In short

Based on our research, the safest way to use a redirect on a sending domain is a clean 301 to your real site over HTTPS, served from shared infrastructure whose addresses also carry a large number of ordinary websites. That keeps the domain out of the clusters of outreach domains that some blocklists group together. It's the setup we think works best, and it's how new redirects work on Winnr for domains whose DNS Winnr manages, with nothing to configure. Below: how redirects work, why the hosting address matters more than the page, and what we measured.

There are a lot of opinions on how sending-domain redirects should work, and plenty of great minds in cold email have explored every angle. We've done our own deep research too. This is what we found is safest and works best, and it's how Winnr redirects now work, to give your domains the best protection and deliverability.

Cold email runs on secondary domains. getacme.com and tryacme.com carry the outreach so acme.com stays protected, and when a prospect types one of them into a browser it should lead straight to the real company. Here's how that redirect works, what we measured, and the setup we think works best.

How a sending-domain redirect works

Three things happen when someone visits a sending domain:

  1. DNS lookup. The domain's A record returns the IP address of the web server that answers for it.
  2. A secure connection. The browser connects to that address and checks the domain's TLS certificate.
  3. The redirect. The server replies with a status code, ideally 301 Moved Permanently, and the address of your main site.

Anyone can repeat step one for any domain. That means the address your sending domain resolves to is public, and so is every other domain that resolves to the same place.

Why the hosting address matters

Redirects in cold email are usually served by a small number of web servers run by the infrastructure provider, so large numbers of unrelated outreach domains end up on the same few addresses. That makes them easy to group together.

Some blocklists use exactly that kind of relationship. When several domains on one address are listed, the others on it can start to look like part of the same activity. A well-run domain can be judged partly by its neighbours. The fix isn't changing what the redirect shows. It's changing where it lives.

What we measure

We track blocklist signals across the domains on our platform, and redirects gave us a clean way to test the question: the way redirect addresses had been assigned to domains was effectively random, so if the address made no difference, listing rates would look the same everywhere once you account for who owns each domain. They didn't.

  1. For one of the major URI blocklists, the address mattered. Domains that shared an address with already-listed domains were listed noticeably more often, even compared with other domains owned by the same customer.
  2. Other major domain blocklists didn't show the pattern. Their listings followed the domain and how it was used.
  3. Page content didn't change categorisation. In our checks with a large web-filtering vendor, redirect domains didn't take on their destination site's category. Categorisation followed sending behaviour, not the website.

That told us where to focus: not what the redirect shows, but the infrastructure underneath it.

What we think works best

  1. A clean permanent redirect. Every redirect is a standard 301 over HTTPS, on both the bare domain and www. The path and query string carry over, so getacme.com/pricing?ref=email lands on acme.com/pricing?ref=email, and search engines get an unambiguous signal about which domain is the original.
  2. Shared infrastructure with ordinary websites. For domains whose DNS Winnr manages (the default), new redirects are served from shared web infrastructure whose addresses also carry a large number of unrelated, everyday websites. Your sending domain doesn't sit in a small cluster of outreach domains, and the address itself says nothing about it.
  3. Verified before it goes live. Every redirect passes automated checks before it's switched over: a valid certificate, and the homepage, deeper pages and www all redirecting to the right place.
  4. Monitored after. We keep checking live redirects. If anything fails, the domain moves to our own redirect servers automatically, so the redirect never stops working.
Nothing to configure on Winnr

Set a redirect on the Domains page, or in the purchase wizard when you buy domains, and Winnr handles the rest. See Domain redirects and email forwarding for the steps.

Where domain masking fits

Domain masking serves your website's content on the sending domain itself, so visitors stay on getacme.com while seeing your real site. It's another way to give a sending domain a credible presence, and it's a popular option in cold email. Winnr's work sits at a different layer: what your domain resolves to and who it's grouped with, which is the relationship our measurements showed blocklists reading.

We keep measuring

Blocklists and mailbox providers keep refining how they connect domains, so we keep measuring listing signals across the domains on our platform. If the data points somewhere new, we'll update this recommendation and how Winnr handles redirects.

The bigger deliverability picture

A well set-up redirect keeps your domain from inheriting problems it didn't cause. The factors that most decide whether a domain stays clean are still:

Related guides: Cold email DNS setup checklist, why Winnr uses DMARC p=reject, and how to recover a burned domain.

Frequently Asked Questions

Does a sending domain's redirect affect deliverability?

It can. What matters most is the web address the domain resolves to and which other domains share it, because some blocklists group domains by shared infrastructure. A clean 301 served from an address shared with ordinary websites keeps your domain out of those groups.

What's the difference between a redirect and domain masking?

A redirect sends the visitor on to your main website, so the address bar changes to your main domain. Domain masking serves your site's content on the sending domain, so the address bar stays on the sending domain. Winnr focuses on where the redirect is hosted, which is the relationship our measurements showed blocklists reading.

Should my sending domain redirect to my main website?

In most cases, yes. A domain that loads nothing or shows a parked page looks unfinished to prospects who check it. A permanent redirect shows the domain belongs to a real company and tells search engines which domain is the original.

Do I need to do anything to get this on Winnr?

No. Set a redirect as usual and Winnr handles hosting, verification and monitoring. It applies to new redirects on domains whose DNS Winnr manages, which is the default when you buy a domain or point its nameservers at Winnr. If you connected a domain with manual DNS records, the Domains page shows the A record to publish.

Does the redirect keep the page and tracking parameters?

Yes. The path and query string carry over, so a link to a specific page with tracking parameters on your sending domain lands on the same page, with the same parameters, on your main site.