Domain Infrastructure
Overview
Cold email deliverability depends entirely on infrastructure decisions made
before the first email is sent. The domain names, mailbox providers, DNS
configuration, and rotation strategy form the foundation on which all
outbound rests. A poor infrastructure setup will produce poor deliverability
regardless of copy quality or targeting precision.
This skill produces a complete domain infrastructure plan: which secondary
domains to register, how to provision mailboxes across providers (Google
Workspace, Microsoft 365, Zoho), DNS authentication configuration for each
domain, inbox rotation schedules, and a monitoring framework to detect
degradation before it impacts campaigns.
The non-obvious rule: never send cold email from your primary business domain.
Your primary domain carries your transactional email (password resets,
invoices, customer notifications, support tickets) and your corporate email
(sales, support, executives). A reputation hit on the primary domain from
cold email complaints or bounces takes down ALL of those functions
simultaneously. Cold email must operate on entirely separate, isolated
infrastructure.
When to Use
- User says "set up domains for cold email" or "buy sending domains" →
activate this skill
- User asks "how many domains do I need" or "how many mailboxes per domain" →
activate this skill
- User wants to "provision mailboxes for outreach" or "set up Google
Workspace for outbound" → activate this skill
- User mentions "DNS configuration for email," "inbox rotation," or
"primary domain isolation" → activate this skill
- User asks "should I use Google or Microsoft for cold email" or
"Zoho vs Gmail for outreach" → activate this skill
- User wants to "scale sending capacity" or "add more mailboxes" →
activate this skill
Do NOT use for:
- Configuring SPF/DKIM/DMARC records → use
email-deliverability
(domain-infrastructure tells you WHICH domains and mailboxes;
email-deliverability configures authentication ON them)
- Selecting a sending platform → use
sending-platforms
- Designing email sequences → use
cold-email-strategy
Authoritative Foundations
This skill draws from the following established methodologies:
Google Workspace Admin Best Practices — Documentation on mailbox
provisioning, sending limits, and security configuration. Google Workspace
is the most common cold email mailbox provider due to deliverability
reputation and API access for sending platforms.
Microsoft 365 Exchange Online — Admin documentation on mailbox
provisioning, outbound spam policies, and sending limits. M365 is second
most common. Higher reputation barrier for new tenants but stronger
deliverability once established.
Zoho Mail Admin — Alternative provider for cost-conscious setups.
Lower per-mailbox cost but lower default sending limits and less API
maturity for sending platform integration.
ICANN / Domain Registration Best Practices — Guidelines on domain
registration, WHOIS privacy, and domain age considerations. Domain age is
a reputation factor — newly registered domains (under 90 days) face higher
scrutiny from inbox providers.
Validity / Return Path — Sender Score — Domain-level reputation scoring
that informs domain rotation decisions. A domain with a Sender Score below
70 should be rotated out of active sending.
Eric Nowoslawski — Growth Engine X. Capacity planning for scale: 2
inboxes per domain (contain blast radius), 1:1 backup inboxes matching
active send capacity, 50% spare warming at all times. Scale math: target
daily volume ÷ 30 sends/inbox ÷ 2 inboxes/domain = domains needed. Pair with
email-deliverability for warmup and monitoring. Playbook →
../cold-email-strategy/references/eric-nowoslawski-outbound.md.
Prerequisites
- Access to a domain registrar (Namecheap, GoDaddy, Google Domains, Cloudflare
Registrar, Porkbun, etc.)
- Budget for domains ($10-15/year per domain) and mailboxes (Google Workspace
~$6-18/user/month, M365 ~$6-22/user/month, Zoho ~$1-4/user/month)
- DNS management access (usually through the registrar or Cloudflare)
- Optional: LeadMagic API key for pre-send email verification to integrate
with sending infrastructure
- Reference files:
references/deliverability-primer.md for sending limits
and domain isolation best practices
Step-by-Step Process
Phase 1: Intake
Gather the following from the user. Ask all questions at once:
Primary business domain: What is the domain used for corporate email,
website, and transactional email? This will be left untouched — we only
configure secondary domains.
Target sending volume: How many total emails per day do you need to
send? This determines how many mailboxes and domains are needed.
Budget: What's the monthly budget for domains and mailboxes? This
determines provider choice and scale.
Current setup: Any existing secondary domains or mailboxes already
in use? If yes, how old are they, what's their sending history?
Preferred providers: Any existing relationship with Google Workspace,
M365, or Zoho? Do you prefer one over the others?
Domain registrar: Which registrar do you use? Do you use Cloudflare
for DNS? These affect how DNS records are managed.
Sending platform: Which platform will send the emails (Smartlead,
Instantly, Salesforge, Apollo)? This affects mailbox integration
requirements.
Warmup plan: Will you warm up manually, use the sending platform's
warmup, or both? This affects the provisioning timeline.
Geographic requirements: Any data residency requirements (GDPR
in EU, data localization laws)? This affects provider and region selection.
