Home › Provider guides

How to Warm Up a SendGrid Sending Domain

By BobWorkUpdated 2026-10-0311 min read
SendGrid sending domain warm-up flow with DNS authentication, SMTP, receiving inbox, and ramp schedule

To warm up a SendGrid sending domain, authenticate the domain, connect SendGrid SMTP with username apikey, add a real receiving inbox, and start at 3 warm-up emails per day. If you send campaign volume before DNS, replies, and spam placement look stable, mailbox providers have little reason to trust the domain. This guide gives the records, ramp, checks, and stop rules.

SendGrid is not a mailbox. It is a sending platform, so warm-up needs two parts: SendGrid for outbound mail and a receiving inbox for replies, spam checks, and thread activity. BobWork’s free email warm-up tool supports this route with SendGrid SMTP credentials plus a receiving inbox over IMAP.

This guide is for a sending domain. If you bought a dedicated IP, you also need SendGrid’s IP warm-up process. IP warm-up does not replace domain, content, and sending-identity warm-up.

What does SendGrid verify?

SendGrid first checks whether you are allowed to send for the domain. In SendGrid, start at Settings → Sender Authentication → Authenticate Your Domain.

The current SendGrid flow asks for your DNS host, then gives records to publish. Modern setups usually use CNAME records. Publish the exact host and value SendGrid gives you. Do not rewrite hostnames, proxy CNAMEs through a CDN, or remove domain parts unless your DNS provider’s UI requires it.

CheckWhat it provesWhere to fix it
Domain authenticationSendGrid may send for your domainSendGrid Sender Authentication and DNS
DKIMMail was signed by an authorised senderSendGrid DNS CNAMEs, often s1 and s2 selectors
SPF / return-pathThe bounce identity is authorised and can alignSendGrid CNAME or SPF include, depending on setup
DMARCThe visible From domain has a policyDNS TXT record at _dmarc
SMTP authenticationYour app may relay through SendGridSendGrid API key and SMTP settings
Receiving inboxReplies and spam placement can be checkedIMAP inbox connected beside SendGrid

Mailbox providers judge more than DNS. They also look at sending consistency, bounces, complaint risk, engagement, spam-folder placement, and whether the message resembles bulk abuse.

For Gmail recipients, keep spam complaint rates under 0.1% and never above 0.3%, following Google’s sender guidelines. Treat that as a ceiling, not a target. During warm-up, complaints should be as close to zero as possible.

How do you connect SendGrid?

Use SMTP relay plus receiving inbox. SendGrid sends the warm-up email. Your connected inbox receives replies and lets the engine check whether its own warm-up mail landed in Spam.

Create the API key first. In SendGrid, go to Settings → API Keys → Create API Key. Use a key with Mail Send access. Copy it immediately, because secret keys are usually shown once.

SettingValue
SMTP hostsmtp.sendgrid.net
Port587
EncryptionSTARTTLS
Usernameapikey
PasswordYour SendGrid API key
From domainYour authenticated sending domain

The username is literal. Do not use your SendGrid login email as the SMTP username. SendGrid’s SMTP relay documentation uses apikey as the username and the API key as the password.

Next, connect a receiving inbox. SendGrid does not provide an IMAP inbox, so warm-up needs another mailbox that can receive, reply, and let the engine inspect only its own warm-up messages.

Receiving inboxConnection route
Gmail or Google WorkspaceGoogle sign-in with gmail.modify, or IMAP with an app password
Zoho MailZoho Mail API with a Self Client code, or IMAP on Mail Lite+
Lark MailIMAP with a mail-client password
Yahoo MailIMAP with an app password
iCloud MailIMAP with an app password
Other mailboxAny IMAP mailbox

Outlook and Microsoft 365 are not supported yet because Microsoft requires OAuth. Google may show an unverified-app notice because BobWork has not completed the CASA audit. If that is not acceptable for your workspace, use an IMAP app-password route where your provider allows it.

Each BobWork account warms in the shared network by default and can switch to a private pool where only your own mailboxes write to each other (at least two needed). One account can include up to 20 mailboxes. The warm-up network explainer explains how private pools differ from shared pools.

The engine only touches its own warm-up mail. It identifies messages by a hidden header, or by a known subject for Zoho API senders. Real mail is not read, moved, or answered.

Which DNS records matter?

Start in SendGrid, not in your DNS editor. SendGrid’s domain authentication guide gives the exact records for your account, domain, and security settings.

Most current SendGrid setups provide CNAME records. They often include one return-path style CNAME and two DKIM CNAMEs. DKIM commonly uses selectors such as s1 and s2.

