Menu

Burned cold email domain: how to tell, and how to recover it

Rather not build this yourself? Pipefire runs your cold email end to end.See how it works →

A burned cold email domain is one whose reputation has dropped far enough that its mail routes to spam or gets blocked outright. You can usually tell before a provider blocks you outright, if you are watching the right numbers.

Our guide to cold email domains covers buying, naming and retiring sending domains in general. This page goes deeper on one part of that. It covers the signals that mean a domain is burned, whether to nurse it back or cut it loose, the actual recovery steps, and what to expect from Microsoft and Google once a provider has already acted on you.

How do you know a cold email domain is burned?

You know a cold email domain is burned when its mail reliably lands in spam or gets rejected, not just occasionally. One bounce or one spam folder placement is normal; a pattern across several signals is burned.

Our cold email domains guide lists the basic warning signs. Here is how to confirm each one, in the order they usually appear:

  • Warm-up mail lands in spam. Confirm it on the warm-up mail itself: if more than 1 in 10 warm-up messages over the last week landed in spam, the problem is the domain, because warm-up traffic has no bad list to blame. Cold mail from the same mailbox is probably filing the same way.
  • Bounces climb past 3%. Read the bounce messages, not just the count. "User unknown" codes point to the list; "blocked" or "policy" codes point to the domain itself, which is the worse case.
  • Spam complaints pass 0.1%. Google's sender guidelines set the ceiling at 0.3%. Treating 0.1%, a third of that, as the point to act leaves room to fix the cause before you are anywhere near Google's own limit.
  • Replies drop while send volume stays flat. A falling reply rate with no change in targeting or volume often means mail is quietly filing into spam rather than reaching anyone.
  • A provider rejects the mail outright. A non-delivery report citing a block, or a message that never reaches the recipient's inbox folder in a placement test, is the clearest signal of all: a human check, not an inference from your own numbers.

None of these alone proves a domain is gone. A single bad list can spike bounces on an otherwise healthy domain. What makes a domain burned is two or more of these showing up together, and staying bad after you stop sending from it.

Should you recover a burned cold email domain or replace it?

Recover a domain if the damage is recent, small and traceable to one fixable cause. Replace it if the damage is severe, has lasted weeks, or you cannot find a specific cause to fix.

SignalRecoverReplace
Cause found and fixed (broken DNS record, one bad list, a volume spike)Yes, rest and re-warmNot needed
Warm-up spam rate still high after a clean rest periodMaybe, give it longerYes, if it does not improve
A provider sent an explicit block or NDRPossible, through that provider's delist processYes, if several providers are blocking it
Damage has lasted weeks with no improvementNoYes
You cannot identify what caused itNoYes

The decision usually comes down to cost against certainty. A replacement sending domain costs about $11. That is why our guide to cold email domains recommends keeping a spare, already-warm domain on hand, so a bad one can be swapped out without stopping the campaign. Recovery costs nothing in cash but costs time, and there is no guarantee it works.

How do you recover a burned cold email domain?

Recover a burned domain by stopping cold sending from it immediately, finding the cause, fixing it, then re-earning trust slowly instead of restarting at full volume. Skipping any of these steps usually means doing it again.

  1. Stop cold sending from the domain at once. Keep your other domains running; one burned domain should not stop the whole campaign.
  2. Check authentication. Confirm SPF, DKIM and DMARC still pass in the message headers. A DNS change elsewhere, or a record that expired, can quietly break one of these without anything else changing.
  3. Check what changed. Look at volume, list source and content in the days before the drop. A jump in daily sends, a new unverified list, or a new link are the most common triggers.
  4. Clean the list. Remove anything that bounced and verify what remains, so the next batch does not reopen the same wound.
  5. Rest the domain on warm-up only. No cold sending while you watch whether warm-up mail starts landing in the inbox again.
  6. Restart cold sending slowly if warm-up recovers. Begin at a low daily volume, well below your normal ramp, and increase gradually while watching bounce and complaint rates.
  7. Retire the domain if it does not recover. If warm-up mail keeps landing in spam after a genuine rest period, stop trying to fix it and move to a replacement.

How long does cold email domain recovery take?

Cold email domain recovery takes a variable amount of time, and nobody can promise you a number of days. Fixing a broken DNS record can restore deliverability within hours; rebuilding a damaged reputation after real spam complaints or sustained bounces takes weeks of clean, low-volume sending, and some domains never recover at all.

Apollo's own warm-up guidance is blunt about this. If a sender's reputation is already damaged, warm-up may not be enough to fix it, and its recommendation is to start fresh with a new domain or mailbox and rebuild trust from there. That matches what our email warm-up guide says about the same tradeoff: warm-up builds a sending history, it does not undo a bad one.