Phase 2: Research
Before provisioning, research the domain landscape:
Primary domain reputation check: Verify the primary domain has a clean
reputation. Even though we won't send cold from it, a damaged primary
domain reputation can affect secondary domains if they're too closely
connected (same WHOIS, same IP, same brand name in domain). Check:
- Google Postmaster Tools for the primary domain
- MXToolbox blacklist check for the primary domain
- Any existing SPF/DKIM/DMARC configuration
Domain naming strategy: Research available domain names. The domain
name DOES matter for deliverability. Avoid:
- Exact match of primary brand name (too obvious, links to primary domain)
- Hyphenated domains (associated with spam)
- Very long domains (over 20 characters)
- ccTLDs for non-geographic targeting (.co, .io are fine; .tk, .ml are not)
- Domains registered in the last 24 hours (need 2+ weeks of age before
sending, ideally 90+ days)
Good naming patterns:
[brand][variant].com — e.g., getbrand.com, brandhq.com, trybrand.com
[brand][descriptor].com — e.g., brandops.com, brandteam.com
- Generic-but-professional:
[industry][term].com — e.g., saaescalate.com
Provider pricing comparison (current market):
- Google Workspace Business Starter: ~$7.20/user/month (annual)
- Google Workspace Business Standard: ~$14.40/user/month (annual)
- Microsoft 365 Business Basic: ~$6.00/user/month (annual)
- Microsoft 365 Business Standard: ~$12.50/user/month (annual)
- Zoho Mail Lite: ~$1.00/user/month (annual)
- Zoho Mail Premium: ~$4.00/user/month (annual)
Note: prices subject to change. Verify current pricing before quoting.
Phase 3: Execution
Step 1: Calculate Capacity Requirements
Determine how many domains and mailboxes are needed:
Base formula: mailboxes_needed = ceil(daily_target_volume / 40)
Explanation: 40 emails/day per mailbox is the recommended safe volume for
sustained sending. You can push to 50 but it leaves no headroom. Using 40
allows for reply handling and minor volume spikes without crossing the limit.
Domain allocation:
- 3-5 sending domains recommended for redundancy
- 2-3 mailboxes per domain maximum
- No domain should carry more than 3 mailboxes — if one mailbox triggers a
spam complaint, the domain reputation affects all mailboxes on that domain.
Limiting to 2-3 per domain contains the blast radius.
Examples:
- 80 emails/day: 2 mailboxes, 1-2 domains
- 200 emails/day: 5 mailboxes, 2-3 domains
- 400 emails/day: 10 mailboxes, 3-5 domains
- 800 emails/day: 20 mailboxes, 4-5+ domains (consider dedicated sending IPs
at this scale)
Step 2: Domain Registration
For each domain:
- Register through your preferred registrar.
- Enable WHOIS privacy protection (free on most registrars). Public WHOIS
with matching registrant information across domains links them together,
which inbox providers can detect.
- Set auto-renew. A forgotten renewal that lets a domain lapse will break
sequences and potentially create a deliverability event.
- Add to DNS management (Cloudflare is recommended for fast DNS propagation
and API access).
- If using Cloudflare: enable DNSSEC for additional trust signaling.
- Document: domain name, registrar, registration date, renewal date, DNS
provider, nameservers.
Domain age note: If possible, register domains at least 2 weeks before you
need to send. 90+ days of age before cold sending is ideal. A domain
registered today and sending cold email tomorrow is a strong spam signal.
Step 3: Mailbox Provisioning (Google Workspace)
For each mailbox on a Google Workspace domain:
Sign up for Google Workspace for the domain. If you already have a
Workspace tenant on one secondary domain, you can add additional domains
as domain aliases (cheaper) or separate tenants (better isolation).
Create user accounts for each mailbox:
- Use professional naming:
[firstname]@[domain], [firstinitial][lastname]@[domain],
or role-based: outreach1@[domain], hello@[domain]
- Never use names like
email1@, send1@, cold1@ — these are spam
signals detected by inbox providers
- Set up a professional display name and profile photo for each account
- Configure signature: first name only, no title/company logo
Configure security:
- Enable 2FA on all accounts (platform integrations use app passwords or
OAuth, not raw passwords)
- Create app passwords for each mailbox that the sending platform will use
- Disable IMAP/POP if not needed (reduce attack surface)
- Set up forwarding to a monitoring inbox for reply handling
Google Workspace-specific sending considerations:
- Google Workspace has a sending limit of 2,000 recipients per day per
account, but cold email reputation management requires staying at 30-50
- Google enforces the limit based on the account's reputation, not just
the raw number
- New accounts (under 30 days) face stricter rate limiting
Document for each mailbox: email address, display name, app password
(store securely), login email, 2FA method, forwarding configuration.
Step 3b: Mailbox Provisioning (Microsoft 365)
For each mailbox on an M365 domain:
- Sign up for Microsoft 365 Business Basic for the domain.
- Create user accounts following the same naming conventions as Google.
- Configure security: MFA, app passwords for platform integration.
