spam placement stays low |
| 6 | 13/day | 30% of target | 0 | No repeated bounces |
| 7 | 15/day | 30% of target | 0 | Domain checks remain green |
| 8 | 17/day | 30% of target | Very small test only | Check 7-day spam rate |
| 9 | 19/day | 30% of target | Very small test only | Watch replies and spam |
| 10 | 21/day | 30% of target | Keep low | Avoid campaign jumps |
| 11 | 23/day | 30% of target | Keep low | Check mailbox placement |
| 12 | 25/day | 30% of target | Keep low | Confirm DMARC alignment |
| 13 | 27/day | 30% of target | Keep low | Review sender errors |
| 14 | 29/day | 30% of target | Existing domains may begin carefully | Ready only if metrics pass |
| 15+ | 30/day default | 30% of target | Typically 30–50/day per mailbox | Keep warm-up at 10–15/day |
Sends are spread across 09:00–18:00 in the mailbox’s own time zone. The scheduler decides every 15 minutes with randomness. A pair of mailboxes never writes to each other twice within 3 hours, and peers on a different domain or provider are picked twice as often. The warm-up strategy page gives the engine rules.
About 40% of received warm-up mail gets a reply. Threads end after 3 messages. Content is plain office talk: plain text, no links, no images, and first-name greetings.
If you use a dedicated IP, follow SendGrid’s own IP warm-up guidance too. SendGrid’s IP warm-up documentation covers the IP side. That schedule is separate from domain and mailbox reputation.
For a custom plan, use the warm-up schedule generator. Keep it conservative for a new domain. Add mailboxes instead of forcing one mailbox to send too much.
What blocks SendGrid warm-up?
Most failures come from configuration mistakes. Fix these before you blame reputation.
SMTP authentication fails. Use apikey as the username and the API key as the password. Check that the key has Mail Send access. If you regenerated the key, update the warm-up connection.
The From domain is not authenticated. Warm the real authenticated domain you plan to use. Do not warm example.com while SendGrid authentication is for mail.example.com, unless that is the exact sending identity you will use.
DNS records are copied incorrectly. DNS providers handle hostnames differently. Some want s1._domainkey; others want s1._domainkey.yourdomain.com. If verification fails, look for doubled endings such as yourdomain.com.yourdomain.com.
CNAME records are proxied. Authentication CNAMEs should resolve directly. If your DNS provider has proxy mode, turn it off for SendGrid authentication records.
There is no receiving inbox. A SendGrid API key can send, but it cannot check Spam or reply from an inbox. Add a real IMAP inbox for receiving and reply activity.
Volume rises before evidence improves. Time alone is not enough. BobWork marks a mailbox ready for outbound only after 14+ days warming, a 7-day spam rate of 3% or lower, and at least 30 warm-up emails received.
Spam placement crosses the warning line. Pause a mailbox for a few days above a 5% spam rate. Warm-up mail found in Spam is moved to Inbox, marked read, labelled Warm-up, and archived after 24 hours. The free pool does this automatically for its own warm-up messages.
Campaign content is too different. If warm-up is plain text but your campaign starts with heavy HTML, tracking links, images, and aggressive claims, the signal does not carry cleanly. Keep early campaigns simple. The guide on why emails go to spam lists the usual causes.
You confuse IP and domain readiness. A warmed dedicated IP does not make a new domain trusted. A warmed domain can still suffer if the dedicated IP jumps too quickly. Treat them as separate risk surfaces.
What should you do now?
Use this checklist before you send real volume through SendGrid.
| Step | Action | How to verify |
|---|---|---|
| 1 | Authenticate the domain in SendGrid | SendGrid shows the domain as verified |
| 2 | Publish SendGrid CNAMEs exactly | DNS lookup returns the SendGrid targets |
| 3 | Check SPF | The SPF checker shows one valid SPF record |
| 4 | Check DKIM selectors | The DKIM checker finds s1 and s2, or the selectors SendGrid gave you |
| 5 | Add DMARC | The DMARC checker finds _dmarc.yourdomain.com |
| 6 | Create a SendGrid API key | Key has Mail Send access |
| 7 | Configure SMTP | Host smtp.sendgrid.net, port 587, username apikey, password is API key |
| 8 | Connect a receiving inbox | IMAP or provider API connection succeeds |
| 9 | Start warm-up at 3/day | First warm-up messages send and receive correctly |
| 10 | Watch spam placement | 7-day spam rate stays at or below 3% before outbound |
| 11 | Keep weekends lower | Weekend sending runs at about 30% of weekday volume |
| 12 | Hold campaign volume down | Real outreach stays around 30–50/day per mailbox after readiness |
Do not skip verification because SendGrid accepted the SMTP send. SMTP acceptance only means SendGrid took the message. It does not prove the recipient trusted it, placed it in Inbox, or saw aligned authentication.
When is SendGrid ready?
A SendGrid sending domain is ready when the setup and behaviour both look stable. Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain.
In BobWork, “ready for outbound” means all three conditions are true: 14+ days warming, 7-day spam rate at or below 3%, and at least 30 warm-up emails received. The health score is Healthy at 85 or higher, Watch from 60 to 84, At risk below 60, and Blocked if login or permission fails.
Keep warm-up running during campaigns, but reduce it to maintenance volume. A practical range is 10–15 warm-up emails per day while the mailbox sends real outreach. For cold outreach, keep volume around 30–50 per day per mailbox. Add mailboxes rather than pushing one sender harder.
If you need more context on timing, read the day-by-day warm-up timeline. It explains what should happen in the first two weeks and when to wait.
You can set this up free with BobWork Email Warm-up at emailwarmup.bobwork.ai. Use SendGrid for SMTP sending, connect a receiving inbox, verify SPF, DKIM, and DMARC, then let the warm-up build traffic slowly before your campaign starts.
Frequently asked questions
How do I warm up a SendGrid domain?
Authenticate the domain in SendGrid, publish SPF, DKIM, and DMARC, connect SendGrid SMTP with username apikey, add a receiving inbox, then start low. A safe warm-up starts at 3 emails per day, rises gradually, and waits for low spam placement before real outreach.
Is SendGrid IP warm-up the same as email warm-up?
No. SendGrid IP warm-up is for dedicated IP sending volume. Email warm-up builds sending-domain and mailbox reputation through normal-looking sends, replies, and inbox recovery. If you use a dedicated IP, do both.
What username do I use for SendGrid SMTP?
Use apikey as the SMTP username. Use the actual SendGrid API key as the SMTP password. The host is smtp.sendgrid.net. Port 587 with STARTTLS is the usual choice for authenticated SMTP sending.
Do I need a receiving inbox with SendGrid?
Yes. SendGrid sends email, but warm-up also needs replies and spam-folder checks. Connect a receiving inbox over IMAP, such as Gmail, Google Workspace, Zoho, Lark, Yahoo, iCloud, or another IMAP mailbox.
Which DNS records does SendGrid need?
SendGrid domain authentication typically gives CNAME records for DKIM and return-path/SPF handling. DKIM commonly uses s1 and s2 selectors. You should also publish a DMARC TXT record at _dmarc.yourdomain.com.
How long does SendGrid warm-up take?
Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Do not judge readiness from time alone; check DNS, spam placement, replies, and complaint risk before increasing real sending.
Can I warm up SendGrid on a shared IP?
Yes, but you cannot control the shared IP’s warm-up schedule. Focus on your domain authentication, sending identity, receiving inbox, low volume, and spam placement. Dedicated IP users should also follow SendGrid’s own IP warm-up guidance.
Warm this mailbox up for free
Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.