Resist the urge to put a number on it anyway. A domain with one bad week of bounces, cleaned up fast, can look normal again in under a month.

A domain with sustained spam complaints across several providers may not come back no matter how long you rest it. Treat any specific day count you read elsewhere as a guess dressed up as a fact, including one from us. We would rather tell you it varies than invent a figure that does not hold for your case.

Why did Microsoft block my cold email domain?

Microsoft blocks a sending domain or IP address when its filters decide your mail looks abusive, regardless of your intent. This usually follows the same pattern as any other provider. Too much volume too fast, complaints, or a list with bad addresses can all trigger it, but Microsoft's response is often a hard block rather than a quiet spam-folder filing.

If Outlook or Microsoft 365 has rejected your mail, the non-delivery report usually names the reason and points you to Microsoft's own remediation path:

  • The Office 365 Anti-Spam IP Delist Portal at sender.office.com lets you submit the blocked IP address for review once you believe the underlying problem is fixed.
  • Microsoft's delist guidance at its Defender for Office 365 documentation explains the process: use the email address that received the bounce and the blocked IP address on the delist portal. If the bounce shows error 5.7.511 instead, the portal will not work; email delist@microsoft.com with the full bounce message and IP address.

Submitting a delist request before fixing the cause rarely works, because the same behavior that triggered the block will trigger it again. Fix authentication, cut volume and clean the list first, then submit the request. Microsoft says results from the delist portal can take up to 24 hours or longer; if the bounce instead shows error 5.7.511, the alternate route by email to delist@microsoft.com gets a response within 48 hours, according to Microsoft's own documentation.

For what reputation is and how it is scored, see sender reputation for cold email.

What does Google Postmaster Tools tell you about a burned cold email domain?

Google Postmaster Tools shows you what Gmail sees about your authentication, spam rate and delivery errors for a domain. It is the closest thing to an outside view of your reputation at the world's largest inbox provider. Set it up by adding and verifying your sending domain, following Google's own setup instructions.

Three dashboards matter most for a domain you suspect is burned:

  • Spam rate. How often Gmail users mark your mail as spam, tracked against Google's 0.3% ceiling.
  • Authentication. Whether SPF, DKIM and DMARC are passing for the mail you actually send, not just configured correctly on paper.
  • Delivery errors. Rejections and temporary failures broken out by cause, which often point straight at the problem.

One change matters here: Google retired the old "high, medium, low, bad" domain and IP reputation score from Postmaster Tools in September 2025, according to Twilio's writeup of the change. There is no single reputation grade to check anymore. What remains, and what you should actually watch, is the spam rate dashboard, the authentication dashboard and delivery errors, cross-referenced against the sender requirements in Google's email sender guidelines.

Practically, that means treating Postmaster Tools as a set of independent signals rather than one score. Check whether your spam rate sits near Google's 0.3% ceiling, whether SPF, DKIM and DMARC authentication show as passing, and whether delivery errors are appearing for this domain. A domain burned at Gmail will usually show a rising spam rate here before Gmail users notice anything missing from their inbox.

Pipefire watches for the earliest of these signals itself. It pauses a campaign once bounces pass 3% or complaints pass 0.1%, and pulls a mailbox back into warm-up once its warm-up spam rate reaches 20% over the last 7 days, so a domain gets rested before it is burned. Our deliverability page explains every threshold it checks.

Burned cold email domain FAQ

Can a burned cold email domain affect my other domains?

Not directly, if your sending domains are genuinely separate with their own DNS records and mailboxes. Inbox providers judge each domain mostly on its own history, which is the whole reason to spread cold email across several sending domains rather than one.

Is it worth trying to recover a cheap cold email sending domain?

Usually not if a replacement costs about $11 and the domain shows severe, sustained damage. Spend the effort recovering a domain only when the cause is clear and fixable; otherwise a fresh domain and a few weeks of warm-up is often faster than waiting on an uncertain recovery.

What is the first thing to do when a cold email domain gets flagged?

Stop cold sending from it immediately and check authentication. Most flags trace back to a broken SPF, DKIM or DMARC record, a volume spike, or a bad list, and you cannot diagnose any of them while mail keeps going out.

Does rewarming a burned domain work the same way as warming a new cold email domain?

The mechanics are the same: send small volumes of mail that gets opened and replied to, and watch the warm-up spam rate. The difference is that a new domain starts at zero reputation while a burned one starts in a hole. Recovery can take longer than the normal warm-up schedule, and it is not guaranteed to finish at all.

Does a pre-warmed replacement domain fix cold email deliverability instantly?

No. Even a domain that has been warming for weeks still needs its cold volume ramped up gradually rather than jumped to full speed, and "pre-warmed" describes time spent rather than a guaranteed result. Check any replacement domain's own warm-up results before trusting it with real volume.