- M365-specific considerations:
- Microsoft's outbound spam filtering is aggressive by default — new
tenants may be restricted to minimal outbound volume
- The "Restrict sending to internal recipients only" policy on new tenants
must be explicitly disabled
- Microsoft has a Recipient Rate Limit of 10,000 recipients/day, but
practical cold limits are same as Google (30-50)
- Outlook deliverability is often better for B2B reaching Microsoft-heavy
organizations
Step 3c: Mailbox Provisioning (Zoho Mail)
For each mailbox on a Zoho domain:
- Sign up for Zoho Mail (Lite or Premium plan).
- Create user accounts.
- Zoho-specific considerations:
- Lower per-mailbox cost ($1-4/month vs $6-18)
- Lower default sending limits: 250-500/day depending on plan, but cold
email requires same 30-50/day discipline
- Less mature API for sending platform integration — confirm your platform
supports Zoho before committing
- Good for budget-constrained setups or supplementary mailboxes
Step 4: DNS Configuration per Domain
For each domain, before sending a single email:
A. SPF record: Create a TXT record at the root that authorizes the
mailbox provider (Google, M365, Zoho) AND the sending platform:
v=spf1 include:_spf.google.com include:_spf.[sendingplatform].com -all
(Adjust includes based on provider and platform.)
B. DKIM: Generate DKIM keys through the mailbox provider's admin console
and add the DNS records. Use a unique selector per provider:
- Google:
google._domainkey
- M365:
selector1._domainkey and selector2._domainkey
- Zoho:
zoho._domainkey
C. DMARC: Add the DMARC record at _dmarc.[domain]:
v=DMARC1; p=none; rua=mailto:dmarc@[yourdomain].com; fo=1;
(Monitoring mode initially; progress to reject after warmup.)
D. Custom tracking domain (for sending platforms): If using Smartlead,
Instantly, or similar platforms, set up a CNAME record for click/open
tracking:
track.[domain] CNAME [platform-tracking-endpoint]
This prevents the platform's shared tracking domain from being flagged
and dragging down your deliverability.
E. Verify DNS propagation: After adding records, verify with:
dig TXT [domain] for SPF
dig TXT google._domainkey.[domain] for DKIM
dig TXT _dmarc.[domain] for DMARC
- MXToolbox or similar for comprehensive verification
Step 5: Design Inbox Rotation
Inbox rotation distributes sending across mailboxes to maintain consistent
volume without any single mailbox exceeding limits:
Daily rotation pattern (example for 5 mailboxes sending 200/day):
- Mailbox 1: 40 sends (prospects 1-40)
- Mailbox 2: 40 sends (prospects 41-80)
- Mailbox 3: 40 sends (prospects 81-120)
- Mailbox 4: 40 sends (prospects 121-160)
- Mailbox 5: 40 sends (prospects 161-200)
Rotation rules:
- Each prospect is assigned to a single mailbox for the entire sequence.
Do not rotate a prospect across mailboxes — this breaks thread context
and looks like a deliverability trick to inbox providers.
- Even distribution: each mailbox gets the same daily volume (±10%).
- Time zone alignment: if possible, assign prospects to mailboxes in their
time zone so sends happen during the prospect's business hours.
- Reputation-based redistribution: if one mailbox shows degraded engagement,
temporarily redirect a portion of its volume to other mailboxes while
investigating.
Step 6: Set Up Monitoring
Before sending, set up monitoring for every domain and mailbox:
Google Postmaster Tools: Register every domain. This is free and
provides the best deliverability data for Gmail recipients (~45% of B2B).
Microsoft SNDS: Register every sending IP. Covers Outlook/Hotmail
recipients (~20% of B2B).
MXToolbox monitoring: Set up automated blacklist checks for every
domain. Free tier allows weekly monitoring.
Sending platform deliverability dashboard: Configure in-platform
deliverability monitoring (Smartlead's Deliverability Tab, Instantly's
Health Score, etc.).
Internal tracking sheet: Create a spreadsheet tracking per-mailbox
and per-domain metrics: sends, opens, replies, bounces, complaints,
unsubscribes. Review weekly.
Phase 4: Delivery
Deliver a complete infrastructure plan:
Domain Inventory: All registered domains with registration dates,
registrars, DNS providers, and renewal dates.
Mailbox Inventory: Every mailbox with email address, provider, plan,
sending limit, and integration status.
DNS Configuration Map: Per-domain DNS records (SPF, DKIM, DMARC, MX,
tracking CNAME) in copy-paste format for the DNS console.
Rotation Schedule: Daily sending allocation per mailbox with time
zone assignments.
Scaling Plan: How to add more capacity when needed (additional
mailboxes within existing domains vs new domains).
Cost Projection: Monthly and annual cost breakdown by provider.
Output Format
# Domain Infrastructure Plan for [Company]
## Output Artifact Details
Use `references/output-artifacts.md` for the full capacity calculation, domain inventory, mailbox inventory, DNS examples, inbox rotation schedule, monitoring configuration, scaling plan, and cost summary. The main output must summarize final counts, DNS records, monitoring thresholds, owner, and rollout dates.