RecordTypical hostTypical valuePurpose
Return-path / SPF CNAMEem1234.yourdomain.comSendGrid target ending in sendgrid.netLets SendGrid manage bounce identity and SPF alignment
DKIM CNAME 1s1._domainkey.yourdomain.comSendGrid DKIM targetLets receivers verify SendGrid’s DKIM signature
DKIM CNAME 2s2._domainkey.yourdomain.comSendGrid DKIM targetSupports SendGrid’s DKIM setup and rotation
DMARC TXT_dmarc.yourdomain.comv=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comPublishes your domain policy

Some legacy or manual setups may ask for an SPF TXT include. The include is typically include:sendgrid.net. Add it to your existing SPF record only if your setup needs it. Do not create two SPF TXT records at the root domain.

A combined SPF record may look like this:

v=spf1 include:sendgrid.net include:_spf.google.com ~all

That is only an example. Your real SPF depends on every sender you use. If you also send from Google Workspace, Zoho, Amazon SES, Mailgun, or another platform, include all authorised senders in one SPF record.

Check the records before warm-up starts:

Start DMARC at p=none while testing. Move toward stricter policies only after all legitimate senders pass authentication. DMARC is not a warm-up trick; it is a domain control.

DNS can take time to propagate. If SendGrid still says a record is missing, compare the full host and value character by character. Common failures are doubled domains, copied quotes, proxied CNAMEs, or records added to the wrong DNS zone.

What SendGrid warm up ramp works?

Warm-up should look like normal, human-paced sending. A sudden jump from zero to campaign volume gives mailbox providers little evidence that the new sending pattern is wanted.

BobWork’s ramp starts at 3 emails per day, adds 2 per day, and caps at 30 per day by default. The cap is editable per mailbox, up to 100, but a higher cap is not the goal for cold outreach. During active campaigns, keep warm-up around 10–15 per day.

Warm-up dayWarm-up targetWeekend targetReal cold outboundWhat to check
13/day30% of target0SendGrid SMTP works; DNS verified
25/day30% of target0DKIM passes on received mail
37/day30% of target0Replies start appearing
49/day30% of target0No authentication failures
511/day30% of target0Spam placement stays low
613/day30% of target0No repeated bounces
715/day30% of target0Domain checks remain green
817/day30% of targetVery small test onlyCheck 7-day spam rate
919/day30% of targetVery small test onlyWatch replies and spam
1021/day30% of targetKeep lowAvoid campaign jumps
1123/day30% of targetKeep lowCheck mailbox placement
1225/day30% of targetKeep lowConfirm DMARC alignment
1327/day30% of targetKeep lowReview sender errors
1429/day30% of targetExisting domains may begin carefullyReady only if metrics pass
15+30/day default30% of targetTypically 30–50/day per mailboxKeep warm-up at 10–15/day

Sends are spread across 09:00–18:00 in the mailbox’s own time zone. The scheduler decides every 15 minutes with randomness. A pair of mailboxes never writes to each other twice within 3 hours, and peers on a different domain or provider are picked twice as often. The warm-up strategy page gives the engine rules.

About 40% of received warm-up mail gets a reply. Threads end after 3 messages. Content is plain office talk: plain text, no links, no images, and first-name greetings.

If you use a dedicated IP, follow SendGrid’s own IP warm-up guidance too. SendGrid’s IP warm-up documentation covers the IP side. That schedule is separate from domain and mailbox reputation.

For a custom plan, use the warm-up schedule generator. Keep it conservative for a new domain. Add mailboxes instead of forcing one mailbox to send too much.

What blocks SendGrid warm-up?

Most failures come from configuration mistakes. Fix these before you blame reputation.

SMTP authentication fails. Use apikey as the username and the API key as the password. Check that the key has Mail Send access. If you regenerated the key, update the warm-up connection.

The From domain is not authenticated. Warm the real authenticated domain you plan to use. Do not warm example.com while SendGrid authentication is for mail.example.com, unless that is the exact sending identity you will use.

DNS records are copied incorrectly. DNS providers handle hostnames differently. Some want s1._domainkey; others want s1._domainkey.yourdomain.com. If verification fails, look for doubled endings such as yourdomain.com.yourdomain.com.

CNAME records are proxied. Authentication CNAMEs should resolve directly. If your DNS provider has proxy mode, turn it off for SendGrid authentication records.

There is no receiving inbox. A SendGrid API key can send, but it cannot check Spam or reply from an inbox. Add a real IMAP inbox for receiving and reply activity.

Volume rises before evidence improves. Time alone is not enough. BobWork marks a mailbox ready for outbound only after 14+ days warming, a 7-day spam rate of 3% or lower, and at least 30 warm-up emails received.

Spam placement crosses the warning line. Pause a mailbox for a few days above a 5% spam rate. Warm-up mail found in Spam is moved to Inbox, marked read, labelled Warm-up, and archived after 24 hours. The free pool does this automatically for its own warm-up messages.