## Quality Check
Before delivering, verify:
- [ ] Is the primary business domain completely excluded from cold sending?
- [ ] Are 3-5 secondary domains planned (or scaled proportionally to volume)?
- [ ] Are there 2-3 mailboxes per domain maximum?
- [ ] Is the daily volume per mailbox set to 30-50 (recommended 40)?
- [ ] Are domain names professional and not spam-signaling?
- [ ] Is WHOIS privacy enabled on all domains?
- [ ] Are DNS records provided in copy-paste format for each domain?
- [ ] Does DMARC start in monitoring mode (`p=none`)?
- [ ] Is there a custom tracking domain configured per domain?
- [ ] Is Google Postmaster Tools registration included?
- [ ] Is blacklist monitoring set up?
- [ ] Is the cost projection complete and realistic?
- [ ] Is the scaling plan defined with trigger conditions?
- [ ] Are 2FA and app passwords configured for all mailboxes?
## Common Pitfalls
1. **Sending from the primary domain.** This is the cardinal sin of domain
infrastructure. A single spam complaint on the primary domain takes down
all corporate and transactional email. Never, under any circumstances,
send cold email from your primary domain.
2. **Too few domains.** Running all mailboxes on a single domain means one
reputation event kills all sending capacity. 3 domains is the minimum
for production outbound. 5 is better for volume above 300/day.
3. **Too many mailboxes per domain.** When one mailbox on a domain gets
flagged for spam, the domain reputation drops — affecting every mailbox
on that domain. Limiting to 2-3 per domain contains the blast radius.
4. **Spammy mailbox names.** `email-marketing@`, `sales-outreach@`, `cold1@`
— inbox providers flag these patterns. Use professional,
human-looking email addresses.
5. **No WHOIS privacy.** Matching WHOIS registrant info across domains
creates an easily identifiable pattern that inbox providers can use to
link your domains. A reputation hit on one domain can cascade.
6. **Sending from brand-new domains.** A domain registered yesterday and
sending cold email today is a strong spam signal. Inbox providers track
domain age. 2 weeks minimum before sending, 90+ days ideal.
7. **No tracking domain customization.** Using the sending platform's
default tracking domain puts your deliverability at the mercy of every
other user on that shared domain. A spammer on the shared domain
damages your reputation.
8. **No monitoring before sending.** Setting up domains and mailboxes without
simultaneously setting up Google Postmaster Tools, SNDS, and blacklist
monitoring means you're flying blind. You won't know deliverability is
broken until open rates collapse.
9. **Rotating prospects across mailboxes mid-sequence.** Moving a prospect
from mailbox A to mailbox B in the middle of a sequence breaks thread
context, resets engagement history, and looks suspicious. Each prospect
stays with one mailbox for the entire sequence.
10. **Ignoring DNS propagation time.** DNS changes can take up to 48 hours
to propagate globally. Always verify DNS records after 48 hours. Never
start sending immediately after adding DNS records.
## Provider Decision Matrix
Use `references/provider-decision-matrix.md` when the task requires provider comparison. Keep the primary output focused on the chosen provider, DNS records, inbox allocation, and monitoring plan.
## Execution Artifacts
- `references/framework-notes.md` — Framework index and authority routing
- `templates/output-template.md` — Deliverable shell for agent output
- `scripts/check-output.py` — Lightweight deliverable validator
- `../cold-email-strategy/references/eric-nowoslawski-outbound.md` — Inbox/domain ratio, backup capacity, scale math (Eric Nowoslawski)
- `references/deliverability-primer.md` — Deliverability fundamentals
- `references/output-artifacts.md` — Extended output tables and inventories
- `references/provider-decision-matrix.md` — Mailbox provider comparison
## Related Skills
- `email-deliverability` — adjacent workflow to use before or after this skill
- `sending-platforms` — adjacent workflow to use before or after this skill
- `cold-email-strategy` — adjacent workflow to use before or after this skill
- `technical-seo` — adjacent workflow to use before or after this skill
1---2name: domain-infrastructure3description: Designs and provisions the domain and mailbox infrastructure for cold email outreach: secondary domains, mailbox setup (Google Workspace, M365, Zoho), DNS authentication records, inbox rotation, and primary domain isolation. Use when the user asks to set up sending domains, provision mailboxes, configure DNS for cold email, or plan domain rotation for outbound. Activates on phrases like "set up sending domains," "buy secondary domains," "provision mailboxes," "configure email for cold outreach," or "domain rotation plan."4license: MIT5---67# Domain Infrastructure89## Overview1011Cold email deliverability depends entirely on infrastructure decisions made12before the first email is sent. The domain names, mailbox providers, DNS13configuration, and rotation strategy form the foundation on which all14outbound rests. A poor infrastructure setup will produce poor deliverability15regardless of copy quality or targeting precision.1617This skill produces a complete domain infrastructure plan: which secondary18domains to register, how to provision mailboxes across providers (Google19Workspace, Microsoft 365, Zoho), DNS authentication configuration for each20domain, inbox rotation schedules, and a monitoring framework to detect21degradation before it impacts campaigns.2223The non-obvious rule: never send cold email from your primary business domain.24Your primary domain carries your transactional email (password resets,25invoices, customer notifications, support tickets) and your corporate email26(sales, support, executives). A reputation hit on the primary domain from27cold email complaints or bounces takes down ALL of those functions28simultaneously. Cold email must operate on entirely separate, isolated29infrastructure.3031## When to Use3233- User says "set up domains for cold email" or "buy sending domains" →34 activate this skill35- User asks "how many domains do I need" or "how many mailboxes per domain" →36 activate this skill37- User wants to "provision mailboxes for outreach" or "set up Google38 Workspace for outbound" → activate this skill39- User mentions "DNS configuration for email," "inbox rotation," or40 "primary domain isolation" → activate this skill41- User asks "should I use Google or Microsoft for cold email" or42 "Zoho vs Gmail for outreach" → activate this skill43- User wants to "scale sending capacity" or "add more mailboxes" →44 activate this skill4546Do NOT use for:47- Configuring SPF/DKIM/DMARC records → use `email-deliverability`48 (domain-infrastructure tells you WHICH domains and mailboxes;49 email-deliverability configures authentication ON them)50- Selecting a sending platform → use `sending-platforms`51- Designing email sequences → use `cold-email-strategy`5253## Authoritative Foundations5455This skill draws from the following established methodologies:5657- **Google Workspace Admin Best Practices** — Documentation on mailbox58 provisioning, sending limits, and security configuration. Google Workspace59 is the most common cold email mailbox provider due to deliverability60 reputation and API access for sending platforms.6162- **Microsoft 365 Exchange Online** — Admin documentation on mailbox63 provisioning, outbound spam policies, and sending limits. M365 is second64 most common. Higher reputation barrier for new tenants but stronger65 deliverability once established.6667- **Zoho Mail Admin** — Alternative provider for cost-conscious setups.68 Lower per-mailbox cost but lower default sending limits and less API69 maturity for sending platform integration.7071- **ICANN / Domain Registration Best Practices** — Guidelines on domain72 registration, WHOIS privacy, and domain age considerations. Domain age is73 a reputation factor — newly registered domains (under 90 days) face higher74 scrutiny from inbox providers.7576- **Validity / Return Path — Sender Score** — Domain-level reputation scoring77 that informs domain rotation decisions. A domain with a Sender Score below78 70 should be rotated out of active sending.7980- **Eric Nowoslawski — Growth Engine X.** Capacity planning for scale: **281 inboxes per domain** (contain blast radius), **1:1 backup inboxes** matching82 active send capacity, **50% spare warming** at all times. Scale math: target83 daily volume ÷ 30 sends/inbox ÷ 2 inboxes/domain = domains needed. Pair with84 `email-deliverability` for warmup and monitoring. Playbook →85 `../cold-email-strategy/references/eric-nowoslawski-outbound.md`.8687## Prerequisites8889- Access to a domain registrar (Namecheap, GoDaddy, Google Domains, Cloudflare90 Registrar, Porkbun, etc.)91- Budget for domains ($10-15/year per domain) and mailboxes (Google Workspace92 ~$6-18/user/month, M365 ~$6-22/user/month, Zoho ~$1-4/user/month)93- DNS management access (usually through the registrar or Cloudflare)94- Optional: LeadMagic API key for pre-send email verification to integrate95 with sending infrastructure96- Reference files: `references/deliverability-primer.md` for sending limits97 and domain isolation best practices9899## Step-by-Step Process100101### Phase 1: Intake102103Gather the following from the user. Ask all questions at once:1041051. **Primary business domain:** What is the domain used for corporate email,106 website, and transactional email? This will be left untouched — we only107 configure secondary domains.1081092. **Target sending volume:** How many total emails per day do you need to110 send? This determines how many mailboxes and domains are needed.1111123. **Budget:** What's the monthly budget for domains and mailboxes? This113 determines provider choice and scale.1141154. **Current setup:** Any existing secondary domains or mailboxes already116 in use? If yes, how old are they, what's their sending history?1171185. **Preferred providers:** Any existing relationship with Google Workspace,119 M365, or Zoho? Do you prefer one over the others?1201216. **Domain registrar:** Which registrar do you use? Do you use Cloudflare122 for DNS? These affect how DNS records are managed.1231247. **Sending platform:** Which platform will send the emails (Smartlead,125 Instantly, Salesforge, Apollo)? This affects mailbox integration126 requirements.1271288. **Warmup plan:** Will you warm up manually, use the sending platform's129 warmup, or both? This affects the provisioning