Campaign content is too different. If warm-up is plain text but your campaign starts with heavy HTML, tracking links, images, and aggressive claims, the signal does not carry cleanly. Keep early campaigns simple. The guide on why emails go to spam lists the usual causes.

You confuse IP and domain readiness. A warmed dedicated IP does not make a new domain trusted. A warmed domain can still suffer if the dedicated IP jumps too quickly. Treat them as separate risk surfaces.

What should you do now?

Use this checklist before you send real volume through SendGrid.

StepActionHow to verify
1Authenticate the domain in SendGridSendGrid shows the domain as verified
2Publish SendGrid CNAMEs exactlyDNS lookup returns the SendGrid targets
3Check SPFThe SPF checker shows one valid SPF record
4Check DKIM selectorsThe DKIM checker finds s1 and s2, or the selectors SendGrid gave you
5Add DMARCThe DMARC checker finds _dmarc.yourdomain.com
6Create a SendGrid API keyKey has Mail Send access
7Configure SMTPHost smtp.sendgrid.net, port 587, username apikey, password is API key
8Connect a receiving inboxIMAP or provider API connection succeeds
9Start warm-up at 3/dayFirst warm-up messages send and receive correctly
10Watch spam placement7-day spam rate stays at or below 3% before outbound
11Keep weekends lowerWeekend sending runs at about 30% of weekday volume
12Hold campaign volume downReal outreach stays around 30–50/day per mailbox after readiness

Do not skip verification because SendGrid accepted the SMTP send. SMTP acceptance only means SendGrid took the message. It does not prove the recipient trusted it, placed it in Inbox, or saw aligned authentication.

When is SendGrid ready?

A SendGrid sending domain is ready when the setup and behaviour both look stable. Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain.

In BobWork, “ready for outbound” means all three conditions are true: 14+ days warming, 7-day spam rate at or below 3%, and at least 30 warm-up emails received. The health score is Healthy at 85 or higher, Watch from 60 to 84, At risk below 60, and Blocked if login or permission fails.

Keep warm-up running during campaigns, but reduce it to maintenance volume. A practical range is 10–15 warm-up emails per day while the mailbox sends real outreach. For cold outreach, keep volume around 30–50 per day per mailbox. Add mailboxes rather than pushing one sender harder.

If you need more context on timing, read the day-by-day warm-up timeline. It explains what should happen in the first two weeks and when to wait.

You can set this up free with BobWork Email Warm-up at emailwarmup.bobwork.ai. Use SendGrid for SMTP sending, connect a receiving inbox, verify SPF, DKIM, and DMARC, then let the warm-up build traffic slowly before your campaign starts.

Frequently asked questions

How do I warm up a SendGrid domain?

Authenticate the domain in SendGrid, publish SPF, DKIM, and DMARC, connect SendGrid SMTP with username apikey, add a receiving inbox, then start low. A safe warm-up starts at 3 emails per day, rises gradually, and waits for low spam placement before real outreach.

Is SendGrid IP warm-up the same as email warm-up?

No. SendGrid IP warm-up is for dedicated IP sending volume. Email warm-up builds sending-domain and mailbox reputation through normal-looking sends, replies, and inbox recovery. If you use a dedicated IP, do both.

What username do I use for SendGrid SMTP?

Use apikey as the SMTP username. Use the actual SendGrid API key as the SMTP password. The host is smtp.sendgrid.net. Port 587 with STARTTLS is the usual choice for authenticated SMTP sending.

Do I need a receiving inbox with SendGrid?

Yes. SendGrid sends email, but warm-up also needs replies and spam-folder checks. Connect a receiving inbox over IMAP, such as Gmail, Google Workspace, Zoho, Lark, Yahoo, iCloud, or another IMAP mailbox.

Which DNS records does SendGrid need?

SendGrid domain authentication typically gives CNAME records for DKIM and return-path/SPF handling. DKIM commonly uses s1 and s2 selectors. You should also publish a DMARC TXT record at _dmarc.yourdomain.com.

How long does SendGrid warm-up take?

Use at least 14 days for an existing domain. Use 3–4 weeks for a new domain. Do not judge readiness from time alone; check DNS, spam placement, replies, and complaint risk before increasing real sending.

Can I warm up SendGrid on a shared IP?

Yes, but you cannot control the shared IP’s warm-up schedule. Focus on your domain authentication, sending identity, receiving inbox, low volume, and spam placement. Dedicated IP users should also follow SendGrid’s own IP warm-up guidance.

Warm this mailbox up for free

Connect it in a minute. It warms on the shared network or in your own private pool, ramps 3 to 30 a day, and the dashboard tells you when you are ready.

Start free