timeline.1301319. **Geographic requirements:** Any data residency requirements (GDPR132 in EU, data localization laws)? This affects provider and region selection.133134### Phase 2: Research135136Before provisioning, research the domain landscape:1371381. **Primary domain reputation check:** Verify the primary domain has a clean139 reputation. Even though we won't send cold from it, a damaged primary140 domain reputation can affect secondary domains if they're too closely141 connected (same WHOIS, same IP, same brand name in domain). Check:142 - Google Postmaster Tools for the primary domain143 - MXToolbox blacklist check for the primary domain144 - Any existing SPF/DKIM/DMARC configuration1451462. **Domain naming strategy:** Research available domain names. The domain147 name DOES matter for deliverability. Avoid:148 - Exact match of primary brand name (too obvious, links to primary domain)149 - Hyphenated domains (associated with spam)150 - Very long domains (over 20 characters)151 - ccTLDs for non-geographic targeting (.co, .io are fine; .tk, .ml are not)152 - Domains registered in the last 24 hours (need 2+ weeks of age before153 sending, ideally 90+ days)154155 Good naming patterns:156 - `[brand][variant].com` — e.g., `getbrand.com`, `brandhq.com`, `trybrand.com`157 - `[brand][descriptor].com` — e.g., `brandops.com`, `brandteam.com`158 - Generic-but-professional: `[industry][term].com` — e.g., `saaescalate.com`1591603. **Provider pricing comparison (current market):**161 - Google Workspace Business Starter: ~$7.20/user/month (annual)162 - Google Workspace Business Standard: ~$14.40/user/month (annual)163 - Microsoft 365 Business Basic: ~$6.00/user/month (annual)164 - Microsoft 365 Business Standard: ~$12.50/user/month (annual)165 - Zoho Mail Lite: ~$1.00/user/month (annual)166 - Zoho Mail Premium: ~$4.00/user/month (annual)167168 Note: prices subject to change. Verify current pricing before quoting.169170### Phase 3: Execution171172#### Step 1: Calculate Capacity Requirements173174Determine how many domains and mailboxes are needed:175176Base formula: `mailboxes_needed = ceil(daily_target_volume / 40)`177178Explanation: 40 emails/day per mailbox is the recommended safe volume for179sustained sending. You can push to 50 but it leaves no headroom. Using 40180allows for reply handling and minor volume spikes without crossing the limit.181182Domain allocation:183- 3-5 sending domains recommended for redundancy184- 2-3 mailboxes per domain maximum185- No domain should carry more than 3 mailboxes — if one mailbox triggers a186 spam complaint, the domain reputation affects all mailboxes on that domain.187 Limiting to 2-3 per domain contains the blast radius.188189Examples:190- 80 emails/day: 2 mailboxes, 1-2 domains191- 200 emails/day: 5 mailboxes, 2-3 domains192- 400 emails/day: 10 mailboxes, 3-5 domains193- 800 emails/day: 20 mailboxes, 4-5+ domains (consider dedicated sending IPs194 at this scale)195196#### Step 2: Domain Registration197198For each domain:1992001. Register through your preferred registrar.2012. Enable WHOIS privacy protection (free on most registrars). Public WHOIS202 with matching registrant information across domains links them together,203 which inbox providers can detect.2043. Set auto-renew. A forgotten renewal that lets a domain lapse will break205 sequences and potentially create a deliverability event.2064. Add to DNS management (Cloudflare is recommended for fast DNS propagation207 and API access).2085. If using Cloudflare: enable DNSSEC for additional trust signaling.2096. Document: domain name, registrar, registration date, renewal date, DNS210 provider, nameservers.211212Domain age note: If possible, register domains at least 2 weeks before you213need to send. 90+ days of age before cold sending is ideal. A domain214registered today and sending cold email tomorrow is a strong spam signal.215216#### Step 3: Mailbox Provisioning (Google Workspace)217218For each mailbox on a Google Workspace domain:2192201. Sign up for Google Workspace for the domain. If you already have a221 Workspace tenant on one secondary domain, you can add additional domains222 as domain aliases (cheaper) or separate tenants (better isolation).2232242. Create user accounts for each mailbox:225 - Use professional naming: `[firstname]@[domain]`, `[firstinitial][lastname]@[domain]`,226 or role-based: `outreach1@[domain]`, `hello@[domain]`227 - Never use names like `email1@`, `send1@`, `cold1@` — these are spam228 signals detected by inbox providers229 - Set up a professional display name and profile photo for each account230 - Configure signature: first name only, no title/company logo2312323. Configure security:233 - Enable 2FA on all accounts (platform integrations use app passwords or234 OAuth, not raw passwords)235 - Create app passwords for each mailbox that the sending platform will use236 - Disable IMAP/POP if not needed (reduce attack surface)237 - Set up forwarding to a monitoring inbox for reply handling2382394. Google Workspace-specific sending considerations:240 - Google Workspace has a sending limit of 2,000 recipients per day per241 account, but cold email reputation management requires staying at 30-50242 - Google enforces the limit based on the account's reputation, not just243 the raw number244 - New accounts (under 30 days) face stricter rate limiting2452465. Document for each mailbox: email address, display name, app password247 (store securely), login email, 2FA method, forwarding configuration.248249#### Step 3b: Mailbox Provisioning (Microsoft 365)250251For each mailbox on an M365 domain:2522531. Sign up for Microsoft 365 Business Basic for the domain.2542. Create user accounts following the same naming conventions as Google.2553. Configure security: MFA, app passwords for platform integration.2564. M365-specific considerations:257 - Microsoft's outbound spam filtering is aggressive by default — new258 tenants may be restricted to minimal outbound volume259 - The "Restrict sending to internal recipients only" policy on new tenants260 must be explicitly disabled261 - Microsoft has a Recipient Rate Limit of 10,000 recipients/day, but262 practical cold limits are same as Google (30-50)263 - Outlook deliverability is often better for B2B reaching Microsoft-heavy264 organizations265266#### Step 3c: Mailbox Provisioning (Zoho Mail)267268For each mailbox on a Zoho domain:2692701. Sign up for Zoho Mail (Lite or Premium plan).2712. Create user accounts.2723. Zoho-specific considerations:273 - Lower per-mailbox cost ($1-4/month vs $6-18)274 - Lower default sending limits: 250-500/day depending on plan, but cold275 email requires same 30-50/day discipline276 - Less mature API for sending platform integration — confirm your platform277 supports Zoho before committing278 - Good for budget-constrained setups or supplementary mailboxes279280#### Step 4: DNS Configuration per Domain281282For each domain, before sending a single email:283284A. **SPF record:** Create a TXT record at the root that authorizes the285 mailbox provider (Google, M365, Zoho) AND the sending platform:286 ```287 v=spf1 include:_spf.google.com include:_spf.[sendingplatform].com -all288 ```289 (Adjust includes based on provider and platform.)290291B. **DKIM:** Generate DKIM keys through the mailbox provider's admin console292 and add the DNS records. Use a unique selector per provider:293 - Google: `google._domainkey`294 - M365: `selector1._domainkey` and `selector2._domainkey`295 - Zoho: `zoho._domainkey`296297C. **DMARC:** Add the DMARC record at `_dmarc.[domain]`:298 ```299 v=DMARC1; p=none; rua=mailto:dmarc@[yourdomain].com; fo=1;300 ```301 (Monitoring mode initially; progress to reject after warmup.)302303D. **Custom tracking domain (for sending platforms):** If using Smartlead,304 Instantly, or similar platforms, set up a CNAME record for click/open305 tracking:306 ```307 track.[domain] CNAME [platform-tracking-endpoint]308 ```309 This prevents the platform's shared tracking domain from being flagged310 and dragging down your deliverability.311312E. **Verify DNS propagation:** After adding records, verify with:313 - `dig TXT [domain]` for SPF314 - `dig TXT google._domainkey.[domain]` for DKIM315 - `dig TXT _dmarc.[domain]` for DMARC316 - MXToolbox or similar for comprehensive verification317318#### Step 5: Design Inbox Rotation319320Inbox rotation distributes sending across mailboxes to maintain consistent321volume without any single mailbox exceeding limits:322323Daily rotation pattern (example for 5 mailboxes sending 200/day):324- Mailbox 1: 40 sends (prospects 1-40)325- Mailbox 2: 40 sends (prospects 41-80)326- Mailbox 3: 40 sends (prospects 81-120)327- Mailbox 4: 40 sends (prospects 121-160)328- Mailbox 5: 40 sends (prospects 161-200)329330Rotation rules:331- Each prospect is assigned to a single mailbox for the entire sequence.332 Do not rotate a prospect across mailboxes — this breaks thread context333 and looks like a deliverability trick to inbox providers.334- Even distribution: each mailbox gets the same daily volume (±10%).335- Time zone alignment: if possible, assign prospects to mailboxes in their336 time zone so sends happen during the prospect's business hours.337- Reputation-based redistribution: if one mailbox shows degraded engagement,338 temporarily redirect a portion of its volume to other mailboxes while339 investigating.340341#### Step 6: Set Up Monitoring342343Before sending, set up monitoring for every domain and mailbox:3443451. **Google Postmaster Tools:** Register every domain. This is free and346 provides the best deliverability data for Gmail recipients (~45% of B2B).3473482. **Microsoft SNDS:** Register every sending IP. Covers Outlook/Hotmail349 recipients (~20% of B2B).3503513. **MXToolbox monitoring:** Set up automated blacklist checks for every352 domain. Free tier allows weekly monitoring.3533544. **Sending platform deliverability dashboard:** Configure in-platform355 deliverability monitoring (Smartlead's Deliverability Tab, Instantly's356 Health Score, etc.).3573585. **Internal tracking sheet:** Create a spreadsheet tracking per-mailbox359 and per-domain metrics: sends, opens, replies, bounces, complaints,360 unsubscribes. Review weekly.361362### Phase 4: Delivery363364Deliver a complete infrastructure plan:3653661. **Domain Inventory:** All registered domains with registration dates,367 registrars, DNS providers, and renewal dates.3683692. **Mailbox Inventory:** Every mailbox with email address, provider, plan,370 sending limit, and integration status.3713723. **DNS Configuration Map:** Per-domain DNS records (SPF, DKIM, DMARC, MX,373 tracking CNAME) in copy-paste format for the DNS console.3743754. **Rotation Schedule:** Daily sending allocation per mailbox with time376 zone assignments.3773785. **Scaling Plan:** How to add more capacity when needed (additional379 mailboxes within existing domains vs new domains).3803816. **Cost Projection:** Monthly and annual cost breakdown by provider.382383## Output Format384385```markdown386# Domain Infrastructure Plan for [Company]387388## Output Artifact Details389390Use `references/output-artifacts.md` for the full capacity calculation, domain inventory, mailbox inventory, DNS examples, inbox rotation schedule, monitoring configuration, scaling plan, and cost summary. The main output must summarize final counts, DNS records, monitoring thresholds, owner, and rollout dates.391392## Quality Check393394Before delivering, verify:395396- [ ] Is the primary business domain completely excluded from cold sending?397- [ ] Are 3-5 secondary domains planned (or scaled proportionally to volume)?398- [ ] Are there 2-3 mailboxes per domain maximum?399- [ ] Is the daily volume per mailbox set to 30-50 (recommended 40)?400- [ ] Are domain names professional and not spam-signaling?401- [ ] Is WHOIS privacy enabled on all domains?402- [ ] Are DNS records provided in copy-paste format for each domain?403- [ ] Does DMARC start in monitoring mode (`p=none`)?404- [ ] Is there a custom tracking domain configured per domain?405- [ ] Is Google Postmaster Tools registration included?406- [ ] Is blacklist monitoring set up?407- [ ] Is the cost projection complete and realistic?408- [ ] Is the scaling plan defined with trigger conditions?409- [ ] Are 2FA and app passwords configured for all mailboxes?410411## Common Pitfalls4124131. **Sending from the primary domain.** This is the cardinal sin of domain414 infrastructure. A single spam complaint on the primary domain takes down415 all corporate and transactional email. Never, under any circumstances,416 send cold email from your primary domain.4174182. **Too few domains.** Running all mailboxes on a single domain means one419 reputation event kills all sending capacity. 3 domains is the minimum420 for production outbound. 5 is better for volume above 300/day.4214223. **Too many mailboxes per domain.** When one mailbox on a domain gets423 flagged for spam, the domain reputation drops — affecting every mailbox424 on that domain. Limiting to 2-3 per domain contains the blast radius.4254264. **Spammy mailbox names.** `email-marketing@`, `sales-outreach@`, `cold1@`427 — inbox providers flag these patterns. Use professional,428 human-looking email addresses.4294305. **No WHOIS privacy.** Matching WHOIS registrant info across domains431 creates an easily identifiable pattern that inbox providers can use to432 link your domains. A reputation hit on one domain can cascade.4334346. **Sending from brand-new domains.** A domain registered yesterday and435 sending cold email today is a strong spam signal. Inbox providers track436 domain age. 2 weeks minimum before sending, 90+ days ideal.4374387. **No tracking domain customization.** Using the sending platform's439 default tracking domain puts your deliverability at the mercy of every440 other user on that shared domain. A spammer on the shared domain441 damages your reputation.4424438. **No monitoring before sending.** Setting up domains and mailboxes without444 simultaneously setting up Google Postmaster Tools, SNDS, and blacklist445 monitoring means you're flying blind. You won't know deliverability is446 broken until open rates collapse.4474489. **Rotating prospects across mailboxes mid-sequence.** Moving a prospect449 from mailbox A to mailbox B in the middle of a sequence breaks thread450 context, resets engagement history, and looks suspicious. Each prospect451 stays with one mailbox for the entire sequence.45245310. **Ignoring DNS propagation time.** DNS changes can take up to 48 hours454 to propagate globally. Always verify DNS records after 48 hours. Never455 start sending immediately after adding DNS records.456457## Provider Decision Matrix458459Use `references/provider-decision-matrix.md` when the task requires provider comparison. Keep the primary output focused on the chosen provider, DNS records, inbox allocation, and monitoring plan.460461## Execution Artifacts462463- `references/framework-notes.md` — Framework index and authority routing464- `templates/output-template.md` — Deliverable shell for agent output465- `scripts/check-output.py` — Lightweight deliverable validator466- `../cold-email-strategy/references/eric-nowoslawski-outbound.md` — Inbox/domain ratio, backup capacity, scale math (Eric Nowoslawski)467- `references/deliverability-primer.md` — Deliverability fundamentals468- `references/output-artifacts.md` — Extended output tables and inventories469- `references/provider-decision-matrix.md` — Mailbox provider comparison470471## Related Skills472473- `email-deliverability` — adjacent workflow to use before or after this skill474- `sending-platforms` — adjacent workflow to use before or after this skill475- `cold-email-strategy` — adjacent workflow to use before or after this skill476- `technical-seo` — adjacent workflow to use before or after this skill